Jump to content

Heartbleed


Cellar

Recommended Posts

  • Replies 32
  • Created
  • Last Reply
Posted

Done, thanks :thumbup:

 

Problem is that it's pointless to change your password if the site hasn't been patched, and the LastPass hearttbleed checker can't check thehub.

Posted
Next, change your passwords for major accounts — email, banking and social media logins — on sites that were affected by Heartbleed but patched the problem. However, if the site or service hasn't patched the flaw yet, there's no point to changing your password. Instead, ask the company when it expects to push out a fix to deal with Heartbleed.
Posted

I love how the security team behind releasing the bug have created such a great marketing/branding strategy. Bug announcements are usually so drab, and a big one like this really did need something special. Check out their site: http://heartbleed.com/

Guest EdEdEd
Posted

Please explain to the stupid people: (i.e. me)

Posted

Please explain to the stupid people: (i.e. me)

 

You know when you see https in the website address? that means the communication between you and the webserver is encrypted using SSL. The OpenSSL implementation of this has a security vulnerability that allows someone to intercept and access your info. Now, the problem is that even when you don't use the secure (https) version of a site, very often the sending of authentication info (password) is sent via SSL, so even a site like this one, which doesn't have an https version may have leaked your username/password during the login process.

Guest EdEdEd
Posted

You know when you see https in the website address? that means the communication between you and the webserver is encrypted using SSL. The OpenSSL implementation of this has a security vulnerability that allows someone to intercept and access your info. Now, the problem is that even when you don't use the secure (https) version of a site, very often the sending of authentication info (password) is sent via SSL, so even a site like this one, which doesn't have an https version may have leaked your username/password during the login process.

:eek: :o

 

So change all my passwords?

 

But how does one know said site implemented the Fixed OpenSSL?

Posted

You know when you see https in the website address? that means the communication between you and the webserver is encrypted using SSL. The OpenSSL implementation of this has a security vulnerability that allows someone to intercept and access your info. Now, the problem is that even when you don't use the secure (https) version of a site, very often the sending of authentication info (password) is sent via SSL, so even a site like this one, which doesn't have an https version may have leaked your username/password during the login process.

 

Thanks for the explanation. Just to be clear, is the worst that can happen here somebody gets my Hub password an post in my behalf?

Posted

You know when you see https in the website address? that means the communication between you and the webserver is encrypted using SSL. The OpenSSL implementation of this has a security vulnerability that allows someone to intercept and access your info. Now, the problem is that even when you don't use the secure (https) version of a site, very often the sending of authentication info (password) is sent via SSL, so even a site like this one, which doesn't have an https version may have leaked your username/password during the login process.

 

how would it be different if at all if you use something like Tapatalk?

Guest EdEdEd
Posted

Thanks for the explanation. Just to be clear, is the worst that can happen here somebody gets my Hub password an post in my behalf?

And any other site...

Archived

This topic is now archived and is closed to further replies.

Settings My Forum Content My Followed Content Forum Settings Ad Messages My Ads My Favourites My Saved Alerts My Pay Deals Help Logout