Heartbleed bug

Off Topic (Everything besides dubstep)
Forum rules
Please read and follow this sub-forum's specific rules listed HERE, as well as our sitewide rules listed HERE.

Link to the Secret Ninja Sessions community ustream channel - info in this thread
nitz
Posts: 3105
Joined: Fri Jan 09, 2009 5:28 pm

Heartbleed bug

Post by nitz » Wed Apr 09, 2014 10:09 pm

Flaw in open SSL - very huge apparently. I believed it when i got an email from SC saying for security reasons were logging everyone out, sign in with a new password.

This nicely produced website has all the details:

http://heartbleed.com

No details of bank details being robbed - yet..

"All good, dubstepforum.com seems fixed or unaffected!"
http://filippo.io/Heartbleed/#dubstepforum.com
A brand new song!

Soundcloud

User avatar
mks
Posts: 4155
Joined: Tue Apr 04, 2006 3:35 am
Location: Planet Earth

Re: Heartbleed bug

Post by mks » Wed Apr 09, 2014 10:21 pm

Anyone using Yahoo among many other sites, change your password.

titchbit
Posts: 3536
Joined: Sat May 11, 2013 8:16 pm
Location: levitating on bass weight

Re: Heartbleed bug

Post by titchbit » Thu Apr 10, 2014 4:53 pm

Any other sites besides soundcloud and yahoo being affected that we know?

Phigure
Posts: 14134
Joined: Fri May 28, 2010 5:55 am
Contact:

Re: Heartbleed bug

Post by Phigure » Thu Apr 10, 2014 5:22 pm

Basically every service that used OpenSSL (like 2/3 of the internet) and hasn't updated their systems with the fix

The worst thing about this exploit is that it doesn't really leave a trace so it's impossible to know if you've been affected. Also the exploit allows the private keys for SSL certificates to be stolen so all past SSL traffic can be decrypted
j_j wrote:^lol
Soundcloud | Twitter

User avatar
rockonin
Posts: 3515
Joined: Tue Oct 16, 2012 4:05 pm
Location: Buttoned Up

Re: Heartbleed bug

Post by rockonin » Thu Apr 10, 2014 5:24 pm

I'm using Norton 360 Identity safe login feature.
Image
https://soundcloud.com/rockonin
ehbes wrote:I'll remember that when City wins the league :W:

Phigure
Posts: 14134
Joined: Fri May 28, 2010 5:55 am
Contact:

Re: Heartbleed bug

Post by Phigure » Thu Apr 10, 2014 5:29 pm

I just googled what the fuck that even is and it turns out they use SSL too :t:

Change your passwords to be on the safe side
j_j wrote:^lol
Soundcloud | Twitter

User avatar
mks
Posts: 4155
Joined: Tue Apr 04, 2006 3:35 am
Location: Planet Earth

Re: Heartbleed bug

Post by mks » Thu Apr 10, 2014 5:57 pm

Flickr and Imgur accounts were compromised. Tumblr has patched their servers but you need to update your passwords on any accounts that you have on these sites.

https://en.wikipedia.org/wiki/Heartbleed_bug

nitz
Posts: 3105
Joined: Fri Jan 09, 2009 5:28 pm

Re: Heartbleed bug

Post by nitz » Thu Apr 10, 2014 7:01 pm

"FBI"


the ironic
A brand new song!

Soundcloud

User avatar
_ronzlo_
Posts: 1006
Joined: Wed Mar 19, 2014 7:29 pm

Re: Heartbleed bug

Post by _ronzlo_ » Thu Apr 10, 2014 7:31 pm


User avatar
m8son666
moist
Posts: 6580
Joined: Sun Sep 15, 2013 6:36 pm
Location: MODERATOR
Contact:

Re: Heartbleed bug

Post by m8son666 » Thu Apr 10, 2014 7:32 pm

god forbid someone hacks my dsf account
Soundcloud
kay wrote:We kept pointing at his back and (quietly) telling people "That's M8son...."
wolf89 wrote:I really don't think I'm a music snob.

User avatar
AxeD
Posts: 9361
Joined: Tue Oct 20, 2009 10:10 pm
Location: Damstarem

Re: Heartbleed bug

Post by AxeD » Thu Apr 10, 2014 7:39 pm

Yeah, so the important stuff is not protected with this crap right?
I use 4 different passwords now anyways.
Agent 47 wrote:Next time I can think of something, I will.

User avatar
Jizz
Posts: 3470
Joined: Mon Aug 30, 2010 4:43 pm
Location: London

Re: Heartbleed bug

Post by Jizz » Thu Apr 10, 2014 7:52 pm

urr Soundcloud's not letting me change my password, apparently its a "bad gateway 502"

User avatar
Forum
Posts: 10686
Joined: Sat Dec 15, 2007 1:55 am
Location: J R Hartley

Re: Heartbleed bug

Post by Forum » Thu Apr 10, 2014 8:08 pm

What about things like amazon, paypal, o2 that have my bank details?

I'll never remember a whole load of new passwords
Image Image

User avatar
m8son666
moist
Posts: 6580
Joined: Sun Sep 15, 2013 6:36 pm
Location: MODERATOR
Contact:

Re: Heartbleed bug

Post by m8son666 » Thu Apr 10, 2014 8:09 pm

meh as always i am apathetic about this i have the same password for everything and can't be arsed to change them

inb4 all my money gets taken
Soundcloud
kay wrote:We kept pointing at his back and (quietly) telling people "That's M8son...."
wolf89 wrote:I really don't think I'm a music snob.

Phigure
Posts: 14134
Joined: Fri May 28, 2010 5:55 am
Contact:

Re: Heartbleed bug

Post by Phigure » Thu Apr 10, 2014 8:29 pm

southstar wrote:What about things like amazon, paypal, o2 that have my bank details?

I'll never remember a whole load of new passwords
if you used the same password on a site that was compromised, then attackers can try to use that username/email and password pair on other sites like amazon, paypal, etc, so yeah i'd probably change passwords

the odds are probably pretty low but it cant hurt to be safe

edit:
AxeD wrote:Yeah, so the important stuff is not protected with this crap right?
nope. basically any "secure" site uses ssl (if you see https in the url and/or the little padlock in the address bar, it's using ssl), and openssl specifically is the default implementation on apache and nginx servers (which are 2/3 of servers)
Last edited by Phigure on Thu Apr 10, 2014 8:49 pm, edited 2 times in total.
j_j wrote:^lol
Soundcloud | Twitter

User avatar
_ronzlo_
Posts: 1006
Joined: Wed Mar 19, 2014 7:29 pm

Re: Heartbleed bug

Post by _ronzlo_ » Thu Apr 10, 2014 8:37 pm

So if you use the same passwords for porn as you do for banking...

:oops:


:cornlol:
nowaysj wrote: ...But the chick's panties that you drop with a keytar, marry that B.


hifi
Posts: 3328
Joined: Sun Apr 04, 2010 6:54 am

Re: Heartbleed bug

Post by hifi » Thu Apr 10, 2014 9:36 pm

what i do is i just add an extra number so: password, password1, password2, etc hacker would never guess to add that extra #

Phigure
Posts: 14134
Joined: Fri May 28, 2010 5:55 am
Contact:

Re: Heartbleed bug

Post by Phigure » Thu Apr 10, 2014 9:51 pm

except that its not a dude sitting at a computer screen typing in your password, anyone competent enough to be doing this sort of attack is going to have code thatll try permutations of your password (capitalize certain letters, add numbers to the end, etc)
j_j wrote:^lol
Soundcloud | Twitter

nousd
Posts: 8654
Joined: Tue Oct 16, 2007 2:22 am
Location: approaching the flux pavillion

Re: Heartbleed bug

Post by nousd » Thu Apr 10, 2014 10:07 pm

seriously
wouldn't a smart bug track attempted password changes?

btw, thought this thread was about the ebola outbreak
(which could be way more serious)
{*}

User avatar
_ronzlo_
Posts: 1006
Joined: Wed Mar 19, 2014 7:29 pm

Re: Heartbleed bug

Post by _ronzlo_ » Thu Apr 10, 2014 10:22 pm

Right, except this isn't a case of a single or handful of possibly unsafe entities sneakily trying to crack your system in realtime:

rather, this means that although no massive breaches have been reported yet, every single site employing the compromised outdated protocols has its backdoor essentially unlocked for anyone inclined to do so, and if any of them were to be compromised, they can have a go at anything cached on your system (passwords, $$$ info, yadda) very easily. Those security certificates you get from trusted sites mean less than nothing in this scenario.
nowaysj wrote: ...But the chick's panties that you drop with a keytar, marry that B.


Locked

Who is online

Users browsing this forum: No registered users and 0 guests