Author Topic: Heartbleed Bug  (Read 3566 times)

Offline MoGro17

  • Dansdeals Platinum Elite
  • ****
  • Join Date: Apr 2013
  • Posts: 348
  • Total likes: 8
  • DansDeals.com Hat Tips 0
  • Gender: Male
    • View Profile
  • Location: Area 51
Heartbleed Bug
« on: April 10, 2014, 04:20:23 PM »
I'm wondering why there is no discussion from the techies here about the heartbleed bug. (I've seen some places call it a bug and others call it a virus.) Call it what you will, A LOT of websites used OpenSSL for encryption and it seems that the "secure" info has really been accessible to bad people all this time. 

Offline MoGro17

  • Dansdeals Platinum Elite
  • ****
  • Join Date: Apr 2013
  • Posts: 348
  • Total likes: 8
  • DansDeals.com Hat Tips 0
  • Gender: Male
    • View Profile
  • Location: Area 51
Re: Heartbleed Bug
« Reply #1 on: April 10, 2014, 04:25:42 PM »
This link kinda helps explain what happened and what it means.
p.s. also known as "heart bleed".

http://www.cnet.com/news/heartbleed-bug-undoes-web-encryption-reveals-user-passwords/

Also, This link takes you to the official, technical description of the bug.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160

Offline Achas Veachas

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Jul 2012
  • Posts: 4789
  • Total likes: 114
  • DansDeals.com Hat Tips 3
    • View Profile
    • Torah && Tech
Re: Heartbleed Bug
« Reply #2 on: April 11, 2014, 12:25:31 AM »

Offline DanH

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Oct 2011
  • Posts: 2181
  • Total likes: 26
  • DansDeals.com Hat Tips 2
    • View Profile
Re: Heartbleed Bug
« Reply #3 on: April 11, 2014, 01:37:49 AM »
For tech help feel free to Telegram me @DanTechSupp

Offline yitzf

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Mar 2011
  • Posts: 2634
  • Total likes: 53
  • DansDeals.com Hat Tips 4
    • View Profile

Offline yitzf

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Mar 2011
  • Posts: 2634
  • Total likes: 53
  • DansDeals.com Hat Tips 4
    • View Profile
Re: Heartbleed Bug
« Reply #5 on: April 11, 2014, 02:24:11 AM »
Explained very well in this video (8:30 min)



HT: Krebs

Offline AnonymousUser

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Feb 2013
  • Posts: 3002
  • Total likes: 13
  • DansDeals.com Hat Tips 0
    • View Profile
Re: Heartbleed Bug
« Reply #6 on: April 11, 2014, 09:35:07 AM »
Or a little shorter here: http://xkcd.com/1354/

Offline Achas Veachas

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Jul 2012
  • Posts: 4789
  • Total likes: 114
  • DansDeals.com Hat Tips 3
    • View Profile
    • Torah && Tech
Re: Heartbleed Bug
« Reply #7 on: April 11, 2014, 09:45:27 AM »

Offline MoGro17

  • Dansdeals Platinum Elite
  • ****
  • Join Date: Apr 2013
  • Posts: 348
  • Total likes: 8
  • DansDeals.com Hat Tips 0
  • Gender: Male
    • View Profile
  • Location: Area 51
Re: Heartbleed Bug
« Reply #8 on: April 11, 2014, 10:38:16 AM »
so we're all just sitting tight until we know that the leak has been sealed and then we change all our passwords and CC #s?

TOR says to stay away from the internet for a while, so....

Offline AnonymousUser

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Feb 2013
  • Posts: 3002
  • Total likes: 13
  • DansDeals.com Hat Tips 0
    • View Profile
Re: Heartbleed Bug
« Reply #9 on: April 11, 2014, 10:38:17 AM »
Beat me to it :)
LOL. What percentage of DDF do you think reads xkcd?

Offline MoGro17

  • Dansdeals Platinum Elite
  • ****
  • Join Date: Apr 2013
  • Posts: 348
  • Total likes: 8
  • DansDeals.com Hat Tips 0
  • Gender: Male
    • View Profile
  • Location: Area 51
Re: Heartbleed Bug
« Reply #10 on: April 11, 2014, 10:39:20 AM »
p.s. TOR = The Onion Router

Google it.

Offline AnonymousUser

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Feb 2013
  • Posts: 3002
  • Total likes: 13
  • DansDeals.com Hat Tips 0
    • View Profile
Re: Heartbleed Bug
« Reply #11 on: April 11, 2014, 10:57:58 AM »
so we're all just sitting tight until we know that the leak has been sealed and then we change all our passwords and CC #s?

TOR says to stay away from the internet for a while, so....
Take a look at this article: This List Reveals the Heartbleed-Affected Passwords to Change Now.

Here is an article written by one of the Wunderlist engineers about how they dealt with the issue. Highly technical, but interesting nonetheless.

Offline Achas Veachas

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Jul 2012
  • Posts: 4789
  • Total likes: 114
  • DansDeals.com Hat Tips 3
    • View Profile
    • Torah && Tech
Re: Heartbleed Bug
« Reply #12 on: April 11, 2014, 11:39:35 AM »
LOL. What percentage of DDF do you think reads xkcd?
There are a few, I'm really religious about it :P
But if you search you should find the big offenders...
« Last Edit: April 11, 2014, 11:52:18 AM by Achas Veachas »

Offline yitzf

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Mar 2011
  • Posts: 2634
  • Total likes: 53
  • DansDeals.com Hat Tips 4
    • View Profile
Re: Heartbleed Bug
« Reply #13 on: April 11, 2014, 12:25:45 PM »
If you have LastPass you can go to your vault and on the left side click on security check, and it will give you a list of your websites that are affected, and which ones you should change passwords now and which ones you should wait.

I only had six sites affected out of over 200.

Offline Moshe123

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Sep 2012
  • Posts: 6228
  • Total likes: 916
  • DansDeals.com Hat Tips 1
  • Gender: Male
    • View Profile
  • Location: Spring Valley
  • Programs: Lost
Re: Heartbleed Bug
« Reply #14 on: April 11, 2014, 03:09:33 PM »

Offline sky121

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: May 2011
  • Posts: 11724
  • Total likes: 168
  • DansDeals.com Hat Tips 12
    • View Profile
Re: Heartbleed Bug
« Reply #15 on: April 11, 2014, 05:08:16 PM »
Is there anything to do about it at the moment or are we all just waiting for a patch from Google?
"Not all who wander are lost"

Offline Joe4007

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Feb 2013
  • Posts: 4092
  • Total likes: 158
  • DansDeals.com Hat Tips 11
    • View Profile
  • Location: NY
Re: Heartbleed Bug
« Reply #16 on: April 11, 2014, 05:16:00 PM »
Is there anything to do about it at the moment or are we all just waiting for a patch from Google?
According to that list, Google already has a patch.

Offline sky121

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: May 2011
  • Posts: 11724
  • Total likes: 168
  • DansDeals.com Hat Tips 12
    • View Profile
Re: Heartbleed Bug
« Reply #17 on: April 11, 2014, 05:17:06 PM »
According to that list, Google already has a patch.

Sorry, I meant from Android. A patch for our phones.
"Not all who wander are lost"

Offline Joe4007

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Feb 2013
  • Posts: 4092
  • Total likes: 158
  • DansDeals.com Hat Tips 11
    • View Profile
  • Location: NY
Re: Heartbleed Bug
« Reply #18 on: April 11, 2014, 05:20:23 PM »
Sorry, I meant from Android. A patch for our phones.
Not sure I'm following. Where is your phone connected to via open SSL that you would need a patch?

Offline sky121

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: May 2011
  • Posts: 11724
  • Total likes: 168
  • DansDeals.com Hat Tips 12
    • View Profile
Re: Heartbleed Bug
« Reply #19 on: April 11, 2014, 05:20:52 PM »
It seems like many sites have patched their sites. How come they haven't recommended for their users to change their passwords?
 
"Not all who wander are lost"