Donate To Keep The Site Ad Free
Results 1 to 22 of 22

Thread: Heartbleed

  1. #1
    Oz the Gweat and Tewwible mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae's Avatar

    Join Date
    Oct 2007
    Location
    New Jersey
    Posts
    35,586
    Country
    Country Flag
    Gender
    Gender

    Default Heartbleed


  2. #2
    The Tenant Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean's Avatar

    Join Date
    May 2007
    Location
    Chinatown
    Posts
    28,087
    Country
    Country Flag

    Default

    oh good Lord

    thank you pablo! do you think the eBay and paypal passwords should be changed, too? not that bears have anything there, just wondering

    Ask not what bears can do for you, but what you can do for bears. (razz)
    When one is in agreement with bears one is always correct. (mae)

    bears are back!!!!!!!!!!!!!!!!!!!!!!

  3. #3
    Oz the Gweat and Tewwible mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae's Avatar

    Join Date
    Oct 2007
    Location
    New Jersey
    Posts
    35,586
    Country
    Country Flag
    Gender
    Gender

    Default

    To be safe, it wouldn't hurt. You just have to make sure the site has updated their SSL certificate to the new version.

  4. #4
    The Tenant Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean has a brilliant future Jean's Avatar

    Join Date
    May 2007
    Location
    Chinatown
    Posts
    28,087
    Country
    Country Flag

    Default

    oops... stupid bears didn't understand what you just said

    Ask not what bears can do for you, but what you can do for bears. (razz)
    When one is in agreement with bears one is always correct. (mae)

    bears are back!!!!!!!!!!!!!!!!!!!!!!

  5. #5
    Oz the Gweat and Tewwible mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae's Avatar

    Join Date
    Oct 2007
    Location
    New Jersey
    Posts
    35,586
    Country
    Country Flag
    Gender
    Gender

    Default

    Here's one article that explains it in some detail:

    http://www.thewire.com/technology/20...ternet/360366/
    Do you Yahoo? Do you use your Yahoo password on other sites? That password was possibly compromised by the security bug, and you'll have to change it once the bug is fixed. But because each system administrator has to manually fix the problem, which takes time, there's really nothing you can do until the compromised sites are up and running with an updated version of OpenSSL, and a new security certificate in place — a "reset" of the encryption used to protect current and archived information on the server going forward. Yahoo is working on a fix, but isn't there yet with all of its properties. Each site affected will have to do the same. Until then, stay away from those sites. It could take days, or longer, for vulnerable sites to recover from the bug.
    Basically, changing a password now for a site that hasn't fixed this is pointless.

  6. #6
    Rabid Billybumbler fearless-freak will become famous soon enough fearless-freak will become famous soon enough fearless-freak's Avatar

    Join Date
    Apr 2013
    Posts
    2,552
    Country
    Country Flag
    Gender
    Gender

    Default

    i heard about this last night and i imediatley changed my passwords for my e-mails
    <img src=http://www.gollancz.co.uk/wp-content/uploads/2013/02/GG_badge_LR1.jpg border=0 alt= />

  7. #7
    Rebel Heather19 has a reputation beyond repute Heather19 has a reputation beyond repute Heather19 has a reputation beyond repute Heather19 has a reputation beyond repute Heather19 has a reputation beyond repute Heather19 has a reputation beyond repute Heather19 has a reputation beyond repute Heather19 has a reputation beyond repute Heather19 has a reputation beyond repute Heather19 has a reputation beyond repute Heather19 has a reputation beyond repute Heather19's Avatar

    Join Date
    Oct 2007
    Posts
    14,995

    Default

    I just went and changed my yahoo password, was I too early?
    Only the gentle are ever really strong.

  8. #8
    Word Slinger Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent's Avatar

    Join Date
    May 2007
    Posts
    7,066

    Default

    If a site has not yet updated its OpenSSH, then changing your password right now actually makes you more vulnerable because your data is (albeit slightly) more likely to be in resident memory.

    This site is quite informative: http://mashable.com/2014/04/09/heart...ites-affected/

  9. #9
    Guardian of the Beam ELazansky is just really nice ELazansky is just really nice ELazansky is just really nice ELazansky is just really nice ELazansky is just really nice ELazansky's Avatar

    Join Date
    Dec 2009
    Posts
    3,014
    Country
    Country Flag
    Gender
    Gender

    Default

    My Yahoo password is unique to Yahoo, so I assume that I would be OK. I did change my Yahoo password to be safe.

  10. #10
    Word Slinger Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent's Avatar

    Join Date
    May 2007
    Posts
    7,066

    Default

    I wonder if this explains why so many people have had their Yahoo email accounts hijacked in recent months.

  11. #11
    Oz the Gweat and Tewwible mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae's Avatar

    Join Date
    Oct 2007
    Location
    New Jersey
    Posts
    35,586
    Country
    Country Flag
    Gender
    Gender

    Default

    Quote Originally Posted by ELazansky View Post
    My Yahoo password is unique to Yahoo, so I assume that I would be OK.
    You should never use the same password anywhere else. I can heartily (hehe) recommend using LastPass. It's free and awesome: http://blog.lastpass.com/2014/04/las...bleed-bug.html

  12. #12
    Roont jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic's Avatar

    Join Date
    May 2007
    Location
    Cleveland, Ohio
    Posts
    15,760
    My Mood
    Tired
    Country
    Country Flag

    Default

    How do you know if a site has fixed the problem?

    John

  13. #13
    Oz the Gweat and Tewwible mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae's Avatar

    Join Date
    Oct 2007
    Location
    New Jersey
    Posts
    35,586
    Country
    Country Flag
    Gender
    Gender

    Default

    Quote Originally Posted by jhanic View Post
    How do you know if a site has fixed the problem?

    John
    You can use an online checker like:

    It's not fool-proof, though. The site's SSL certificate has to be dated at least April 8, 2014, which is what these checks look for.

  14. #14
    Word Slinger Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent's Avatar

    Join Date
    May 2007
    Posts
    7,066

    Default

    Here's a testing site -- it's not a guarantee, but it's better than nothing: http://filippo.io/Heartbleed/

  15. #15
    Oz the Gweat and Tewwible mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae's Avatar

    Join Date
    Oct 2007
    Location
    New Jersey
    Posts
    35,586
    Country
    Country Flag
    Gender
    Gender

    Default

    Here's more info on which top sites were affected and have fixed the vulnerability and which steps should be taken next if necessary: http://www.cnet.com/how-to/which-sit...eartbleed-bug/

  16. #16
    Guardian of the Beam ELazansky is just really nice ELazansky is just really nice ELazansky is just really nice ELazansky is just really nice ELazansky is just really nice ELazansky's Avatar

    Join Date
    Dec 2009
    Posts
    3,014
    Country
    Country Flag
    Gender
    Gender

    Default

    Quote Originally Posted by pablo View Post
    Quote Originally Posted by ELazansky View Post
    My Yahoo password is unique to Yahoo, so I assume that I would be OK.
    You should never use the same password anywhere else. I can heartily (hehe) recommend using LastPass. It's free and awesome: http://blog.lastpass.com/2014/04/las...bleed-bug.html
    I do use LastPass. That's why my password for Yahoo is unique. All of my passwords are unique.

  17. #17
    Word Slinger Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent's Avatar

    Join Date
    May 2007
    Posts
    7,066

    Default

    LastPass was also affected by HeartBleed.

  18. #18
    Oz the Gweat and Tewwible mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae's Avatar

    Join Date
    Oct 2007
    Location
    New Jersey
    Posts
    35,586
    Country
    Country Flag
    Gender
    Gender

    Default

    Quote Originally Posted by Bev Vincent View Post
    LastPass was also affected by HeartBleed.
    Not really:

    http://blog.lastpass.com/2014/04/las...bleed-bug.html
    In summary, LastPass customers do not need to be concerned about their LastPass accounts. Though LastPass employs OpenSSL, we have multiple layers of encryption to protect our users and never have access to those encryption keys.
    It wouldn't be crazy to change your master password, though.

  19. #19
    Word Slinger Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent has a brilliant future Bev Vincent's Avatar

    Join Date
    May 2007
    Posts
    7,066

    Default

    Read farther down the page:

    LastPass utilizes OpenSSL for HTTPS/TLS/SSL encryption and we were therefore “vulnerable” to this bug. For anyone who was using this tool: http://filippo.io/Heartbleed/#lastpass.com to check whether LastPass was vulnerable, it would have shown that we were vulnerable until this morning, when we restarted our servers after the patched OpenSSL software update.

  20. #20
    Oz the Gweat and Tewwible mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae seldom gets put on hold mae's Avatar

    Join Date
    Oct 2007
    Location
    New Jersey
    Posts
    35,586
    Country
    Country Flag
    Gender
    Gender

    Default

    That's right, but LastPass doesn't hold the keys to your encrypted data, that always stays on your computer, which is why it's so cool and safe.

  21. #21
    Roont jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic has a brilliant future jhanic's Avatar

    Join Date
    May 2007
    Location
    Cleveland, Ohio
    Posts
    15,760
    My Mood
    Tired
    Country
    Country Flag

    Default

    Thanks everyone for the info!

    John

  22. #22
    Caution: eye irritant Jon has a reputation beyond repute Jon has a reputation beyond repute Jon has a reputation beyond repute Jon has a reputation beyond repute Jon has a reputation beyond repute Jon has a reputation beyond repute Jon has a reputation beyond repute Jon has a reputation beyond repute Jon has a reputation beyond repute Jon has a reputation beyond repute Jon has a reputation beyond repute Jon's Avatar

    Join Date
    May 2007
    Location
    Heaven and Hell
    Posts
    16,028
    My Mood
    Blah
    Country
    Country Flag
    Gender
    Gender

    Default

    I changed the password to my treehouse!
    All that's left of what we were is what we have become.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts