The Glade 4.0 https://gladerebooted.net/ |
|
OpenSSL vulnerability - Heartbleed https://gladerebooted.net/viewtopic.php?f=5&t=10873 |
Page 1 of 1 |
Author: | Mookhow [ Fri Apr 11, 2014 1:17 pm ] |
Post subject: | OpenSSL vulnerability - Heartbleed |
What is it? Heartbleed is a vulnerability in recent (2012-2014) versions of the OpenSSL library that allows malicious attackers to steal data from webservers. See this XKCD comic for details: Spoiler: Is the Glade affected? No. If the website doesn't use https, then it's not affected. If the website doesn't use OpenSSL, it's not affected. If the version of OpenSSL is before early 2012, it's not affected. What should I do if I think I'm compromised? If a website does have a vulnerable version of OpenSSL, hopefully they've updated their software by now to a fixed version. If so, changing your password is your best course of action. If they haven't, don't go to the website until they do. That's all I got for now. I'm sure others can add more info and discourse. |
Author: | Lenas [ Fri Apr 11, 2014 1:30 pm ] |
Post subject: | Re: OpenSSL vulnerability - Heartbleed |
Don't change your password for a particular website until that website has said that they've patched the exploit. Otherwise you'll just have to change it again afterwards. |
Author: | TheRiov [ Fri Apr 11, 2014 3:00 pm ] |
Post subject: | |
More than that, if you use the same password/login for a number of sites, and you change them all when even one is still pre-patch, you risk exposing that username/password combo, compromising all sites. Only change the passwords for sites known to be unaffected (If it shared a username/password with other sites that were) or sites that are now patched. https://lastpass.com/heartbleed/ Does some checking -- if anyone knows a better check site, pass it on. I believe Chrome has an extension published somewhere that will warn you if you're at a heartbleed vulnerable site, as well. |
Author: | Müs [ Fri Apr 11, 2014 6:48 pm ] |
Post subject: | |
Author: | Kaffis Mark V [ Sat Apr 12, 2014 8:22 am ] |
Post subject: | |
You mean the thing Mookhow posted in the spoiler of the OP, Müs? |
Author: | Müs [ Mon Apr 14, 2014 1:56 pm ] |
Post subject: | |
Shush you. :p |
Page 1 of 1 | All times are UTC - 6 hours [ DST ] |
Powered by phpBB® Forum Software © phpBB Group https://www.phpbb.com/ |