Page 1 of 1

Heartbleed Bug: Tech firms urge password reset

PostPosted: Thu Apr 10, 2014 1:30 pm
by RoboCop
Several tech firms are urging people to change all their passwords after the discovery of a major security flaw.

The Yahoo blogging platform Tumblr has advised the public to "change your passwords everywhere - especially your high-security services like email, file storage and banking".

Security advisers have given similar warnings about the Heartbleed Bug.

It follows news that a product used to safeguard data could be compromised to allow eavesdropping.

OpenSSL is a popular cryptographic library used to digitally scramble sensitive data as it passes to and from computer servers so that only the service provider and the intended recipients can make sense of it.


Continue reading the main story

Code: Select all
http://www.bbc.co.uk/news/technology-26954540

Re: Heartbleed Bug: Tech firms urge password reset

PostPosted: Fri Apr 11, 2014 7:13 am
by Kherr
I've been hearing a lot about this Heartbleed Bug recently. Just about every day I get an email from some provider of a number of services I use urging me to change my password. I just thought it was spam and/or phishing attempts. I'll do a little more digging on this issue and find out exactly what the issue is.


Also, a minor heads up - you don't want to change your passwords on affected sites UNTIL THEY UPDATE THEIR OpenSSL AND SECURE THEMSELVES! You can check sites on a site-to-site basis here:

Code: Select all
https://lastpass.com/heartbleed/


I tried pulling up data on us, but we were unable to have our SSL cert extracted...

Re: Heartbleed Bug: Tech firms urge password reset

PostPosted: Sat Apr 12, 2014 2:08 pm
by crustyasp46
heartbleed.jpeg
heartbleed.jpeg (8.07 KiB) Viewed 4618 times
Man Behind Heartbleed: It Was a 'Trivial' Mistake
Meanwhile, guy who found the bug donates reward

Code: Select all
http://www.newser.com/story/185178/man-behind-heartbleed-it-was-a-trivial-mistake.html

Re: Heartbleed Bug: Tech firms urge password reset

PostPosted: Mon Apr 14, 2014 3:35 pm
by Hot Trout
Just so that everyone knows. Our server was not using OpenSSL and was not effected by this bug. Good to know.