News / Science & Technology

'Heartbleed' Flaw Endangers Encrypted Data Online

FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
A glitch in software meant to encrypt and protect online transactions has potentially exposed millions of passwords, credit card numbers and other sensitive bits of information to potential theft by computer hackers.
 
Security researchers at Google and Internet security firm Codenomicon revealed the breakdown, known as "Heartbleed", on Tuesday. The glitch was in a vulnerable version of software known as OpenSSL.  
 
OpenSSL software is meant to protect online accounts for emails, instant messaging and a wide range of electronic commerce.
 
Heartbleed is of particular concern because it went undetected for more than two years, making it difficult for people to know if they’ve been compromised. Security researchers are advising people to consider changing their online passwords.
 
“The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software,” according to the website Heartbleed.com, which was set up by Codenomicon. “This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content.”
 
Codenomicon said it had tested its own services “from an attacker’s perspective" and successfully stolen “usernames and passwords, instant messages, emails and business critical documents” all “without leaving a trace.”
 
The discovery of the bug prompted the U.S. Department of Homeland Security to issue a warning computer users and systems administrators to see whether they’re using OpenSSL.
 
Codenomicon is advising service providers and users to “install the fix as it becomes available for the operating systems, networked appliances and software they use.”

Experts say Heartbleed is serious and of concern to all Internet users, but that before changing passwords, check to see that the bug has been patched.

"Many are calling for an immediate change to passwords - a call to action I fully endorse with one caveat," said Christopher Burgess, CEO of Prevendra, Inc., an Internet security firm. "If the entity with whom you are about to change your password has not updated their SSL, you are changing your password into an insecure environment.  I advocate checking for the update from your vendor - once they confirm, then change the password to a strong password."

Burgess added that it's important to remember that the problem isn't on your device or machine, but rather on the servers supporting websites we visit each day.

You can check if a website has updated its servers by visiting this Heartbleed testing site.

You May Like

At Khmer Rouge Court, Long-Awaited Verdict Approaches

First phase of trial, which is coming to an end, has focused on forced exodus of Phnom Penh in 1975 - and now many are hopeful justice will be served More

Video When Fighting Eases, Gazans Line Up at Bakeries

When there is a lull in the conflict, residents who have been hunkered down in their apartments rush out to stock up on food and other necessities More

Video Information War Rages Alongside Real One in Ukraine

Downing of Malaysian airliner, allegations of cross-border shelling move information war in war-torn country to a new level More

This forum has been closed.
Comments
     
There are no comments in this forum. Be first and add one

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Information War Rages Alongside Real One in Ukrainei
X
Al Pessin
July 31, 2014 8:13 PM
The downing of the Malaysian airliner two weeks ago, and allegations that Russians are shelling Ukrainian troops across the border, have moved the information war swirling around the Ukrainian conflict to a new level. VOA's Al Pessin reports from Kyiv.
Video

Video Information War Rages Alongside Real One in Ukraine

The downing of the Malaysian airliner two weeks ago, and allegations that Russians are shelling Ukrainian troops across the border, have moved the information war swirling around the Ukrainian conflict to a new level. VOA's Al Pessin reports from Kyiv.
Video

Video When Fighting Eases, Gazans Line Up at Bakeries

When there is a lull in the conflict in Gaza, residents who have been hunkered down in their apartments rush out to stock up on food and other necessities. Probably the most important destination is the local bakery. VOA’s Scott Bobb reports from Gaza City.
Video

Video US-Funded Program Offers Honduran Children Alternative to Illegal Immigration

President Obama and Central American leaders recently agreed to come up with a plan to address poverty and crime in the region that is fueling the surge of young migrants trying to illegally enter the United States. VOA’s Brian Padden looks at one such program in Honduras - funded in part by the United States - which gives street kids not only food and safety but a chance for a better life without, crossing the border.
Video

Video 'Fab Lab' Igniting Revolution in Kenya

The University of Nairobi’s Science and Technology Park is banking on 3-D prototyping to spark a manufacturing revolution in the country. Lenny Ruvaga has more for from Nairobi's so-called “FabLab” for VOA.
Video

Video Gazans in Shelled School Sought Shelter

Israel's air and ground assault against Hamas-led fighters in Gaza has forced many Palestinians to flee their homes, seeking safety. But safe places are hard to find, as VOA’s Scott Bobb reports from Jabaliya.
Video

Video Rapid Spread of Ebola in West Africa Prompts Global Alert

Across West Africa, health officials are struggling to keep up with what the World Health Organization describes as the worst ebola outbreak on record. The virus has killed hundreds of people this year. U.S. President Barack Obama and other world leaders are watching the developments closely as they weigh what actions, if any, are needed to help contain the disease.
Video

Video Michelle Obama: Young Africans Need to Embrace Women's Rights

U.S. first lady Michelle Obama urged some of Africa's best and brightest to advocate for women's rights in their home countries. As VOA's Pam Dockins explains, Obama spoke to some 500 participants of the Young African Leaders Initiative, a six-week U.S.-based training and development program.
Video

Video Immigrant Influx on Texas Border Heats Up Political Debate

Immigrants from Central America continue to cross the U.S.-Mexico border in south Texas, seeking asylum in the United States, as officials grapple with ways to deal with the problem and provide shelter for thousands of minors among the illegal border crossers. As VOA's Greg Flakus reports from Houston, the issue is complicated by internal U.S. politics and U.S. relations with the troubled nations that immigrants are fleeing.
Video

Video Study: Latino Students Most Segregated in California

Even though legal school segregation ended in the United States 60 years ago, one study finds segregation still occurs in the U.S. based on income and race. The University of California Los Angeles Civil Rights Project finds that students in California are more segregated by race than ever before, especially Latinos. Elizabeth Lee reports for VOA from Los Angeles.

AppleAndroid