Register ICMag Forum Menu Features
You are viewing our:
in:
Forums > Talk About It! > Security & Legal Issues > Heartbleed Security Flaw affects most of Internet

Thread Title Search
Click for Weed Seed Shop
Post Reply
Heartbleed Security Flaw affects most of Internet Thread Tools Search this Thread
Old 04-09-2014, 03:31 PM #1
dddaver
Senior Member

dddaver's Avatar

Join Date: Dec 2010
Location: uh...yeah
Posts: 2,345
dddaver has a brilliant futuredddaver has a brilliant futuredddaver has a brilliant futuredddaver has a brilliant futuredddaver has a brilliant futuredddaver has a brilliant futuredddaver has a brilliant futuredddaver has a brilliant futuredddaver has a brilliant futuredddaver has a brilliant futuredddaver has a brilliant future
Heartbleed Security Flaw affects most of Internet

Please note: ICMag is not affected as we have a version of ssl that is not compromised! - Skip

(CNN)
-- A major online security vulnerability dubbed "Heartbleed" could put your personal information at risk, including passwords, credit card information and e-mails.
Heartbleed is a flaw in OpenSSL, an open-source encryption technology that is used by an estimated two-thirds of Web servers. It is behind many HTTPS sites that collect personal or financial information. These sites are typically indicated by a lock icon in the browser to let site visitors know the information they're sending online is hidden from prying eyes.
Cybercriminals could exploit the bug to access visitors' personal data as well as a site's cryptographic keys, which can be used to impersonate that site and collect even more information.
It was discovered by a Google researcher and an independent Finnish security firm called Codenomicon. The researchers have put up a dedicated site to answer common questions about the bug. They even gave it an adorably gruesome custom icon.
Heartbleed is the result of a small coding error but it could have far-reaching consequences and affect the majority of Internet users.
Researchers discovered the issue last week and published their findings on Monday, but said the problem has been present for more than two years, since March 2012. Any communications that took place over SSL in the past two years could have been subject to malicious eavesdropping.
What makes the bug particularly problematic is that there is no simple fix. Action needs to be taken by both the compromised sites and individuals who have visited them.
To protect their user data and encryption keys, sites must upgrade to the patched version of OpenSSL, revoke compromised SSL certificates and get new ones issued.
Many major websites including Google, Facebook, Yahoo and Amazon have said they've taken steps to secure their sites. Security researchers demonstrated the flaw by stealing Yahoo e-mail logins on Tuesday morning, but Yahoo has since fixed the issue across its major sites, including Tumblr.
It's not just an issue for major sites. Smaller online stores and services use OpenSSL, and those sites might take longer to make the necessary fixes. Websites don't typically publicize whether they're using OpenSSL, so the process will also be bumpy for consumers.
Individuals should update their passwords across the various Web pages they use, but only once they have confirmed a site has already taken the proper measures to address Heartbleed. If they don't and that site is still at risk, the new password could also be compromised. Many sites will also likely send e-mails instructing customers to update passwords if necessary.
__________________
my gggeneration

DAV -

I can't decide which I like better: either, arguing on the internet is like winning in the Special Olympics, you might win but you're still retarded; or never argue with an idiot, they will drag you down to their level, and beat you with experience; or you can't fix stupid, so why argue with it? They all are funny, and all are true too.

"Well, da Nile ain't just some big river in Egypt neither."

"No reason to get excited," the thief, he kindly spoke,
"There are many here among us who feel that life is but a joke.
But you and I, we've been through that, and this is not our fate,
So let us not talk falsely now, the hour is getting late.
-
Bob Dylan: All Along the Watchtower


Rights aren’t rights if someone can take them away.
-George Carlin

"The fool thinks himself to be wise, but the wise Man knows himself to be a fool
"
-William Shakespeare


Long signatures suck.
-dddaver


Last edited by Skip; 04-11-2014 at 03:44 AM.. Reason: Added info about icmag not being affected.
dddaver is offline Quote


4 members found this post helpful.
Old 04-09-2014, 03:56 PM #2
sourpuss
Rainman

sourpuss's Avatar

Join Date: Aug 2013
Location: Ontario
Posts: 3,761
sourpuss is a splendid one to beholdsourpuss is a splendid one to beholdsourpuss is a splendid one to beholdsourpuss is a splendid one to beholdsourpuss is a splendid one to beholdsourpuss is a splendid one to beholdsourpuss is a splendid one to beholdsourpuss is a splendid one to beholdsourpuss is a splendid one to beholdsourpuss is a splendid one to beholdsourpuss is a splendid one to behold
Good to know...thx
sourpuss is offline Quote


Old 04-09-2014, 05:38 PM #3
Skip
Let's Get Small!

Skip's Avatar

Join Date: Jan 2004
Posts: 5,456
Skip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond repute
Quote:
Heartbleed is the result of a small coding error
Inserted by an agent of the NSA, no doubt.

The NSA alone has caused far more damage to our national security than all the hackers in the world. They've put backdoors on all the major software made in the USA. This is now seriously harming the business interests of the US Tech industry to the tune of $billions as companies foreign and domestic begin to switch from US software to that made elsewhere with more security.

Big Brother has fucked us over again.
__________________
"America's freedom lies in cannabis." - feltonmuggs

"Prohibition is the gateway to fascism." - Treewizard
Skip is offline Quote


5 members found this post helpful.
Old 04-10-2014, 01:24 AM #4
Dropped Cat
Six Gummi Bears and Some Scotch

Dropped Cat's Avatar

Join Date: Jan 2014
Posts: 2,615
Dropped Cat has a brilliant futureDropped Cat has a brilliant futureDropped Cat has a brilliant futureDropped Cat has a brilliant futureDropped Cat has a brilliant futureDropped Cat has a brilliant futureDropped Cat has a brilliant futureDropped Cat has a brilliant futureDropped Cat has a brilliant futureDropped Cat has a brilliant futureDropped Cat has a brilliant future
I can still download porn, though, right?

Silly innerwebs. Hope it doesn't stop my N*tflix or anything important.

I'll have to post that on my Facebo*k page now, so everyone knows.
__________________
"So we're just done with phrasing, right, that's not a thing anymore?."
Dropped Cat is offline Quote


Old 04-11-2014, 03:25 AM #5
Skip
Let's Get Small!

Skip's Avatar

Join Date: Jan 2004
Posts: 5,456
Skip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond repute
Facts about Heartbleed:
It's been active for the last two years in software used to secure the internet using ssl.

There is now a fix, and it's being implemented across the web as I write this.

GOOD NEWS! The version of ssl in use on our servers is not vulnerable to this bug!

It's a serious problem as it allows hackers to possibly access data being sent across the web.

It affected millions of websites and software by big companies like Cisco.

So to protect yourself you should change your passwords everywhere esp. if personal info is at stake
__________________
"America's freedom lies in cannabis." - feltonmuggs

"Prohibition is the gateway to fascism." - Treewizard

Last edited by Skip; 04-12-2014 at 05:38 PM..
Skip is offline Quote


1 members found this post helpful.
Old 04-11-2014, 05:55 PM #6
Skip
Let's Get Small!

Skip's Avatar

Join Date: Jan 2004
Posts: 5,456
Skip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond reputeSkip has a reputation beyond repute
I checked again with our hosting company and they've fixed all sites on their servers if they were at risk.

So Seedbay and Seedboutique are also OK to use and not affected
by heartbeat.

But you should still change passwords for your own piece of mind, esp. on other sites.
__________________
"America's freedom lies in cannabis." - feltonmuggs

"Prohibition is the gateway to fascism." - Treewizard
Skip is offline Quote


Old 04-11-2014, 09:54 PM #7
Wiggs Dannyboy
Last Laugh Foundation

Wiggs Dannyboy's Avatar

Join Date: Nov 2010
Location: Jitterbug Perfume
Posts: 2,695
Wiggs Dannyboy has disabled reputation
Here's a link that shows which websites were potentially a problem with this bug and which one's weren't. Just in case anybody wants to change their password.

https://mashable.com/2014/04/09/heart...ites-affected/
__________________
Want To Know How To Put Youtube Videos into your posts?

Click on the link below:

https://www.icmag.com/ic/showpost.ph...74&postcount=3
Wiggs Dannyboy is offline Quote


2 members found this post helpful.
Old 04-11-2014, 11:18 PM #8
Wiggs Dannyboy
Last Laugh Foundation

Wiggs Dannyboy's Avatar

Join Date: Nov 2010
Location: Jitterbug Perfume
Posts: 2,695
Wiggs Dannyboy has disabled reputation
Quote:
Originally Posted by Skip View Post
Inserted by an agent of the NSA, no doubt.

The NSA alone has caused far more damage to our national security than all the hackers in the world. They've put backdoors on all the major software made in the USA. This is now seriously harming the business interests of the US Tech industry to the tune of $billions as companies foreign and domestic begin to switch from US software to that made elsewhere with more security.

Big Brother has fucked us over again.
And...here's the latest:

https://www.huffingtonpost.com/2014/0...n_5134813.html

NSA Knew About And 'Exploited' Heartbleed For Years: Bloomberg


The Heartbleed bug just went from bad to worse to truly, utterly terrifying.

The National Security Agency knew of the existence of the catastrophic bug for at least two years and kept it a secret from the public and the cybersecurity community in order to exploit it, according to a bombshell report from Bloomberg News. However, the agency is denying the story.

While it's unclear what the agency was able to do with its knowledge of the exploit, we at least know this: If the report is true, the NSA knew about one of the most dangerous bugs in Internet history, and it did nothing to warn us about it.

"NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed vulnerability, until it was made public in a private-sector cybersecurity report," the NSA said in a statement circulated to reporters. "Reports that say otherwise are wrong." A White House spokesperson also stated that no federal agency was aware of the bug.

First discovered by Google and Codenomicon, a security firm, the Heartbleed bug is a flaw in the encryption used to protect vast number of websites from hackers. The fear is that the bug may expose credit card numbers, passwords and more.

Yahoo, Amazon and many, many other major websites used the free code, called OpenSSL, since encryption software is notoriously difficult to write.

Immediately after news of Heartbleed broke, some suspected that the NSA was exploiting the security lapse to access people's private data. Others saw it coming even before that: The documents leaked by former NSA contractor Edward Snowden indicated that the NSA partnered its British spying equivalent, the GCHQ, to try to crack SSL and other encryption standards that protect the Internet.
The two sources who spoke to Bloomberg are confirming those fears Friday.

Now that we know that the NSA knew about the bug, the question is how exactly they exploited it. Before this news broke, Wired reported that the bug might not be all that handy for the NSA. Heartbleed lets an attacker scoop up data from a website, but according to the story's author, Kim Zetter, "the data that’s returned is random — whatever is in the memory at the time — and requires an attacker to query multiple times to collect a lot of data."

The piece of the data that had security experts most worried -- the private SSL keys -- may be safe from the NSA's clutches. Theoretically, with a website's private key, a bad actor could steal information from a website months or years after the Heartbleed bug has been patched in its system. But after several tests, the online security company CloudFlare said it was unable to use Heartbleed to extract those keys. However, another researcher at Errata Security was much less sure about private keys being safe.
But the bits of data the agency was able to vacuum up with Heartbleed could be used in its many other data-gathering initiatives. "Putting the Heartbleed bug in its arsenal, the NSA was able to obtain passwords and other basic data that are the building blocks of the sophisticated hacking operations at the core of its mission," Bloomberg's Michael Riley wrote.
__________________
Want To Know How To Put Youtube Videos into your posts?

Click on the link below:

https://www.icmag.com/ic/showpost.ph...74&postcount=3
Wiggs Dannyboy is offline Quote


Old 04-12-2014, 01:26 AM #9
OGShaman
Guest

Posts: n/a
Quote


1 members found this post helpful.
Old 04-12-2014, 02:08 AM #10
siftedunity
cant re Member

siftedunity's Avatar

Join Date: Jul 2012
Location: away where the flowers grow
Posts: 3,322
siftedunity has much to be proud ofsiftedunity has much to be proud ofsiftedunity has much to be proud ofsiftedunity has much to be proud ofsiftedunity has much to be proud ofsiftedunity has much to be proud ofsiftedunity has much to be proud ofsiftedunity has much to be proud ofsiftedunity has much to be proud ofsiftedunity has much to be proud ofsiftedunity has much to be proud of
sounds like the millennium bug all over again.
siftedunity is offline Quote


Post Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


All times are GMT +2. The time now is 11:58 AM.


Click to visit Alchimia Grow Shop


This site is for educational and entertainment purposes only.
You must be of legal age to view ICmag and participate here.
All postings are the responsibility of their authors.
Powered by: vBulletin Copyright ©2000 - 2018, Jelsoft Enterprises Ltd.