[Heartbleed bug] Have you changed your internet passwords yet?
Join the discussion
Registration is free. Ask a follow-up in this thread, or start your own.
6 replies · 2K views
Discussion
Physics news on Phys.org
dipole
- 553
- 149
Does physicsforums use open SSL?
- 22,170
- 3,335
Is there a list of (important) websites that says which sites are secure (now) and which aren't?
Rick21383
- 31
- 34
micromass said:Is there a list of (important) websites that says which sites are secure (now) and which aren't?
http://mashable.com/2014/04/09/heartbleed-bug-websites-affected/
1MileCrash
- 1,338
- 41
Rick21383 said:
lol, AOL was actually on the chart.
"No, AOL does not incorporate OpenSSL into its pages, as OpenSSL did not exist 200 years ago."
- 22,657
- 7,733
http://www.bloomberg.com/news/2014-...e-used-heartbleed-bug-exposing-consumers.html
Bloomberg reports that, according to “two people familiar with the matter,” the NSA has known about the Heartbleed vulnerability for at least two years—and was exploiting it to collect information about people instead of informing those vulnerable and getting it fixed.
According to Slate, "In early 2012 Heartbleed was mistakenly introduced into the code for OpenSSL, an open-source software component for certain popular types of encryption. It would make sense if the NSA found it soon after, because—in addition to using its influence to weaken new or existing encryption—the agency also spends millions of dollars looking for software vulnerabilities that already exist around the Web, especially in open-source code that is more likely to have inconsistent oversight, and therefore bigger errors."
Bloomberg reports that, according to “two people familiar with the matter,” the NSA has known about the Heartbleed vulnerability for at least two years—and was exploiting it to collect information about people instead of informing those vulnerable and getting it fixed.
According to Slate, "In early 2012 Heartbleed was mistakenly introduced into the code for OpenSSL, an open-source software component for certain popular types of encryption. It would make sense if the NSA found it soon after, because—in addition to using its influence to weaken new or existing encryption—the agency also spends millions of dollars looking for software vulnerabilities that already exist around the Web, especially in open-source code that is more likely to have inconsistent oversight, and therefore bigger errors."
- 6,999
- 299
I guess if I wanted to collect a lot of user data right now, a good way would be set up a website where people can enter their the user names and passwords and have them checked to see if they have been stolen 
