Heartbleed bug - everyone knows everything
‹ Previous12
  • Blue Swirl
    Show networks
    Facebook
    Fuck Mugtome
    Twitter
    BlueSwirl
    Xbox
    Blue5wirl
    PSN
    BlueSwirl
    Steam
    BlueSwirl
    Wii
    3DS: 0602-6557-8477, Wii U: BlueSwirl

    Send message
    OK, so there's a flaw in some versions of something called OpenSSL.

    A brief summary, as I've managed to glean from the website above (published by the security group that found the flaw) and my IT professional mates.

    1) This is not a 'man in the middle' attack, like the Apple 'goto fail' security hole a while ago. The attacker can get hold of your information whether you're online or not.
    2) This is a server side problem, so there's nothing you can do to secure your information.
    3) This includes changing passwords. If you change your password and the website in question hasn't fixed their OpenSSL, then the attackers know your new password, too.
    4) This is limited to Linux and BSD operating systems. But given that it's a server problem, and lots of servers use the Unix-like operating systems, then chances are...
    5) Pretty much anything you do online is vulnerable.

    The silver lining is that this has been discovered and can be fixed, so in future, the bad guys can't use it. Not much consolation now, but, er, yeah...

    UPDATES

    Goober found a list that shows which sites are vulnerable and which aren't. Remember, changing your password on the sites effected won't do anything until they fix their OpenSSL. But if you use the same password across multiple sites, including uncompromised places, then it might be worth changing those.
    This might help https://github.com/musalbas/heartbleed-masstest/blob/master/top1000.txt
    Spoiler:

    The EFF have put together some hints and tips for sys admins and web admins.

    For sys admins
    For web admins

    Second article also states that if you've been using HTTPSEverywhere with Firefox or Chrome, you have had an extra layer of protection. (But you're not immune!)

    Elmlea posted it, and it's pretty handy for understanding what's going on. XKCD explains the heartbleed bug:

    heartbleed_explanation.png
    For those with an open mind, wonders always await! - Kilton (monster enthusiast)
  • Blue Swirl
    Show networks
    Facebook
    Fuck Mugtome
    Twitter
    BlueSwirl
    Xbox
    Blue5wirl
    PSN
    BlueSwirl
    Steam
    BlueSwirl
    Wii
    3DS: 0602-6557-8477, Wii U: BlueSwirl

    Send message
    Woops, I also didn't meant to post this to the Games section. Er,  feel free to move this, Powers That Be. EDIT: Moved it me self. Ta, Face.

    Also, a quick update:

    A fix is available, it's now just up to websites to apply it. Keep an eye on your favourite websites news section and then change your password when the fix is applied.
    For those with an open mind, wonders always await! - Kilton (monster enthusiast)
  • FYI: You can edit OP and move it yourself.
    I'm still great and you still love it.
  • Also, yes, big news. I will be going through passwords this week. Thankfully, most services I use have already emailed saying they've patched and done some stuff, still. it's been sitting there for a while, undetected. A worry.
    I'm still great and you still love it.
  • GooberTheHat
    Show networks
    Twitter
    GooberTheHat
    Xbox
    GooberTheHat
    Steam
    GooberTheHat

    Send message
    I am going to have to change my password system now. Bloody stupid internet people.
  • Blue Swirl
    Show networks
    Facebook
    Fuck Mugtome
    Twitter
    BlueSwirl
    Xbox
    Blue5wirl
    PSN
    BlueSwirl
    Steam
    BlueSwirl
    Wii
    3DS: 0602-6557-8477, Wii U: BlueSwirl

    Send message
    Yeah, I've changed my internet banking stuff, just in case, but I'm not going to do the rest until there's more updates that things have been fixed. AFAIK your password, new or old, is public information until things are sorted.
    Facewon wrote:
    FYI: You can edit OP and move it yourself.

    Cheers much, will do that now.
    For those with an open mind, wonders always await! - Kilton (monster enthusiast)
  • Paul the sparky
    Show networks
    Xbox
    Paul the sparky
    PSN
    Neon_Sparks
    Steam
    Paul_the_sparky

    Send message
    If there's one thing I fucking hate about internetting it's having a password for everything. What are the odds of me being e-mugged if I stupidly don't bother changing them?
  • How do I know that's really Swirl posting, and not a hacker who has taken over his account?

    TRUST NO ONE
  • What would happen in the future if your password was retina data or fingerprints. YOU CAN'T CHANGE YOUR EYES OR FINGERS.
  • What would happen in the future if your password was retina data or fingerprints. YOU CAN'T CHANGE YOUR EYES OR FINGERS.

    Yeah but someone can cut them off and use them on scanners.
    "Sometimes it's better to light a flamethrower than curse the darkness." ― Terry Pratchett
  • GooberTheHat
    Show networks
    Twitter
    GooberTheHat
    Xbox
    GooberTheHat
    Steam
    GooberTheHat

    Send message
    As long as someone can get at the raw data any password system is vulnerable.

    What we need is double encrypted direct neural interfaces.
  • Or quantum entangled carrier pigeons.

    "Oooooo oooooo, I'm over here, fuckface"

    Zap.

