News / Science & Technology

'Heartbleed' Flaw Endangers Encrypted Data Online

FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
A glitch in software meant to encrypt and protect online transactions has potentially exposed millions of passwords, credit card numbers and other sensitive bits of information to potential theft by computer hackers.
 
Security researchers at Google and Internet security firm Codenomicon revealed the breakdown, known as "Heartbleed", on Tuesday. The glitch was in a vulnerable version of software known as OpenSSL.  
 
OpenSSL software is meant to protect online accounts for emails, instant messaging and a wide range of electronic commerce.
 
Heartbleed is of particular concern because it went undetected for more than two years, making it difficult for people to know if they’ve been compromised. Security researchers are advising people to consider changing their online passwords.
 
“The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software,” according to the website Heartbleed.com, which was set up by Codenomicon. “This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content.”
 
Codenomicon said it had tested its own services “from an attacker’s perspective" and successfully stolen “usernames and passwords, instant messages, emails and business critical documents” all “without leaving a trace.”
 
The discovery of the bug prompted the U.S. Department of Homeland Security to issue a warning computer users and systems administrators to see whether they’re using OpenSSL.
 
Codenomicon is advising service providers and users to “install the fix as it becomes available for the operating systems, networked appliances and software they use.”

Experts say Heartbleed is serious and of concern to all Internet users, but that before changing passwords, check to see that the bug has been patched.

"Many are calling for an immediate change to passwords - a call to action I fully endorse with one caveat," said Christopher Burgess, CEO of Prevendra, Inc., an Internet security firm. "If the entity with whom you are about to change your password has not updated their SSL, you are changing your password into an insecure environment.  I advocate checking for the update from your vendor - once they confirm, then change the password to a strong password."

Burgess added that it's important to remember that the problem isn't on your device or machine, but rather on the servers supporting websites we visit each day.

You can check if a website has updated its servers by visiting this Heartbleed testing site.

You May Like

N. Korea Sentences American to 6 Years Hard Labor

Matthew Miller's brief trial Sunday comes two weeks after 24-year old Miller and two other American detainees appealed to the US government to help free them More

Pakistan Rejects Afghan Criticism of 480-kilometer Border Trench

Military spokesman tells VOA the project is part of administrative and security measures taken to secure the mountainous border with Afghanistan More

Photogallery Typhoon Kalmaegi Makes Landfall in Philippines

Storm makes landfall late Sunday, cutting power and communications lines and forcing people to flee to higher ground More

This forum has been closed.
Comments
     
There are no comments in this forum. Be first and add one

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Scotland Independence Bid Stokes Global Interesti
X
Henry Ridgwell
September 12, 2014 8:35 PM
The people of Scotland are preparing to vote on whether to become independent and break away from the rest of Britain, in a referendum being watched carefully in many other countries. Some see it as a risky experiment; while others hope a successful vote for independence might energize their own separatist demands. Foreign immigrants to Scotland have a front row seat for the vote. VOA’s Henry Ridgwell spoke to some of them in Edinburgh.
Video

Video Scotland Independence Bid Stokes Global Interest

The people of Scotland are preparing to vote on whether to become independent and break away from the rest of Britain, in a referendum being watched carefully in many other countries. Some see it as a risky experiment; while others hope a successful vote for independence might energize their own separatist demands. Foreign immigrants to Scotland have a front row seat for the vote. VOA’s Henry Ridgwell spoke to some of them in Edinburgh.
Video

Video Washington DC Mural Artists Help Beautify City

Like many cities, Washington has a graffiti problem. Buildings and homes, especially in low-income neighborhoods, are often targets of illegal artwork. But as we hear from VOA’s Julie Taboh, officials in the nation's capital have come up with an innovative program that uses the talents of local artists to beautify the city.
Video

Video Palestinians Turn to Rebuilding Gaza

After almost two months of conflict in Gaza, Palestinians are preparing to rebuild the isolated Mediterranean enclave with assistance from abroad. Meanwhile, an international human rights group has found that Israel likely violated international laws of war during some of its attacks on Gaza. Zlatica Hoke has more.
Video

Video US Muslim Leaders Condemn Islamic State

Leaders of America's Muslim community are condemning the violent extremism of the Islamic State group in Iraq and Syria. The U.S. Muslim leaders say militants are exploiting their faith in a failed effort to justify violent extremism. VOA correspondent Meredith Buel reports.
Video

Video Middle Eastern Church Leaders Highlight Christians’ Plight

Patriarchs of Eastern Rite churches came to Washington this week to draw attention to the attacks against Christians in Syria, Iraq and elsewhere in the Middle East. VOA’s religion correspondent Jerome Socolovsky has more.
Video

Video Americans' Reaction Mixed on Obama Strategy for Islamic State Militants

President Barack Obama’s televised speech on how the United States plans to “degrade and destroy” the group known as the Islamic State reached a prime-time audience of millions. And it came as Americans appear more willing to embrace a bolder, tougher approach to foreign policy. VOA producer Katherine Gypson and reporter Jeff Seldin have this report from Washington.
Video

Video Authorities Allege LA Fashion Industry-Cartel Ties

U.S. officials say they have broken up crime rings that funneled tens of millions of dollars from Mexican drug cartels through fashion businesses in Los Angeles. Mike O'Sullivan reports that authorities announced nine arrests, as 1,000 law enforcement agents fanned out through the city on Wednesday.
Video

Video Bedouin Woman Runs Successful Business in Palestinian City

A Bedouin woman is breaking social taboos by running a successful vacation resort in the Palestinian town of Jericho. Bedouins are a sub-group of Arabs known for their semi-nomadic lifestyle. Zlatica Hoke says the resort in the West Bank's Jordan Valley is a model of success for women in the region.


Carnage and mayhem are part of daily life in northern Nigeria, the result of a terror campaign by the Islamist group Boko Haram. Fears are growing that Nigeria’s government may not know how to counter it, and may be making things worse. More

AppleAndroid