By now everyone on the planet with an internet connection has heard about the OpenSSL bug known as "heartbleed" that can compromise secure (https:) websites (or really, any "secure" communications on any device that uses OpenSSL, including possibly your smartphone.)
So, is it time to panic? Close all your accounts? Log off and retreat to a desert island?
Probably not. Unless you are really paranoid. Which is not necessarily a bad thing.
Personally, I have not done anything. Because, what are you going to do? Anything you type (or say or record) into a computer or any other device connected to the internet is potentially vulnerable. It's a fact of modern life. Deal with it.
Basically, what this bug allows a criminal to do is see 64K chunks of the server's random access memory (RAM) in the clear. Sloppy programming allowed this. The fix is basically one line of code. The exploit is one of the oldest tricks in the book, that is, tricking a program into returning data from out of bounds memory space.
(The inverse is tricking a program into injecting code into out of bounds memory space and executing it. That's how some viruses work. This is not a virus.)
If a big online service has thousands of servers with terabytes or more of RAM, a 64K chunk is like one grain of sand on the beach, right? Plus, it's "random" as in "random" access memory. A random 64K chunk couldn't possibly contain much useful information, right? And the odds of anyone catching a random 64K chunk of data containing something interesting about me are astronomical, right?
Well, yes and no.
The problem is that the 64K chunk of RAM is most likely allocated in the same general vicinity of your browsing session and/or the OpenSSL cryptography functions. This means that stuff like your (or some other unlucky person's) login and password could be hanging around in that space in the clear. Or, a "session key," which would allow a criminal to impersonate you and your browser. Or worse yet, the server's private SSL certificate key (the keys to the kingdom), in which case all communications to and from that server are compromised.
The good news is that a lot of bad and somewhat unlikely things would have to happen for a criminal to be able to exploit this bug.
The bad news is that you could be the unlucky person to have your password or other information exposed. Or a site you visit could be compromised, and NSA (or Facebook) could be watching everything you type on it.
At any rate, I am not aware of any reported actual exploits of the "heartbleed" OpenSSL bug. But the extent of the problem is not yet fully known and we don't know what we don't know.
So, what should you do?
First, you have to wait for the online services you use that also use OpenSSL to apply the fix. (They will also likely have to install new SSL certificates). They should announce that they have done this. Most major sites have already done so. (If you're not sure, you can use one of the verification services that have popped such as this one.)
After you have confirmed that the sites you use have applied the fix, you should next change your passwords on those sites. (And don't use the same password on every site, OK?)
Beyond that, about all you can do is monitor your credit card accounts, bank statements, online merchant accounts, etc. for suspicious activity until this dies down (which may be never). But you should be doing that from time to time anyway.
And lastly, beware of phishing or other scams that try to trick you into disclosing your password and/or other credentials or any other sensitive personal information, either via email, telephone or fake websites. These creeps come out of the woodwork to "help" you whenever there's a widely reported security problem.
For more info:
Everything you need to know about the Heartbleed SSL bug
Anatomy of a data leakage bug - the OpenSSL "heartbleed" buffer overflow
Why Heartbleed is dangerous? Exploiting CVE-2014-0160
Codenomicon Heartbleed Bug page
DISCLAIMER: I am not an internet security expert. Your mileage may vary. Proceed at your own risk. May the odds forever be in your favor. Etc.
|
Topics:
|
|
Discussing:
- Trump Admin wants rid of DEI bike lanes (1 reply)
- New COVID-19 wave, vaccine available soon (2 replies)
- Mark Harmon journalism award (1 reply)
- Senior's fishing, hunting, sportsman license fees increase more than others (2 replies)
- Dolly Parton - we miss you already (1 reply)
- NW Indiana residents on 10th day without power (1 reply)
- Only Republicans moving to Florida? (1 reply)
- ballrooms, bankruptcy, and bulls-- (1 reply)
- SoKno what have you done? (2 replies)
- Vote! Thursday is election day. (4 replies)
- The Odyssey (3 replies)
- AI backlash - Justin Pearson (1 reply)
TN Progressive
- View from the Overlook (Whitescreek Journal)
- Alcoa property taxes will probably not go up (BlountViews)
- Smith & Wesson not a good fit for Blount County (BlountViews)
- Pellissippi Parkway extension delayed again (BlountViews)
- Blount County early voting record turnout (BlountViews)
- WATCH THIS SPACE. (Left Wing Cracker)
- America As It Is Right Now (RoaneViews)
- A friend sent this: From Captain McElwee's Tall Tales of Roane County (RoaneViews)
- The Meidas Touch (RoaneViews)
- Massive Security Breach Analysis (RoaneViews)
- (Whitescreek Journal)
- My choices in the August election (Left Wing Cracker)
TN Politics
- Judge extends pause on ‘unconstitutional’ Trump order, postal rule limiting vote-by-mail (TN Lookout)
- Judge criticizes Trump pressure on prosecutors on reflecting pool vandalism charges (TN Lookout)
- Stockard on the Stump: Towns’ departure opens seat for Shelby Dems appointment (TN Lookout)
- Immigrant advocates highlight Tennessee role in Trump administration’s mass deportation plans (TN Lookout)
- US Supreme Court again urged to permit Trump vote-by-mail restrictions (TN Lookout)
- Defense contractor to lay off 127 workers in Hardeman County (TN Lookout)
Knox TN Today
- Faizon Brandon stars, Vols rout Furman (Knox TN Today)
- Faith Along the Way: Simple Wisdom (Knox TN Today)
- Saturday Catch-Up: 6 stories worth another look (Knox TN Today)
- Ex-Vol helps Colorado defeat Georgia Tech (Knox TN Today)
- Get first look at Lady Vols softball at fall ball (Knox TN Today)
- Pick the score and win dinner at Aubrey’s with the KnoxTNToday Game Ball (Knox TN Today)
- Daily Connections: Your East Tennessee Guide | Sept. 4-6 (Knox TN Today)
- Mountaineer Folk Festival + Master Gardeners + Music in the Grove ++ (Knox TN Today)
- Close to Home: I found a Knoxville treasure hiding in plain sight (Knox TN Today)
- Thanks, Dolly (Knox TN Today)
- Albino alligator arrives in time for BOO! at the Zoo’s return to Zoo Knoxville (Knox TN Today)
- Labor Day honors more than work. It honors the people who keep a community moving (Knox TN Today)
Local TV News
- Faizon Brandon's 5 touchdowns lead Tennessee past Furman (WATE)
- Vols pay tribute to Dolly Parton with 4th Quarter song, halftime performance (WATE)
- New gameday parking option gives Vols fans a way to give back to the community (WATE)
- Zoo Knoxville mourns loss of beloved porcupine Pedzi (WATE)
- Vol Walk canceled ahead of Tennessee's 2026 opening game (WATE)
- McMinn County deputies commended lifesaving efforts in multiple situations (WATE)
News Sentinel
State News
- Georgia beats Tennessee State, and the heat, in blowout opener - Chattanooga Times Free Press (Times Free Press)
- Mocs fall to Tennessee Tech for second straight season - Chattanooga Times Free Press (Times Free Press)
- Vols notebook: Brandon, Matthews a quick combo in passing attack - Chattanooga Times Free Press (Times Free Press)
- Excitement abounds among Vols fans for season opener - Chattanooga Times Free Press (Times Free Press)
Wire Reports
- U.S. military says it hit 3 Iranian tankers after Navy ships targeted - The Washington Post (US News)
- Tucson real estate agent duct-taped to seat after becoming unruly on flight - Arizona Daily Star (Business)
- Putin Meets Witkoff and Kushner in Moscow to Discuss Ukraine War - The New York Times (US News)
- Washington blocks new Trump mail voting rules, keeping midterm election procedures intact - KOMO (US News)
- Hurricane Lowell threatens Hawaiian islands with life-threatening surf - NBC News (US News)
- The Venezuelan billionaire the US investigated for money laundering now has a Pentagon oil deal - Reuters (US News)
- LAPD busts massive street takeover in South Bay, impounding more than 100 cars - Los Angeles Times (US News)
- OpenAI Responds After Report Exposed Another Incident In Which Its AI Agents Went Rogue - Engadget (Business)
- Trump’s MAGA Inc. sends $10M to Texas in first general election spend of the year - Politico (US News)
- Fundraiser for Lindsay Clancy’s Parents Raises Over $1.1 Million After Mistrial - Rolling Stone (US News)
- Trump turns up the heat on Warsh as Fed rate hike looms - CNBC (Business)
- 'Can't Message That Away': GOP Frets as Trump Administration Desperately Spins Record-High Diesel Prices - Common Dreams (Business)
- Tesla’s Cybercab has been deployed, and it’s already under investigation - Ars Technica (Business)
- Kenyans Made a Living Writing College Essays. Then A.I. Arrived. - The New York Times (Business)
- Rates Climb, Stocks Dip After Strong U.S. Jobs Data - WSJ (Business)
Local Media
Lost Medicaid Funding
Search and Archives
TN Progressive
Nearby:
- Blount Dems
- Herston TN Family Law
- Inside of Knoxville
- Instapundit
- Jack Lail
- Jim Stovall
- Knox Dems
- MoxCarm Blue Streak
- Outdoor Knoxville
- Pittman Properties
- Reality Me
- Stop Alcoa Parkway
Beyond:
- Nashville Scene
- Nashville Post
- Smart City Memphis
- TN Dems
- TN Journal
- TN Lookout
- Bob Stepno
- Facing South

You sir are wrong way wrong!
(link...) The correct thing to do is to visit my good friends blog right smack here (link...)
Reality, read my blog...this team is the most elite unit in the world and to be honest I am dam proud to have been a part of it and to have blogged about it.
This is a dynamic time in the world of encryption, Many new methods are being developed many old developments are being broken.