Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Heartbleed: How the Net Bug That Caught Tech Experts by Surprise Affects You
The Blaze ^ | 4-9-14 | Elizabeth Kreft

Posted on 04/09/2014 3:00:05 PM PDT by kingattax

This week web experts discovered a huge flaw in the security software used by millions of Web sites — including many banks, email and social media services. Some sites have likened the breach to leaving your front door unlocked, and anyone who knows how to open the door can intrude and expose your confidential information.

Unfortunately, the fix isn’t as simple as locking the door from inside your house. The code vulnerability exists within layers of secure Internet server coding.

So how does this affect you?

* This week web experts discovered a huge flaw in the security software used by millions of Web sites — including many banks, e-mail and social media services.

* While it is a serious concern for all web users, individual Internet users cannot take direct steps to fix the bug; it exists on Internet servers

* If a site you use is still vulnerable, any hacker who understands how to exploit the weakness will have access to names and passwords, email and message content — truly any data shared over the supposedly secure connection.

* This does not mean your information has already been affected or stolen, but it does mean your personal information is vulnerable to theft until the code fix is applied to each affected server.

(Excerpt) Read more at theblaze.com ...


TOPICS: News/Current Events
KEYWORDS: heartbleed; malware; openssl
Navigation: use the links below to view more comments.
first 1-2021-33 next last

1 posted on 04/09/2014 3:00:05 PM PDT by kingattax
[ Post Reply | Private Reply | View Replies]

To: kingattax

Drive down and talk to your local, cute Teller.


2 posted on 04/09/2014 3:01:55 PM PDT by Paladin2
[ Post Reply | Private Reply | To 1 | View Replies]

To: kingattax
The code vulnerability exists within layers of secure Internet server coding.

If a vulnerability can exist with "layers of secure coding" and undermine the whole structure, why do we call them "layers?"

3 posted on 04/09/2014 3:02:28 PM PDT by Steely Tom (How do you feel about robbing Peter's robot?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: kingattax

This appears to be ‘the big one’ and it was open source.. And the bug went unnoticed since late 2011.. This is a huge blow.

I updated my client stuff to 1.01g, which is fixed. But who knows how long actual web site owners will take to upgrade.


4 posted on 04/09/2014 3:03:59 PM PDT by Monty22002
[ Post Reply | Private Reply | To 1 | View Replies]

To: kingattax; Jim Robinson; John Robinson

Ping !,,,,!,,,!


5 posted on 04/09/2014 3:04:23 PM PDT by moose07 (the truth will out ,one day.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: kingattax

This is all Algore’s fault. He invented a flawed internet.


6 posted on 04/09/2014 3:07:55 PM PDT by Proud2BeRight
[ Post Reply | Private Reply | To 1 | View Replies]

To: kingattax

Any other source other than “The Blaze?” Hate that site and all of its’ pop-ups.


7 posted on 04/09/2014 3:11:57 PM PDT by A_Tradition_Continues (formerly known as Politicalwit ...05/28/98 Class of '98)
[ Post Reply | Private Reply | To 1 | View Replies]

To: A_Tradition_Continues

try this

http://www.businessinsider.com/heartbleed-bug-explainer-2014-4


8 posted on 04/09/2014 3:13:46 PM PDT by kingattax (America needs more real Americans.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: A_Tradition_Continues

https://blog.torproject.org/blog/openssl-bug-cve-2014-0160


9 posted on 04/09/2014 3:15:48 PM PDT by Bobalu (Four Cokes And A Fried Chicken)
[ Post Reply | Private Reply | To 7 | View Replies]

To: kingattax

So it sounds like the problem is with how individual sites handle SSL. Anyone know if Bank of America or PayPal websites are affected by this?


10 posted on 04/09/2014 3:20:14 PM PDT by Menehune56 ("Let them hate so long as they fear" (Oderint Dum Metuant), Lucius Accius (170 BC - 86 BC))
[ Post Reply | Private Reply | To 1 | View Replies]

To: kingattax

check out your bank/etc here to see if it is vulnerable

http://lastpass.com/heartbleed/


11 posted on 04/09/2014 3:31:37 PM PDT by Chode (Stand UP and Be Counted, or line up and be numbered - *DTOM* -vvv- NO Pity for the LAZY - 86-44)
[ Post Reply | Private Reply | To 1 | View Replies]

To: kingattax

Here’s a good source with a few things users can do to help protect themselves. However, it’s the hosting sites and their version of OpenSSL. So ultimately, end users can’t do too much.

http://www.macobserver.com/tmo/article/dealing-with-heartbleed-what-you-need-to-know?utm_campaign=tmo_twitter


12 posted on 04/09/2014 3:33:28 PM PDT by Lake Living
[ Post Reply | Private Reply | To 1 | View Replies]

To: kingattax

Bttt.


13 posted on 04/09/2014 4:24:49 PM PDT by Inyo-Mono (NRA)
[ Post Reply | Private Reply | To 1 | View Replies]

To: kingattax

Now the question is, was it really a bug, or did NSA or the Chinese put it there?


14 posted on 04/09/2014 4:29:16 PM PDT by PapaBear3625 (You don't notice it's a police state until the police come for you.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Everybody

http://www.freerepublic.com/tag/openssl/index?tab=articles


15 posted on 04/09/2014 4:33:51 PM PDT by deks (Sent from my BlackBerry Q10 smartphone :)
[ Post Reply | Private Reply | To 14 | View Replies]

To: moose07

https://freerepulblic.com doesn’t exist, just http;//freerepublic.com Therefore this is not an issue.


16 posted on 04/09/2014 4:38:57 PM PDT by palmer (There's someone in my lead but it's not me)
[ Post Reply | Private Reply | To 5 | View Replies]

To: palmer

sorry, meant to type: https://freerepublic.com


17 posted on 04/09/2014 4:39:39 PM PDT by palmer (There's someone in my lead but it's not me)
[ Post Reply | Private Reply | To 16 | View Replies]

To: Paladin2

18 posted on 04/09/2014 4:42:10 PM PDT by Fightin Whitey
[ Post Reply | Private Reply | To 2 | View Replies]

To: Fightin Whitey

That doesn’t look like a San Francisco Bank....


19 posted on 04/09/2014 4:47:14 PM PDT by Paladin2
[ Post Reply | Private Reply | To 18 | View Replies]

To: Steely Tom
"...why do we call them "layers?""

The billing hours work out better.

20 posted on 04/09/2014 4:49:12 PM PDT by Paladin2
[ Post Reply | Private Reply | To 3 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-33 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson