Table of contents
Hamburger menu icon

Cloudflare bug: Wave data not exposed

By Rob Maurin
Reviewed by
February 21, 2017
5 minutes read

You may have read some news online: A major internet infrastructure provider called Cloudflare reported a bug, which exposed private data of some websites that use its services.

Cloudflare is a very big player in web infrastructure, whose services are used to improve website performance as well as privacy and security. By some estimates, as much as 10% of internet traffic passes through Cloudflare.

A bug in Cloudflare meant that information intended for one website could have been accidentally passed to a different website. Wave uses Cloudflare, so of course we have been in contact with Cloudflare and have been monitoring this situation closely.

We have been informed by Cloudflare that Wave data was not included in the data that is known to have been leaked.We expect Cloudflare to continue investigating, and will update this statement if new information comes to light.

It’s also worth pointing out that this bug was discovered by security researchers at Google, and as of this time there have been no reports of the leaked data being used maliciously.

Nonetheless, we also believe strongly in taking every precaution to protect yourself. Changing (rotating) passwords on a regular basis is good security practice, and we recommend that all customers use this opportunity to do so today, not just for Wave but for any online services you use.

We do not in any way mean to minimize the severity of this matter. It deserves (and is getting) very close scrutiny from our engineering and security teams, and we expect the same to be happening at Cloudflare. But our current understanding is that Wave customer data has not been found in the leaked data.

Appearing on lists

We’re aware of a variety of list that have begun circulating, identifying Cloudflare users.

These lists are generated automatically by checking if a given website appears to use Cloudflare. However, it’s important to note: These are not lists of sites whose data was leaked; they are lists of sites that use some part of Cloudflare’s tool set.

Cloudflare estimates that less than 0.00003% of requests they handle (1 in 3.3 million) were impacted by the “cloudbleed” bug. In other words, these lists are good for identifying which of your services you should be contacting, but they do not identify services whose data was actually compromised.

As always, our customers’ privacy and security are paramount, and we’ll continue to monitor this situation to let you know if anything changes.

starter
Plan
starter
Plan
$0
pro
Plan
$16USD
$20CAD/mo
Option to accept online payments
Starting at
2.9% + $0.60
per credit card transaction
Starting at
2.9% + $0*
per credit card transaction
for first 10 transactions/mo
Unlimited invoices, estimates, bills
Add your logo and brand colors
Automate late payment reminders
with online payments
Wave mobile app
Unlimited bookkeeping records
Dashboard and reports
Auto-import transactions
Auto-merge transactions
Auto-categorize transactions
Add users
Live-person chat and email support
with any paid add-on
Digitally capture unlimited receipts
additional fee
Payroll
additional fee
additional fee
Hire a bookkeeper
additional fee
additional fee
Option to accept online payments
Starting at
2.9% + $0.60
per credit card transaction
Starting at
2.9% + $0*
per credit card transaction
for first 10 transactions/mo
Unlimited invoices, estimates, bills
Add your logo and brand colors
Automate late payment reminders
with online payments
Wave mobile app
Unlimited bookkeeping records
Dashboard and reports
Auto-import transactions
Auto-merge transactions
Auto-categorize transactions
Add users
Live-person chat and email support
with any paid add-on
Digitally capture unlimited receipts
additional fee
Payroll
additional fee
additional fee
Hire a bookkeeper
additional fee
additional fee
starter
Plan
$0
Legacy businesses
New businesses
pro
Plan
$16USD or
$20CAD/mo
starter
Plan
$0
Legacy businesses
New businesses
pro
Plan
$16USD or
$20CAD/mo
Invoicing + payments
Option to accept online payments
(and create unique links with checkouts)
Starting at
2.9% + $0.60
per credit card transaction
Starting at
2.9% + $0.60
per credit card transaction
Starting at
2.9% + $0*
per credit card transaction
for first 10 transactions/mo

Send invoices, estimates, and other docs:

  • via links or PDFs
  • automatically, via Wave
with online payments
with online payments
Automate late payment reminders
with online payments
with online payments
Add your logo and brand colors
Remove Wave branding from footers
Add attachments to invoices and estimates (NEW!)
Create reusable message templates (NEW!)
Invoice and estimate in the mobile app
Accounting
Unlimited bookkeeping records
Auto-import bank transactions
Auto-merge and categorize transactions
Add users to your business
businesses already auto-importing bank transactions and/or that already have users added to their businesses as of May 1, 2024
Digitally capture unlimited receipts
with receipts add-on
with receipts add-on
Manage accounting transactions in the mobile app and sync with desktop (NEW!)
with receipts add-on
with receipts add-on
Other Wave features
Dashboard and reports
Live-person chat + email support
with any optional add-on
with any optional add-on
Optional add-ons
Receipts
nothing changes
additional fee
included
Payroll
nothing changes
additional fee
additional fee
Advisors
nothing changes
additional fee
additional fee
Invoicing + payments
Option to accept online payments
(and create unique links with checkouts)
Starting at
2.9% + $0.60
per credit card transaction
Starting at
2.9% + $0.60
per credit card transaction
Starting at
2.9% + $0*
per credit card transaction for first 10 transactions/mo
Send invoices, estimates, and other docs via links or PDFs
Send invoices, estimates, and other docs automatically, via Wave
with online payments
with online payments
Automate late payment reminders
with online payments
with online payments
Add your logo and brand colors
Remove Wave branding from footers
Add attachments to invoices and estimates (NEW!)
Create reusable message templates (coming NEW!)
Invoice and estimate in the mobile app
Accounting
Unlimited bookkeeping records
Auto-import, -merge, and -categorize bank transactions
businesses already auto-importing bank transactions and/or that already have users added to their businesses as of May 1, 2024
Add users to your business
businesses already auto-importing bank transactions and/or that already have users added to their businesses as of May 1, 2024
Digitally capture unlimited receipts
with receipts add-on
with receipts add-on
Manage accounting transactions in the mobile app and sync with desktop (NEW!)
with receipts add-on
with receipts add-on
Other Wave features
Dashboard and reports
Live-person chat + email support
with any optional add-on
with any optional add-on
Optional add-ons
Receipts
nothing changes
additional fee
included
Payroll
nothing changes
additional fee
additional fee
Advisors
nothing changes
additional fee
additional fee

*While subscribed to Wave’s Pro Plan, get 2.9% + $0 (Visa, Mastercard, Discover) and 3.4% + $0 (Amex) per transaction for the first 10 transactions of each month of your subscription, then 2.9% + $0.60 (Visa, Mastercard, Discover) and 3.4% + $0.60 (Amex) per transaction. Discover processing is only available to US customers. See full terms and conditions for the US and Canada. See Wave’s Terms of Service for more information.

By Rob Maurin
Categories:

The information and tips shared on this blog are meant to be used as learning and personal development tools as you launch, run and grow your business. While a good place to start, these articles should not take the place of personalized advice from professionals. As our lawyers would say: “All content on Wave’s blog is intended for informational purposes only. It should not be considered legal or financial advice.” Additionally, Wave is the legal copyright holder of all materials on the blog, and others cannot re-use or publish it without our written consent.

Create your Wave account today.

Let's do this