Heartbleed

Main forum for site announcements, suggestions, and help.

Moderators: Savor Dam, Vain

Post Reply
User avatar
I'm Murrin
Are you?
Posts: 15840
Joined: Tue Apr 08, 2003 1:09 pm
Location: North East, UK
Contact:

Heartbleed

Post by I'm Murrin »

Web security folks recently discovered a major vulnerability in OpenSSL, a security system used by a majority of websites. This vulnerability, named Heartbleed, made it possible for a user to send requests to the site and receive back secure information - that could include security keys, passwords, and pretty much anything in there. A patch for OpenSSL has been issued, and major websites that had the vulnerability have started upgrading to fix the issue.

[FYI, we know for certain that Yahoo, along with subsidiaries Tumblr and Flickr, were still vulnerable to the Heartbleed exploit when it was publicly announced. Facebook services were vulnerable but have been patched.]

It is not clear whether this flaw was exploited prior to its discovery, but it almost certainly is being exploited now that it's publicly known.

The main thing to take away is this:

Assume that your data on any affected site was not secure. If you have accounts on affected websites, check that they have upgraded their software to fix the issue, and only then should you reset your password.

If the password you used on a vulnerable site was the same as one you used elsewhere, change all of those passwords.

Keeping your passwords unique is recommended, and once again, make sure that sites are not vulnerable to the Heartbleed before changing your password, or else you'll just have to do it all over again.

I do not know if the servers hosting Kevin's Watch use OpenSSL - perhaps Vain can enlighten us on this - but I'd encourage caution.

For more information, check www.heartbleed.com

Also: Useful list of vulnerable sites.
User avatar
aliantha
blueberries on steroids
Posts: 17865
Joined: Tue Mar 05, 2002 7:50 pm
Location: NOT opening up a restaurant in Santa Fe

Post by aliantha »

Thanks, Murrin. :)
Image
Image

EZ Board Survivor

"Dreaming isn't good for you unless you do the things it tells you to." -- Three Dog Night (via the GI)

https://www.hearth-myth.com/
User avatar
Avatar
Immanentizing The Eschaton
Posts: 62038
Joined: Mon Aug 02, 2004 9:17 am
Location: Johannesburg, South Africa
Has thanked: 25 times
Been thanked: 32 times
Contact:

Post by Avatar »

Good heads up from Murrin. Pretty sure this can't affect the Watch as I don't think we use any SSL, but I will check with Vain.

--A
User avatar
Vain
Nom
Posts: 5057
Joined: Sat Mar 02, 2002 3:19 pm
Contact:

Post by Vain »

We're good :)
Post Reply

Return to “Announcements + Suggestions + Q&A + Help”