Print Topic - Archive

Darkshade Forum  /  News  /  No Heartbleeds Here
Posted by: Diddly, April 9, 2014, 10:05pm
Not sure anyone here cares, but in case you do, this site has been doubly tested and is not vulnerable to the Heartbleed exploit plaguing the internet.
Posted by: Diddly, April 11, 2014, 12:35pm; Reply: 1
Seems to be a lot of confusion as to what the HeartBleed exploit is, and why it's such a big issue now even though it's been around for 2 years.

The problem is that someone just discovered it, and it's a big gaping hole.  It's akin to discovering a disposable pen can open U-Shape bicycle locks.  http://archive.wired.com/culture/lifestyle/news/2004/09/64987

Server administrators have to first check if they're using the effected software, patch the hole if it's there, and then regenerate their SSL certificates (because the encryption key might be one of the things that could've been stolen).  Until they regenerate their key, DON'T go changing your password.  It'd be pointless.  You can check if a site is currently vulnerable to HeartBleed here: https://lastpass.com/heartbleed/

XKCD has a great example of how HeartBleed basically works:
Posted by: Danmick, April 11, 2014, 4:53pm; Reply: 2
I expect to start receiving phishing emails within the next day or so asking me to "click here to reset" my Paypal/online banking password" etc.
Print page generated: May 16, 2024, 3:54am