Heartbleed bug
Forum rules
Please read and follow this sub-forum's specific rules listed HERE, as well as our sitewide rules listed HERE.
Link to the Secret Ninja Sessions community ustream channel - info in this thread
Please read and follow this sub-forum's specific rules listed HERE, as well as our sitewide rules listed HERE.
Link to the Secret Ninja Sessions community ustream channel - info in this thread
Heartbleed bug
Flaw in open SSL - very huge apparently. I believed it when i got an email from SC saying for security reasons were logging everyone out, sign in with a new password.
This nicely produced website has all the details:
http://heartbleed.com
No details of bank details being robbed - yet..
"All good, dubstepforum.com seems fixed or unaffected!"
http://filippo.io/Heartbleed/#dubstepforum.com
This nicely produced website has all the details:
http://heartbleed.com
No details of bank details being robbed - yet..
"All good, dubstepforum.com seems fixed or unaffected!"
http://filippo.io/Heartbleed/#dubstepforum.com
Re: Heartbleed bug
Anyone using Yahoo among many other sites, change your password.
Re: Heartbleed bug
Any other sites besides soundcloud and yahoo being affected that we know?
Re: Heartbleed bug
Basically every service that used OpenSSL (like 2/3 of the internet) and hasn't updated their systems with the fix
The worst thing about this exploit is that it doesn't really leave a trace so it's impossible to know if you've been affected. Also the exploit allows the private keys for SSL certificates to be stolen so all past SSL traffic can be decrypted
The worst thing about this exploit is that it doesn't really leave a trace so it's impossible to know if you've been affected. Also the exploit allows the private keys for SSL certificates to be stolen so all past SSL traffic can be decrypted
Re: Heartbleed bug
I'm using Norton 360 Identity safe login feature.
Re: Heartbleed bug
I just googled what the fuck that even is and it turns out they use SSL too
Change your passwords to be on the safe side
Change your passwords to be on the safe side
Re: Heartbleed bug
Flickr and Imgur accounts were compromised. Tumblr has patched their servers but you need to update your passwords on any accounts that you have on these sites.
https://en.wikipedia.org/wiki/Heartbleed_bug
https://en.wikipedia.org/wiki/Heartbleed_bug
Re: Heartbleed bug
god forbid someone hacks my dsf account
Soundcloud
kay wrote:We kept pointing at his back and (quietly) telling people "That's M8son...."
wolf89 wrote:I really don't think I'm a music snob.
Re: Heartbleed bug
Yeah, so the important stuff is not protected with this crap right?
I use 4 different passwords now anyways.
I use 4 different passwords now anyways.
Agent 47 wrote:Next time I can think of something, I will.
Re: Heartbleed bug
What about things like amazon, paypal, o2 that have my bank details?
I'll never remember a whole load of new passwords
I'll never remember a whole load of new passwords

Re: Heartbleed bug
meh as always i am apathetic about this i have the same password for everything and can't be arsed to change them
inb4 all my money gets taken
inb4 all my money gets taken
Soundcloud
kay wrote:We kept pointing at his back and (quietly) telling people "That's M8son...."
wolf89 wrote:I really don't think I'm a music snob.
Re: Heartbleed bug
if you used the same password on a site that was compromised, then attackers can try to use that username/email and password pair on other sites like amazon, paypal, etc, so yeah i'd probably change passwordssouthstar wrote:What about things like amazon, paypal, o2 that have my bank details?
I'll never remember a whole load of new passwords
the odds are probably pretty low but it cant hurt to be safe
edit:
nope. basically any "secure" site uses ssl (if you see https in the url and/or the little padlock in the address bar, it's using ssl), and openssl specifically is the default implementation on apache and nginx servers (which are 2/3 of servers)AxeD wrote:Yeah, so the important stuff is not protected with this crap right?
Last edited by Phigure on Thu Apr 10, 2014 8:49 pm, edited 2 times in total.
Re: Heartbleed bug
So if you use the same passwords for porn as you do for banking...

nowaysj wrote: ...But the chick's panties that you drop with a keytar, marry that B.
Re: Heartbleed bug
what i do is i just add an extra number so: password, password1, password2, etc hacker would never guess to add that extra #
Re: Heartbleed bug
except that its not a dude sitting at a computer screen typing in your password, anyone competent enough to be doing this sort of attack is going to have code thatll try permutations of your password (capitalize certain letters, add numbers to the end, etc)
Re: Heartbleed bug
seriously
wouldn't a smart bug track attempted password changes?
btw, thought this thread was about the ebola outbreak
(which could be way more serious)
wouldn't a smart bug track attempted password changes?
btw, thought this thread was about the ebola outbreak
(which could be way more serious)
{*}
Re: Heartbleed bug
Right, except this isn't a case of a single or handful of possibly unsafe entities sneakily trying to crack your system in realtime:
rather, this means that although no massive breaches have been reported yet, every single site employing the compromised outdated protocols has its backdoor essentially unlocked for anyone inclined to do so, and if any of them were to be compromised, they can have a go at anything cached on your system (passwords, $$$ info, yadda) very easily. Those security certificates you get from trusted sites mean less than nothing in this scenario.
rather, this means that although no massive breaches have been reported yet, every single site employing the compromised outdated protocols has its backdoor essentially unlocked for anyone inclined to do so, and if any of them were to be compromised, they can have a go at anything cached on your system (passwords, $$$ info, yadda) very easily. Those security certificates you get from trusted sites mean less than nothing in this scenario.
nowaysj wrote: ...But the chick's panties that you drop with a keytar, marry that B.
Who is online
Users browsing this forum: No registered users and 0 guests
