Heartbleed: Serious OpenSSL zero day vulnerability revealed

Discussion in 'privacy technology' started by ronjor, Apr 7, 2014.

  1. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
  2. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    Perhaps this has been answered. I missed it if it has.
    Can someone advise me why it is recommended to change your password on a site that is still affected by Heartbleed?
    It seems to me that the new credentials can be harvested in the same manner that the old ones were.
     
  3. SirDrexl

    SirDrexl Registered Member

    Joined:
    Apr 14, 2012
    Posts:
    556
    Location:
    USA
    You change your password AFTER you find that it has been fixed.
     
  4. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    Yes, of course, that makes most sense. I asked because I thought I read somewhere to change them everywhere, regardless of status of the site.
    I tried looking for where I may have read that advice and gave up, figuring that I probably misread it.
    TY for your response, SirDrexl.
     
  5. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,618
  6. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Good advice :thumb:. I didn't start to change my passwords yet, but will surely use this trick when I get to it.

    hqsec
     
  7. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
  8. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,883
    Location:
    Texas
    http://blogs.technet.com/b/security...and-the-openssl-heartbleed-vulnerability.aspx
     
  9. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,883
    Location:
    Texas
  10. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,883
    Location:
    Texas
  11. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    iammike Said
    Makes sense now !

    emmjay Said
    Well that's going to be fun, NOT. Which is likely to mean, many will NOT get patched, EVER !
     
  12. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
    By Graham Cluley:
    In the wake of Heartbleed, watch out for phishing attacks, disguised as password reset emails | HOTforSecurity
     
  13. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,618
  14. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
  15. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,883
    Location:
    Texas
  16. chachazz

    chachazz Updates Team

    Joined:
    Apr 23, 2004
    Posts:
    841
    Mozilla Security - Heartbleed Security Advisory
    ...continue reading.

    Concerning Sync ..."Neither the account server nor a potential attacker could have learned the password or the encryption key that protects Sync data."
     
  17. iammike

    iammike Registered Member

    Joined:
    Jun 13, 2012
    Posts:
    345
    Location:
    SE Asia
    The guy responsible for the Heartbleed bug "confessed" ;)

    -www.pcpro.co.uk/news/388162/heartbleed-coder-bug-in-openssl-was-an-honest-mistake-
     
    Last edited: Apr 11, 2014
  18. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,432
    Location:
    Slovakia
    Sure and everyone, who reviewed it missed it as well, why bother validating a variable, it is only SSL, just submit it?! Snowden anyone, ehm. :isay:
     
  19. lotuseclat79

    lotuseclat79 Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    5,390
  20. iammike

    iammike Registered Member

    Joined:
    Jun 13, 2012
    Posts:
    345
    Location:
    SE Asia
    This thread has so many links that it will take days before I have read them all :thumb:
     
  21. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    I have not received a single request/instruction to change a password... valid or otherwise.
    Has anyone else?
     
  22. SirDrexl

    SirDrexl Registered Member

    Joined:
    Apr 14, 2012
    Posts:
    556
    Location:
    USA
    Another thing I've been doing is, when I find that a site wasn't affected (like PayPal), I'll change something in the entry (like in the notes section) so KeePass registers it as changed. If you can't find anything you want to change, just delete a character, click OK and then type it in again; that will be enough for KeePass to give it a new modification time.
     
  23. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    Very smart.
     
  24. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    AirVPN has a major systems upgrade planned for Sunday:
     
  25. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.