News / Science & Technology

'Heartbleed' Flaw Endangers Encrypted Data Online

FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
A glitch in software meant to encrypt and protect online transactions has potentially exposed millions of passwords, credit card numbers and other sensitive bits of information to potential theft by computer hackers.
 
Security researchers at Google and Internet security firm Codenomicon revealed the breakdown, known as "Heartbleed", on Tuesday. The glitch was in a vulnerable version of software known as OpenSSL.  
 
OpenSSL software is meant to protect online accounts for emails, instant messaging and a wide range of electronic commerce.
 
Heartbleed is of particular concern because it went undetected for more than two years, making it difficult for people to know if they’ve been compromised. Security researchers are advising people to consider changing their online passwords.
 
“The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software,” according to the website Heartbleed.com, which was set up by Codenomicon. “This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content.”
 
Codenomicon said it had tested its own services “from an attacker’s perspective" and successfully stolen “usernames and passwords, instant messages, emails and business critical documents” all “without leaving a trace.”
 
The discovery of the bug prompted the U.S. Department of Homeland Security to issue a warning computer users and systems administrators to see whether they’re using OpenSSL.
 
Codenomicon is advising service providers and users to “install the fix as it becomes available for the operating systems, networked appliances and software they use.”

Experts say Heartbleed is serious and of concern to all Internet users, but that before changing passwords, check to see that the bug has been patched.

"Many are calling for an immediate change to passwords - a call to action I fully endorse with one caveat," said Christopher Burgess, CEO of Prevendra, Inc., an Internet security firm. "If the entity with whom you are about to change your password has not updated their SSL, you are changing your password into an insecure environment.  I advocate checking for the update from your vendor - once they confirm, then change the password to a strong password."

Burgess added that it's important to remember that the problem isn't on your device or machine, but rather on the servers supporting websites we visit each day.

You can check if a website has updated its servers by visiting this Heartbleed testing site.

You May Like

Sunni-Shi’ite Divide Threatens Middle East Stability

Analysts say ancient dispute that traces back to Islamic Revolution is fueling modern day unrest More

Shifting Demographics Lie Beneath Racial Tensions in Ferguson

As Missouri suburb morphed from majority white to majority black, observers say power structure remained static More

Video Artists Shun Russia's Profanity Law

Restriction is toughest since Soviet era, though critics reject move as patronizing and ineffective act of censorship in line with a string of conservative morality laws More

This forum has been closed.
Comments
     
There are no comments in this forum. Be first and add one

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Native Bees May Help Save Cropsi
X
Deborah Block
August 22, 2014 12:23 AM
U.S. President Barack Obama has called for a federal strategy to promote the health of bees that have been declining. The honeybee has been waning due to parasites, disease and pesticides. Wild bees may be used to take over their role as crop pollinators. Scientists first need to learn a lot more about wild bees, says biologist Sam Droege, who is pioneering the first national inventory on native bees. VOA’s Deborah Block went to his research laboratory in Beltsville, Maryland, to bring you more.
Video

Video Native Bees May Help Save Crops

U.S. President Barack Obama has called for a federal strategy to promote the health of bees that have been declining. The honeybee has been waning due to parasites, disease and pesticides. Wild bees may be used to take over their role as crop pollinators. Scientists first need to learn a lot more about wild bees, says biologist Sam Droege, who is pioneering the first national inventory on native bees. VOA’s Deborah Block went to his research laboratory in Beltsville, Maryland, to bring you more.
Video

Video US Defense Officials Plan for Long-Term Strategy to Contain Islamic State

U.S. defense officials say American air strikes in Iraq have helped deter Islamic State militants for the time being, but that a broad international effort is needed to defeat the extremists permanently. Defense Secretary Chuck Hagel warned Thursday that the group formerly known as the Islamic State in Iraq and the Levant, or ISIL, is better organized, and financially and militarily stronger than any other known terrorist group. Zlatica Hoke has more.
Video

Video Drug-Resistant Malaria Spreads in Southeast Asia

On Thailand’s border with Myanmar, also known as Burma, a malaria research and treatment clinic is stepping up efforts to eliminate a drug-resistant form of the parasite - before it spreads abroad. Steve Sandford reports from Mae Sot, Thailand.
Video

Video Gaza Conflict, Hamas Popularity Challenge Abbas

The Palestinian unity government of Mahmoud Abbas has failed to convince Hamas to agree to Egyptian-negotiated terms with Israel on a Gaza cease-fire. VOA State Department Correspondent Scott Stearns reports on what the Gaza conflict means for President Abbas, with whom U.S. officials have worked for years on a two-state solution to the Israeli-Palestinian conflict.
Video

Video Nigeria's 'Nollywood' Movie Industry Rolls in High Gear

Twenty years after its birth in a video shop in Lagos, Nigeria's "Nollywood" is one of the most prolific film industries on earth. Despite low budgets and whirlwind production schedules, Nigerian films are wildly popular in Africa and industry professionals say they hope, in the future, their films will be as great in quality as they are in quantity. Heather Murdock has more for VOA from Lagos.
Video

Video UN Launches 'Biggest Aid Operation in 30 Years' in Iraq

The United Nations has launched what it describes as one of the biggest aid operations in 30 years in northern Iraq, as hundreds of thousands of refugees flee the extremist Sunni militant group calling itself the Islamic State. As Kurdish and Iraqi forces battle the Sunni insurgents, the fighting has forced more people to flee their homes. Kurdish authorities say the international community must act now to avert a humanitarian catastrophe. Henry Ridgwell reports for VOA from London.
Video

Video Cambodian American Hip Hop Artist Sings of Personal Struggles

A growing underground movement of Cambodian American hip hop artists is rapping about the struggles of living in urban America. Most, if not all of them, are refugees or children of refugees who came to the United States from Cambodia to escape the Khmer Rouge genocide of the 1970s. Through their music, the artists hope to give voice to immigrants who have been struggling quietly for years. Elizabeth Lee reports from Long Beach, California.
Video

Video African Media Tries to Educate Public About Ebola

While the Ebola epidemic continues to claim lives in West Africa, information technology specialists, together with radio and TV reporters, are battling misinformation and prejudice about the disease - using social media to educate the public about the deadly virus. VOA’s George Putic has more.

AppleAndroid