Results 1 to 5 of 5

Thread: Tumblr urges change your passwords - all of them

  1. #1
    Boooooom Barakka's Avatar
    Join Date
    Jul 2003
    Location
    ...fixing it in post
    Posts
    1,361
    Thanks
    61
    Thanked
    127 times in 104 posts

    Tumblr urges change your passwords - all of them

    Tumblr are urging users to change their passwords - all of them - for every secure site they use due to the OpenSSL Heartbleed bug.

    The bug which can allow the capture of the encryption keys from the servers memory, while leaving no trace of the attack apparently could affect up to 50% of the servers on the Internet.

    It's times like these i'm glad I have a unique password for every website I have an account for.
    Quote Originally Posted by The Mock Turtle
    “Reeling and Writhing, of course, to begin with, and then the different branches of arithmetic -- Ambition, Distraction, Uglification, and Derision."
    System:Atari 2600 CPU:8-bit 6507 (1.19MHz) RAM:128 bytes Colours: 16 (4 on screen) Resolution: 192x160

  2. #2
    Get off my lawn... rox0r's Avatar
    Join Date
    Jun 2004
    Location
    Location: Location:
    Posts
    1,476
    Thanks
    94
    Thanked
    176 times in 137 posts
    • rox0r's system
      • Motherboard:
      • Asus Crosshair IV Formula
      • CPU:
      • AMD PHENOM2 X6 1090T
      • Memory:
      • 4Gb Corsair XMS3
      • Storage:
      • Samsung 840 240Gb SSD, 1 x 1Tb F1
      • Graphics card(s):
      • AMD R9 280x
      • PSU:
      • Corsair 650 Modular
      • Case:
      • Fractal Designs R3
      • Operating System:
      • Windows 7 x64 Home Premium
      • Monitor(s):
      • Dell 2709W 27"
      • Internet:
      • BT Infinity

    Re: Tumblr urges change your passwords - all of them

    I've recently started to use LastPass after a routine self-google revealed some user info on me, albeit redundant, on a russian hacker site.

    I'm not saying it's an infallible solution but I'm now rotating random generated passwords for over 40 sites in the hope that I'm making my online identity as hard as reasonably possible to 'crack'.

    There's always that niggling doubt that says, "what happens if LastPass gets hacked?" but how far do you go with paranoia before you give up and go completely offline?

  3. #3
    Senior Member watercooled's Avatar
    Join Date
    Jan 2009
    Posts
    11,478
    Thanks
    1,541
    Thanked
    1,029 times in 872 posts

    Re: Tumblr urges change your passwords - all of them

    Quote Originally Posted by rox0r View Post
    I've recently started to use LastPass after a routine self-google revealed some user info on me, albeit redundant, on a russian hacker site.

    I'm not saying it's an infallible solution but I'm now rotating random generated passwords for over 40 sites in the hope that I'm making my online identity as hard as reasonably possible to 'crack'.

    There's always that niggling doubt that says, "what happens if LastPass gets hacked?" but how far do you go with paranoia before you give up and go completely offline?
    Well with the way LastPass works, an attacker would have to do a heck of a lot more than break into their servers to gain anything useful. IIRC LastPass themselves never gets access to your plaintext password or your actual encryption key. If you use a very simple dictionary password and an attacker has plenty of computing resources then it might be a different story, of course, but even then they use key stretching to add greatly to the complexity of an attack - it's not like these websites that use single-round, unsalted MD5 hashes for their logins.

  4. #4
    Get off my lawn... rox0r's Avatar
    Join Date
    Jun 2004
    Location
    Location: Location:
    Posts
    1,476
    Thanks
    94
    Thanked
    176 times in 137 posts
    • rox0r's system
      • Motherboard:
      • Asus Crosshair IV Formula
      • CPU:
      • AMD PHENOM2 X6 1090T
      • Memory:
      • 4Gb Corsair XMS3
      • Storage:
      • Samsung 840 240Gb SSD, 1 x 1Tb F1
      • Graphics card(s):
      • AMD R9 280x
      • PSU:
      • Corsair 650 Modular
      • Case:
      • Fractal Designs R3
      • Operating System:
      • Windows 7 x64 Home Premium
      • Monitor(s):
      • Dell 2709W 27"
      • Internet:
      • BT Infinity

    Re: Tumblr urges change your passwords - all of them

    Indeed, LastPass have confirmed that even though they have been affected by HeartBleed, no user data can have been leaked due to the unique way that their servers never get to see your data.

    This was the reason I chose to entrust my passwords with their service, whether this decision bites me in the arse later in life we shall see but for now I feel a lot less lubed-up-and-bent-over than a lot of people I know right now.

  5. #5
    Senior Member
    Join Date
    Oct 2009
    Posts
    269
    Thanks
    45
    Thanked
    30 times in 26 posts
    • cookie365's system
      • Motherboard:
      • Asus H87M Plus
      • CPU:
      • i3 4340
      • Memory:
      • 2x Kingston HyperX 4Gb
      • Storage:
      • 250Gb Samsung SSD 840 EVO + Seagate 1TB + WD Green 2TB
      • Graphics card(s):
      • Whatever comes with the i3
      • PSU:
      • bequiet StraightPower 600
      • Case:
      • Aquacool Dead Silence
      • Operating System:
      • W10
      • Monitor(s):
      • Rectangular
      • Internet:
      • Cable

    Re: Tumblr urges change your passwords - all of them

    Done my Hexus password, only another 500 or so to go

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •