Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Heartbleed Bug: Chartier Explains How Codenomicon Found The Massive Internet Security Breach
IBTimes.com ^ | April 09 2014 10:16 PM | By Ryan W. Neal

Posted on 04/11/2014 8:22:27 AM PDT by topher

The cybersecurity firm that discovered the so-called Heartbleed bug, a gaping hole in the most widely used software privacy and security software on the Internet, said the flaw went undetected for two years because of the large amount of intensive work it takes to manually test encryption software.

(Excerpt) Read more at ibtimes.com ...


TOPICS: Business/Economy; News/Current Events
KEYWORDS: codenomicon; heartbleed
Navigation: use the links below to view more comments.
first previous 1-2021-32 last
To: topher

Intrusion detection picked up the first attack on this exploit early this AM in the network I manage..


21 posted on 04/11/2014 9:48:43 AM PDT by IamConservative
[ Post Reply | Private Reply | To 1 | View Replies]

To: topher

Bump for later!


22 posted on 04/11/2014 9:49:46 AM PDT by dcwusmc (A FREE People have no sovereign save Almighty GOD!!! III OK We are EVERYWHERE!!!)
[ Post Reply | Private Reply | To 14 | View Replies]

To: rarestia

One additional question rarestia, please. If one does not do anything online other than browse, visit this site of FR and send emails to family from one email site ... from all can gleam that individual is basically safe and may not even need to change their passwords? Is that statement / question an affirmative or am I misreading the information?


23 posted on 04/11/2014 9:56:18 AM PDT by no-to-illegals (Scrutinize our government and Secure the Blessing of Freedom and Justice)
[ Post Reply | Private Reply | To 19 | View Replies]

To: no-to-illegals

Remember that SSL is used to mask your traffic. Since sites like FR, FoxNews, Drudge, etc. don’t use SSL (http vs https), then you really have little with which to be concerned.

Anywhere that sensitive data is passed, anywhere a password is required, anywhere that personally identifiable information is presented to an entity outside of your circle of trust, you SHOULD be using SSL or your data could be compromised.

So to answer your question, are you safe? Sure, you’re safe insomuch as insecure traffic isn’t affected by this data breach. If, however, you are reading your email on a site that does not use SSL or logging into a site, such as FR, where your login is not protected by SSL, then you’re passing all of your credentials and data to that server in clear text which can be read by anyone. Food for thought.


24 posted on 04/11/2014 10:24:17 AM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 23 | View Replies]

To: rarestia
Thank You for a logic answer and an answer each of us can take literally as being Food for thought.
25 posted on 04/11/2014 10:44:53 AM PDT by no-to-illegals (Scrutinize our government and Secure the Blessing of Freedom and Justice)
[ Post Reply | Private Reply | To 24 | View Replies]

To: topher

This site will test any domain to give you some idea of security and whether is is effected by heartbleed or not.

https://www.ssllabs.com/ssltest/


26 posted on 04/11/2014 10:57:52 AM PDT by Lake Living
[ Post Reply | Private Reply | To 1 | View Replies]

To: AppyPappy

That is great. I hope everyone who is wondering what this is all about looks at that. It is clear and accurate.


27 posted on 04/11/2014 11:09:15 AM PDT by T. P. Pole
[ Post Reply | Private Reply | To 15 | View Replies]

To: topher
One of the arguments made for open source software is that all the extra eyes on the code detect bugs faster. It apparently did not work in this case.
28 posted on 04/11/2014 7:36:49 PM PDT by beef (Who Killed Kennewick Man?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Lake Living
I tried this with a couple of banks, and one bank "flunked" and another bank could not be rated.

And these were major banks...

29 posted on 04/11/2014 7:53:51 PM PDT by topher (Traditional values -- especially family values -- which have been proven over time.)
[ Post Reply | Private Reply | To 26 | View Replies]

To: ShadowAce

You seem pretty up on this stuff. This thread http://www.freerepublic.com/focus/f-chat/3143545/posts
says you don’t have to be concerned if you have an apple phone or computer. I’m somewhat skeptical. Is this correct? I thought the problem was on the site you are visiting.


30 posted on 04/11/2014 8:24:46 PM PDT by Lurkina.n.Learnin
[ Post Reply | Private Reply | To 4 | View Replies]

To: Lurkina.n.Learnin
The problem is on the site you are visiting.

However, Apple is claiming that its server-side services are not vulnerable--which is great.

They threw in the other products in that announcement--I think--merely as a matter of marketing.

31 posted on 04/12/2014 7:19:09 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 30 | View Replies]

To: ShadowAce

That’s what I thought. It sounds like a false sense of security if people think they are safe because they use a Mac when what you are using isn’t the problem in the first place.


32 posted on 04/12/2014 7:22:24 AM PDT by Lurkina.n.Learnin
[ Post Reply | Private Reply | To 31 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-32 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson