Results 1 to 11 of 11

Thread: News - Heartbleed bug makes web users concerned and confused

  1. #1
    HEXUS.admin
    Join Date
    Apr 2005
    Posts
    31,709
    Thanks
    0
    Thanked
    2,073 times in 719 posts

    News - Heartbleed bug makes web users concerned and confused

    But there are two simple steps, as recommended by Kaspersky, for users to follow.
    Read more.

  2. #2
    Senior Member
    Join Date
    Sep 2013
    Location
    Europe
    Posts
    596
    Thanks
    42
    Thanked
    13 times in 13 posts
    • DemonHighwayman's system
      • Motherboard:
      • MSI Z97I Gaming
      • CPU:
      • Intel i7 4790K
      • Memory:
      • 16Gb 2.4Ghz Kingston Beast
      • Storage:
      • 256 Gb Samsung 850 Pro (Main), 4TB Toshiba X300 (games), 2TB External TV/Films HDD
      • Graphics card(s):
      • KFA2 RTX 2070 EXOC
      • PSU:
      • Coolermaster Real Power M700
      • Case:
      • Thermaltake Level 20 VT
      • Operating System:
      • Windows 10
      • Monitor(s):
      • Asus PB278Q
      • Internet:
      • Yes most of the time

    Re: News - Heartbleed bug makes web users concerned and confused

    The link for heartbleed test page isn't working

  3. Received thanks from:

    mtyson (10-04-2014)

  4. #3
    Senior Member
    Join Date
    Dec 2003
    Location
    Taichung City
    Posts
    898
    Thanks
    281
    Thanked
    172 times in 121 posts
    • mtyson's system
      • Motherboard:
      • Gigabyte GA-B85M-HD3
      • CPU:
      • Intel Core i7 4790T
      • Memory:
      • 12GB
      • Storage:
      • Sandisk 128GB SSD + Kingston 500GB SSD + NAS etc
      • Graphics card(s):
      • Sapphire Radeon RX 580 Nitro+
      • PSU:
      • Corsair 430W
      • Case:
      • Zalman Z9 Plus
      • Operating System:
      • Windows 10
      • Monitor(s):
      • AOC 31.5-inch VA QHD monitor
      • Internet:
      • 100MB Virgin fibre

    Re: News - Heartbleed bug makes web users concerned and confused

    sorry, link is fixed now

  5. Received thanks from:

    DemonHighwayman (10-04-2014)

  6. #4
    Member
    Join Date
    Sep 2003
    Posts
    176
    Thanks
    173
    Thanked
    18 times in 8 posts

    Re: News - Heartbleed bug makes web users concerned and confused

    Does anyone else see the irony in calling it *Open*SSL...?

  7. #5
    Member
    Join Date
    Jan 2014
    Location
    Bristol
    Posts
    113
    Thanks
    0
    Thanked
    7 times in 5 posts

    Re: News - Heartbleed bug makes web users concerned and confused

    I use lastpass and with in a day they had built in a vulnerability check that checks all the sites I have stored to see if they were affected or not. Cant beat that for customer service!

  8. #6
    Registered+
    Join Date
    Nov 2012
    Location
    Burnley
    Posts
    58
    Thanks
    3
    Thanked
    1 time in 1 post
    • Heisenberg's system
      • Motherboard:
      • Gigabyte GA 970A DS3P
      • CPU:
      • AMD 8320
      • Memory:
      • 8 GB Corsair
      • Storage:
      • 1 TB WD
      • Graphics card(s):
      • 560 Ti
      • PSU:
      • 650 W XFX
      • Case:
      • Fractal R4
      • Operating System:
      • Windows 7 64 Bit
      • Monitor(s):
      • 23" AOC I2367 FH
      • Internet:
      • 160 Mb Virgin Media Broadband

    Re: News - Heartbleed bug makes web users concerned and confused

    Quote Originally Posted by Gh0sty View Post
    I use lastpass and with in a day they had built in a vulnerability check that checks all the sites I have stored to see if they were affected or not. Cant beat that for customer service!
    I also use LastPass now thanks to a friend, can't live without it.

  9. #7
    Senior Member watercooled's Avatar
    Join Date
    Jan 2009
    Posts
    11,478
    Thanks
    1,541
    Thanked
    1,029 times in 872 posts

    Re: News - Heartbleed bug makes web users concerned and confused

    Oh a slight detour from the well-covered direct impact of this flaw, I wonder if this will be a sufficient kick up the rear to get the fragmented mess of certificate revocation sorted?

    As has been alluded to elsewhere, I can see any potentially stolen certificates being used in combination with MITM and/or DNS redirection to create some pretty convincing phishing websites.

    I found a test page from Verisign, to see how various browsers respond: https://test-sspev.verisign.com:2443...risign.html‎
    Firefox, IE and Chrome on desktop all call foul play and refuse to allow the connection, as you'd hope, but Chrome on Android doesn't even complain and just displays the page.

    Upon further reading, it seems even Chrome and FF only really scrutinise EV certificates, and will happily accept 'standard' certificates without complaining: http://news.netcraft.com/archives/20...-practice.html

    IMNSHO, the difference between standard and EV shouldn't be one of 'up-to-spec security' and 'wide open to pwnage if the certificate is stolen', and that strikes me as quite irresponsible at best.

    I've not looked into whether that test site is EV or standard (although I assume the former), but either way, at least the Chrome Android fails quite spectacularly, and IMO this really isn't a trivial matter in light of recent events.

    Any thoughts?

  10. #8
    Registered+
    Join Date
    Apr 2014
    Posts
    44
    Thanks
    1
    Thanked
    0 times in 0 posts
    • mack_5991's system
      • Motherboard:
      • MSI B85I Gaming
      • CPU:
      • i5 4440
      • Memory:
      • CORSAIR XMS3 8GB
      • Storage:
      • Kingston V300 120GB & Seagate 1TB
      • Graphics card(s):
      • ZOTAC GTX 660
      • PSU:
      • CORSAIR CX500M
      • Case:
      • Coolermaster Elite 110
      • Operating System:
      • Windows 7 Ultimate
      • Monitor(s):
      • ACER S220HQL
      • Internet:
      • Virgin media

    Re: News - Heartbleed bug makes web users concerned and confused

    Does anyone have a list of affected sites ?

  11. #9
    Super Moderator Jonj1611's Avatar
    Join Date
    Jun 2008
    Posts
    5,832
    Thanks
    1,871
    Thanked
    1,021 times in 783 posts

    Re: News - Heartbleed bug makes web users concerned and confused

    It says in the story :/
    Jon

  12. #10
    Member
    Join Date
    Aug 2006
    Location
    Glasgow
    Posts
    148
    Thanks
    5
    Thanked
    11 times in 10 posts
    • fatguy666's system
      • Motherboard:
      • MSI Z77A-G45
      • CPU:
      • i5 3570K @ 4.3
      • Memory:
      • 2 x 4GB Crucial 1600
      • Storage:
      • 240GB Sandisk SSD, 500GB + 1.5TB + 3TB + 3TB
      • Graphics card(s):
      • Gigabyte WF3 780 TI OC @ stock
      • PSU:
      • 600w Silent Pro Gold
      • Case:
      • CM690 II Advanced Black & White
      • Operating System:
      • Windows 7
      • Monitor(s):
      • LG 21" IPS
      • Internet:
      • Virgin 100

    Re: News - Heartbleed bug makes web users concerned and confused

    Meh, it's not like I've got any money so the only thing I'd be worried about is losing access to steam.

  13. #11
    ZaO
    Guest

    Re: News - Heartbleed bug makes web users concerned and confused

    Thankyou! Great article! I was wondering how the hell to know which sites I needed to change passwords for, and when to change them. This should make it easier

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •