Forum Discussion

sue_t's avatar
sue_t
Explorer
Apr 09, 2014

Heartbleed bug - has your internet security been affected?

Quoting: On the scale of 1 to 10, this is an 11.

Further quoting, "The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop communications, steal data directly from the services and users and to impersonate services and users."

Learn more:

http://www.businessinsider.com/heartbleed-bug-explainer-2014-4

https://www.schneier.com/blog/archives/2014/04/heartbleed.html

http://arstechnica.com/security/2014/04/critical-crypto-bug-exposes-yahoo-mail-passwords-russian-roulette-style/


  • You know this Bug has been out there for 2 years now. We are just hearing about it.
  • bwanshoom wrote:


    (And rv.net was not impacted since their web server is Windows.)



    As Larry the cable guy would say, That There's funny I don't care who you are.
  • Luckily, the US government sites rarely use SSL so it's a non-issue for them. :R
  • The Canada Revenue Agency has this notice on its site:

    To protect the security of taxpayer information, we have temporarily shutdown public access to our electronic services. We are working to restore these services as soon as possible in a manner that ensures they are safe and secure. For more information, please consult our homepage.
  • It's unlikely that the private keys of servers will have leaked (the "secret keys used to identify the service providers and to encrypt the traffic" from the quote above.) But other information is definitely at risk and given that this issue has been in place for over 2 years there's no telling who knew about it and what they were able to harvest.

    I would expect to see a lot of sites forcing users to reset their passwords in the coming days/weeks as a precaution.

    (And rv.net was not impacted since their web server is Windows.)

About RV Must Haves

Have a product you cannot live without? Share it with the community!8,793 PostsLatest Activity: Aug 22, 2023