What's new

Welcome to Offtopix 👋, Visitor

Off Topix is a well-established general discussion forum that originally opened to the public in 2009! We provide a laid-back atmosphere, and our members are down to earth. We have a ton of content, and fresh stuff is constantly being added. We cover all sorts of topics, so there's bound to be something inside to pique your interest. We welcome anyone and everyone to register and become a member of our awesome community.

Join Our Facebook Page Today!

Join the conversation and help spread the word about offtopix on Facebook! Your voice matters—let’s make an impact together!

Join Our X.com Page Today!

Join the conversation and become a champion for Offtopix on X.com! Your voice is powerful, and together, we can create meaningful change!

Join offtopix Discord Server Today!

Join the conversation and become a champion for Offtopix on Discord! Your voice holds incredible power, and together, we can create impactful change!

"Heartbleed" bug in Web security exposes passwords to hackers

  • Thread starter Thread starter Jazzy
  • Start date Start date
  • Replies Replies 0
  • Views Views 187

Jazzy

Waiting....
Valued Member
Joined
Jan 27, 2010
Posts
71,573
Reaction score
1,221
Points
2,125
Location
State Of Confusion
Website
wober.net
A major new vulnerability called Heartbleed could let attackers gain access to users' passwords and fool people into using bogus versions of Web sites. Some already say they've found Yahoo passwords as a result.

The problem, disclosed Monday night, is in open-source software called OpenSSL that's widely used to encrypt Web communications. Heartbleed can reveal the contents of a server's memory, where the most sensitive of data is stored. That includes private data such as usernames, passwords, and credit card numbers. It also means an attacker can get copies of a server's digital keys then use that to impersonate servers or to decrypt communications from the past or potentially the future, too.

Security vulnerabilities come and go, but this one is extremely serious. Not only does it require significant change at Web sites, it could require anybody who's used them to change passwords too, because they could have been intercepted. That's a big problem as more and more of people's lives move online, with passwords recycled from one site to the next and people not always going through the hassles of changing them.

"We were able to scrape a Yahoo username & password via the Heartbleed bug," tweeted Ronald Prins of security firm Fox-IT, showing a censored example. Added developer Scott Galloway, "Ok, ran my heartbleed script for 5 minutes, now have a list of 200 usernames and passwords for yahoo mail...TRIVIAL!"

Yahoo said just after noon PT that it fixed the primary vulnerability on its main sites: "As soon as we became aware of the issue, we began working to fix it. Our team has successfully made the appropriate corrections across the main Yahoo properties (Yahoo Homepage, Yahoo Search, Yahoo Mail, Yahoo Finance, Yahoo Sports, Yahoo Food, Yahoo Tech, Flickr, and Tumblr) and we are working to implement the fix across the rest of our sites right now. We're focused on providing the most secure experience possible for our users worldwide and are continuously working to protect our users' data."

However, Yahoo didn't offer advice to users about what they should do or what the effect on them is.

Developer and cryptography consultant Filippo Valsorda published a tool that lets people check Web sites for Heartbleed vulnerability. That tool showed Google, Microsoft, Twitter, Facebook, Dropbox, and several other major Web sites to be unaffected -- but not Yahoo. Valsorda's test uses Heartbleed to detect the words "yellow submarine" in a Web server's memory after an interaction using those words.

Other Web sites shown as vulnerable by Valsorda's tool include Imgur, OKCupid, and Eventbrite.

Full Article

Good old Yahoo not offering advice or what effect this has on accounts. I have 3 Yahoo accounts. I have changed all the passwords but not sure if it's too late or not. :mad:
 

Create an account or login to post a reply

You must be a member in order to post a reply

Create an account

Create an account here on Off Topix. It's quick & easy!

Log in

Already have an account? Log in here.

Welcome to Offtopix 👋, Visitor

Off Topix is a well-established general discussion forum that originally opened to the public in 2009! We provide a laid-back atmosphere, and our members are down to earth. We have a ton of content, and fresh stuff is constantly being added. We cover all sorts of topics, so there's bound to be something inside to pique your interest. We welcome anyone and everyone to register and become a member of our awesome community.

Theme customization system

You can customize some areas of the forum theme from this menu.

  • Theme customizations unavailable!

    Theme customization fields are not available to you, please contact the administrator for more information.

  • Choose the color combination that reflects your taste
    Background images
    Color gradient backgrounds
Back