    "Sucker"
    "Sometimes it's better to light a flamethrower than curse the darkness." ― Terry Pratchett
  • Skerret
    Show networks
    Facebook
    die
    Twitter
    @CustomCosy
    Xbox
    Skerret
    PSN
    Skerret
    Steam
    Skerret
    Wii
    get tae

    Send message
    Checked affected sites, I'm safe.  Good, hate changing passwords outside my usual password changing cycle.
    Skerret's posting is ok to trip balls to and read just to experience the ambience but don't expect any content.
    "I'm jealous of sucking major dick!"~ Kernowgaz
  • GooberTheHat
    Show networks
    Twitter
    GooberTheHat
    Xbox
    GooberTheHat
    Steam
    GooberTheHat

    Send message
    Is that the same as mine.

    When you forget them?
  • Skerret
    Show networks
    Facebook
    die
    Twitter
    @CustomCosy
    Xbox
    Skerret
    PSN
    Skerret
    Steam
    Skerret
    Wii
    get tae

    Send message
    Forget what?
    Skerret's posting is ok to trip balls to and read just to experience the ambience but don't expect any content.
    "I'm jealous of sucking major dick!"~ Kernowgaz
  • I got that 1Password thing a little while back - guess it's time to actually go through the main sites and use it's "auto-gen password" thingy.
  • GooberTheHat
    Show networks
    Twitter
    GooberTheHat
    Xbox
    GooberTheHat
    Steam
    GooberTheHat

    Send message
    Skerret wrote:
    Forget what?
    The man with the power.
  • Blue Swirl
    Show networks
    Facebook
    Fuck Mugtome
    Twitter
    BlueSwirl
    Xbox
    Blue5wirl
    PSN
    BlueSwirl
    Steam
    BlueSwirl
    Wii
    3DS: 0602-6557-8477, Wii U: BlueSwirl

    Send message
    If there's one thing I fucking hate about internetting it's having a password for everything. What are the odds of me being e-mugged if I stupidly don't bother changing them?

    At the moment, as far as I know, exactly the same as if you didn't change your passwords. I've changed my online banking stuff, but I'm probably pissing into the wind.

    One of my IT mates says that the problem lies in OpenSSL 1.0.1, while many sites run 0.9.8. Ironically, only places that have had to update due to other security problems are vulnerable. A lot of places are (according to me mate, innit) still using 0.9.8.

    Tl;dr - We're pretty fucked, even if you do change your password, because we can't tell on our end which OpenSSL version each website we visit is using.
    WorKid wrote:
    How do I know that's really Swirl posting, and not a hacker who has taken over his account? TRUST NO ONE

    drEvil.gif
    For those with an open mind, wonders always await! - Kilton (monster enthusiast)
  • GooberTheHat
    Show networks
    Twitter
    GooberTheHat
    Xbox
    GooberTheHat
    Steam
    GooberTheHat

    Send message
    This might help
    https://github.com/musalbas/heartbleed-masstest/blob/master/top1000.txt
    Spoiler:
  • Skerret
    Show networks
    Facebook
    die
    Twitter
    @CustomCosy
    Xbox
    Skerret
    PSN
    Skerret
    Steam
    Skerret
    Wii
    get tae

    Send message
    Skerret wrote:
    Forget what?
    The man with the power.
     
    What power?
    Lord_Griff wrote:
    Who do I sue?
    Sue who?
    Skerret's posting is ok to trip balls to and read just to experience the ambience but don't expect any content.
    "I'm jealous of sucking major dick!"~ Kernowgaz
  • GooberTheHat
    Show networks
    Twitter
    GooberTheHat
    Xbox
    GooberTheHat
    Steam
    GooberTheHat

    Send message
    The power of the voodoo
  • Skerret
    Show networks
    Facebook
    die
    Twitter
    @CustomCosy
    Xbox
    Skerret
    PSN
    Skerret
    Steam
    Skerret
    Wii
    get tae

    Send message
    I though the suing bit replaced that part.  But anyway...

    Who do?
    Skerret's posting is ok to trip balls to and read just to experience the ambience but don't expect any content.
    "I'm jealous of sucking major dick!"~ Kernowgaz
  • GooberTheHat
    Show networks
    Twitter
    GooberTheHat
    Xbox
    GooberTheHat
    Steam
    GooberTheHat

    Send message
    What are you talking about?
  • That's not how that song goes.
  • GooberTheHat
    Show networks
    Twitter
    GooberTheHat
    Xbox
    GooberTheHat
    Steam
    GooberTheHat

    Send message
    What song?
  • You know the one. It goes 

    Bowwww-bow, bow 
    bow bah bah bah bah bup bup
  • GooberTheHat
    Show networks
    Twitter
    GooberTheHat
    Xbox
    GooberTheHat
    Steam
    GooberTheHat

    Send message
    Bup bup bup bup badha bup bup badow?
  • A quick look through that list suggests I'm fine.
  • Nah, it goes do wah diddy diddy dum diddy do.
  • Skerret
    Show networks
    Facebook
    die
    Twitter
    @CustomCosy
    Xbox
    Skerret
    PSN
    Skerret
    Steam
    Skerret
    Wii
    get tae

    Send message
    What are you talking about?
    There's nothing to talk about!
    Skerret's posting is ok to trip balls to and read just to experience the ambience but don't expect any content.
    "I'm jealous of sucking major dick!"~ Kernowgaz
‹ Previous12

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!