- Posts: 5242
Heartbleed Bug
10 Apr 2014 02:56 #143990
by
Heartbleed Bug was created by
Breaking News:
Heartbleed Affects Your Secure Personal Information
A major bug affects the SSL security protocol and makes sites which haven't updated vulnerable to data mining hacks. In general, just wait. Most of us aren't affected, but if you are: change the passwords to websites that are unaffected so that the compromised information can't be used to get into your secure stuff.
A major bug affects the SSL security protocol and makes sites which haven't updated vulnerable to data mining hacks. In general, just wait. Most of us aren't affected, but if you are: change the passwords to websites that are unaffected so that the compromised information can't be used to get into your secure stuff.
Please Log in to join the conversation.
10 Apr 2014 13:34 #144009
by Edan
It won't let me have a blank signature ...
Replied by Edan on topic Heartbleed Bug
I saw this this morning; a little worrying and I will now be changing all my passwords.
It won't let me have a blank signature ...
Please Log in to join the conversation.
10 Apr 2014 14:49 #144011
by
Replied by on topic Heartbleed Bug
I read this as well. Start with any Google passwords as they have already corrected the problem. The next step should be to change your other passwords now and then change them again a week from now once the fix has propagated to the rest of the secure sites you use.
Or just be a caveman and do all your secure transactions face to face for a while.
Or just be a caveman and do all your secure transactions face to face for a while.
Please Log in to join the conversation.
Less
More
- Posts: 2930
10 Apr 2014 23:14 - 10 Apr 2014 23:23 #144065
by Brenna
Walking, stumbling on these shadowfeet
Part of the seduction of most religions is the idea that if you just say the right things and believe really hard, your salvation will be at hand.
With Jediism. No one is coming to save you. You have to get off your ass and do it yourself - Me
Replied by Brenna on topic Heartbleed Bug
Can someone explain this whole thing to me? Ive just had my social media manager freaking out because we're being told on the one hand to change all passwords immediately, and on the other not to until we know that particular platform has been patched...?
I'm not particularity tech savy, I am am a little concerned as my business operates across several of the problematic platforms....
Thoughts?
I'm not particularity tech savy, I am am a little concerned as my business operates across several of the problematic platforms....
Thoughts?
Walking, stumbling on these shadowfeet
Part of the seduction of most religions is the idea that if you just say the right things and believe really hard, your salvation will be at hand.
With Jediism. No one is coming to save you. You have to get off your ass and do it yourself - Me
Last edit: 10 Apr 2014 23:23 by Brenna.
Please Log in to join the conversation.
11 Apr 2014 04:21 - 11 Apr 2014 04:23 #144084
by Adder
Replied by Adder on topic Heartbleed Bug
At the risk of showing how little I know...
The concept of secure internet connections (secure sockets layer - SSL) allowed ecommerce and banking to take off back in the 90's - its the little 's' sometimes seen after http in the address bar; https
So now apparently some software which is/was very popular for websites to use for this service, called OpenSSL, managed to get a vulnerability into it which allowed anyone who knew of it, to intercept passwords etc.
The whole point of SSL is that it is encrypted and secure, so if that is compromised then its a problem! I guess the breadth of the problem depends on the scope of OpenSSL's use throughout the internet.
"It also allowed for a server's private encryption keys to be stolen. Once stolen, these keys can be used by criminals to decrypt data sent between a website's server and a user of that website."
An article here; http://www.smh.com.au/it-pro/security-it/man-who-introduced-serious-heartbleed-security-flaw-denies-he-inserted-it-deliberately-20140410-zqta1.html
The concept of secure internet connections (secure sockets layer - SSL) allowed ecommerce and banking to take off back in the 90's - its the little 's' sometimes seen after http in the address bar; https
So now apparently some software which is/was very popular for websites to use for this service, called OpenSSL, managed to get a vulnerability into it which allowed anyone who knew of it, to intercept passwords etc.
The whole point of SSL is that it is encrypted and secure, so if that is compromised then its a problem! I guess the breadth of the problem depends on the scope of OpenSSL's use throughout the internet.
"It also allowed for a server's private encryption keys to be stolen. Once stolen, these keys can be used by criminals to decrypt data sent between a website's server and a user of that website."
An article here; http://www.smh.com.au/it-pro/security-it/man-who-introduced-serious-heartbleed-security-flaw-denies-he-inserted-it-deliberately-20140410-zqta1.html
Last edit: 11 Apr 2014 04:23 by Adder.
Please Log in to join the conversation.
11 Apr 2014 22:14 #144167
by ren
Convictions are more dangerous foes of truth than lies.
Replied by ren on topic Heartbleed Bug
totjo website doesn't use ssl. We have no sensitive information here, and our openssl package is unaffected. I'm not sure many people will be interested in hacking your gmail account in order to initiate a totjo password reset.
Convictions are more dangerous foes of truth than lies.
Please Log in to join the conversation.