Enjoy unlimited access to all forum features for FREE! Optional upgrade available for extra perks.

In The News: The Heartbleed Bug

Status
Not open for further replies.

Acorn Newsbot

Junior Member
Joined
Jan 28, 2006
Posts
22,605
Reaction score
126
heartbleed-bug_0.png



Security experts this week have discovered that a bug in the software used by millions of websites across the world could have exposed users to spying and online eavesdropping.

The Heartbleed Bug, so called because it exploits an extension called ‘heartbeat’, is present in software that is used in operating systems, servers, instant messaging and email. Called OpenSSL, the software is supposed to protect sensitive data as it is transmitted.

Experts from the net monitoring firm Netcraft, estimate that about 500,000 of the web’s secure servers are running versions of the vulnerable software. It is thought that the bug has been present in versions of OpenSSL that have been available for over two years. Only the latest version, released on 7th April, is immune to the bug. Unfortunately, installing this updated version does not guarantee that people are safe from attacks, as cybercriminals may have already stolen passwords, encryption keys, or other credentials enabling them to access a server.*

The researchers stated, “Considering the long exposure, ease of exploitation and attacks leaving no trace this exposure should be taken seriously”.

Who are the affected sites?

Some commonly used sites that may be vulnerable include:

  • Imgur
  • Flickr
  • OKCupid
  • Lloyds TSB
  • Nationwide
  • Santander
What Can You Do?

Some experts have recommended that people take immediate steps to protect themselves by changing all of their online passwords, including those for social networks, online banking, ecommerce sites, and more.

This is advice that has been repeated by many large companies, including affected ones such as Tumblr, which released a message saying: “"This might be a good day to call in sick and take some time to change your passwords everywhere — especially your high-security services like email, file storage, and banking, which may have been compromised by this bug”.

However, this is not necessarily the best course of action. Mark Schloesser, a security researcher with Rapid7, said that doing so “could even increase the chance of somebody getting the new password through the vulnerability”. This is because logging into an insecure server to change your password could then reveal both your old and your new passwords to a hacker.*

Additionally, he states that there is an estimate that “the larger providers (will) all get patched within the next 24-48 hours” (Thursday to Friday afternoon). Once this time period has passed, he says “I would agree that people should change their credentials when a provider has updated their OpenSSL versions”.*

Staying Safe

As such, we would recommend avoiding logging into any affected website until you are sure that the company has patched the problem, and then changing your passwords. For advice on choosing a strong password, check out Knowthenet’s password section.

To check if a website is still vulnerable to the Heartbleed bug, you can you this online tool, created by developer Filippo Valsorda.

Image from Wikimedia Commons

*






More...
 
Status
Not open for further replies.

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Members online

☆ Premium Listings

Sedo - it.com Premiums

IT.com

Premium Members

Acorn Domains Merch
MariaBuy Marketplace

Domain Forum Friends

Other domain-related communities we can recommend.

Our Mods' Businesses

Perfect
Laskos
*the exceptional businesses of our esteemed moderators
General chit-chat
Help Users
  • No one is chatting at the moment.
  • Helmuts @ Helmuts:
    @Admin please enable the chat visible to unregistered users, or who haven't signed in their accounts. Tx
  • Helmuts @ Helmuts:
    please
    brave_qptn86fptt-png.4616
  • D AcornBot:
    DLOE has left the room.
  • Helmuts @ Helmuts:
    also, please keep the restriction in regards to posting > posting permission should be available to members only
  • Daniel - Monetize.info @ Daniel - Monetize.info:
    Welcome everyone!
  • Helmuts @ Helmuts:
    @Daniel - Monetize.info
    chrome_8fedcfysiy-png.4617
    .. can you see this one?
  • Helmuts @ Helmuts:
    nice, isn't it? :)
  • alan AcornBot:
    alan has left the room.
    • Wow
    Reactions: Jam
  • alan AcornBot:
    alan has joined the room.
  • alan AcornBot:
    alan has left the room.
  • alan AcornBot:
    alan has joined the room.
  • Helmuts @ Helmuts:
    Hi Alan
  • Helmuts @ Helmuts:
    long time no see
  • Helmuts @ Helmuts:
    hows parachute doing?
  • Helmuts @ Helmuts:
    :) huhhh.. Joe Rogan has just published an interview with Donald Trump
    To view this content we will need your consent to set third party cookies.
    For more detailed information, see our cookies page.
  • Helmuts @ Helmuts:
    almost 3 hours..
  • Helmuts @ Helmuts:
    morning all :)
  • Helmuts @ Helmuts:
    .. is anyone going to domain day in Dubai or icann Turkey?
    • Like
    Reactions: gdomains
  • boxerdog AcornBot:
    boxerdog has left the room.
  • Helmuts @ Helmuts:
    Greetings from Istanbul, Turkey!
  • alan AcornBot:
    alan has left the room.
  • C AcornBot:
    cav has left the room.
      C AcornBot: cav has left the room.
      Top Bottom