Heartbleed: Serious OpenSSL zero day vulnerability revealed

Discussion in 'privacy technology' started by ronjor, Apr 7, 2014.

  1. Dermot7

    Dermot7 Registered Member

  2. Page42

    Page42 Registered Member

    Perhaps this has been answered. I missed it if it has.
    Can someone advise me why it is recommended to change your password on a site that is still affected by Heartbleed?
    It seems to me that the new credentials can be harvested in the same manner that the old ones were.
     
  3. SirDrexl

    SirDrexl Registered Member

    You change your password AFTER you find that it has been fixed.
     
  4. Page42

    Page42 Registered Member

    Yes, of course, that makes most sense. I asked because I thought I read somewhere to change them everywhere, regardless of status of the site.
    I tried looking for where I may have read that advice and gave up, figuring that I probably misread it.
    TY for your response, SirDrexl.
     
  5. siljaline

    siljaline Registered Member

  6. Minimalist

    Minimalist Registered Member

    Good advice :thumb:. I didn't start to change my passwords yet, but will surely use this trick when I get to it.

    hqsec
     
  7. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

  8. ronjor

    ronjor Global Moderator

    http://blogs.technet.com/b/security...and-the-openssl-heartbleed-vulnerability.aspx
     
  9. ronjor

    ronjor Global Moderator

  10. ronjor

    ronjor Global Moderator

  11. CloneRanger

    CloneRanger Registered Member

    iammike Said
    Makes sense now !

    emmjay Said
    Well that's going to be fun, NOT. Which is likely to mean, many will NOT get patched, EVER !
     
  12. Dermot7

    Dermot7 Registered Member

    By Graham Cluley:
    In the wake of Heartbleed, watch out for phishing attacks, disguised as password reset emails | HOTforSecurity
     
  13. siljaline

    siljaline Registered Member

  14. Dermot7

    Dermot7 Registered Member

  15. ronjor

    ronjor Global Moderator

  16. chachazz

    chachazz Updates Team

    Mozilla Security - Heartbleed Security Advisory
    ...continue reading.

    Concerning Sync ..."Neither the account server nor a potential attacker could have learned the password or the encryption key that protects Sync data."
     
  17. iammike

    iammike Registered Member

    The guy responsible for the Heartbleed bug "confessed" ;)

    -www.pcpro.co.uk/news/388162/heartbleed-coder-bug-in-openssl-was-an-honest-mistake-
     
    Last edited: Apr 11, 2014
  18. TairikuOkami

    TairikuOkami Registered Member

    Sure and everyone, who reviewed it missed it as well, why bother validating a variable, it is only SSL, just submit it?! Snowden anyone, ehm. :isay:
     
  19. lotuseclat79

    lotuseclat79 Registered Member

  20. iammike

    iammike Registered Member

    This thread has so many links that it will take days before I have read them all :thumb:
     
  21. Page42

    Page42 Registered Member

    I have not received a single request/instruction to change a password... valid or otherwise.
    Has anyone else?
     
  22. SirDrexl

    SirDrexl Registered Member

    Another thing I've been doing is, when I find that a site wasn't affected (like PayPal), I'll change something in the entry (like in the notes section) so KeePass registers it as changed. If you can't find anything you want to change, just delete a character, click OK and then type it in again; that will be enough for KeePass to give it a new modification time.
     
  23. Page42

    Page42 Registered Member

    Very smart.
     
  24. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    AirVPN has a major systems upgrade planned for Sunday:
     
  25. Minimalist

    Minimalist Registered Member

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice