News / Science & Technology

'Heartbleed' Flaw Endangers Encrypted Data Online

FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
A glitch in software meant to encrypt and protect online transactions has potentially exposed millions of passwords, credit card numbers and other sensitive bits of information to potential theft by computer hackers.
 
Security researchers at Google and Internet security firm Codenomicon revealed the breakdown, known as "Heartbleed", on Tuesday. The glitch was in a vulnerable version of software known as OpenSSL.  
 
OpenSSL software is meant to protect online accounts for emails, instant messaging and a wide range of electronic commerce.
 
Heartbleed is of particular concern because it went undetected for more than two years, making it difficult for people to know if they’ve been compromised. Security researchers are advising people to consider changing their online passwords.
 
“The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software,” according to the website Heartbleed.com, which was set up by Codenomicon. “This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content.”
 
Codenomicon said it had tested its own services “from an attacker’s perspective" and successfully stolen “usernames and passwords, instant messages, emails and business critical documents” all “without leaving a trace.”
 
The discovery of the bug prompted the U.S. Department of Homeland Security to issue a warning computer users and systems administrators to see whether they’re using OpenSSL.
 
Codenomicon is advising service providers and users to “install the fix as it becomes available for the operating systems, networked appliances and software they use.”

Experts say Heartbleed is serious and of concern to all Internet users, but that before changing passwords, check to see that the bug has been patched.

"Many are calling for an immediate change to passwords - a call to action I fully endorse with one caveat," said Christopher Burgess, CEO of Prevendra, Inc., an Internet security firm. "If the entity with whom you are about to change your password has not updated their SSL, you are changing your password into an insecure environment.  I advocate checking for the update from your vendor - once they confirm, then change the password to a strong password."

Burgess added that it's important to remember that the problem isn't on your device or machine, but rather on the servers supporting websites we visit each day.

You can check if a website has updated its servers by visiting this Heartbleed testing site.

You May Like

Ukraine Purges Interior Ministry Leadership With Pro-Russian Ties

Interior Minister Avakov says 91 people 'in positions of leadership' have been fired, including 8 generals found to have links to past pro-Moscow governments More

US Airlines Point to Additional Problems of any Ebola Travel Ban

Airline officials note that even under travel ban, they may not be able to determine where passenger set out from, as there are no direct flights from Liberia, Guinea or Sierra Leone More

Nigerian President to Seek Another Term

Goodluck Jonathan has faced intense criticism for failing to stop Boko Haram militants More

This forum has been closed.
Comments
     
There are no comments in this forum. Be first and add one

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Talks to Resume on Winter Gas for Ukrainei
X
Al Pessin
October 25, 2014 4:21 PM
Ukrainian and Russian officials will meet again next week in an effort to settle their dispute over natural gas supplies that threatens to leave Ukraine short of heating fuel for the coming winter. VOA’s Al Pessin reports from London the dispute is complex, and has both economic and geopolitical dimensions.
Video

Video Talks to Resume on Winter Gas for Ukraine

Ukrainian and Russian officials will meet again next week in an effort to settle their dispute over natural gas supplies that threatens to leave Ukraine short of heating fuel for the coming winter. VOA’s Al Pessin reports from London the dispute is complex, and has both economic and geopolitical dimensions.
Video

Video Smugglers Offer Cheap Passage From Turkey to Syria

Smugglers in Turkey offer a relatively cheap passage across the border into Syria. Ankara has stepped up efforts to stem the flow of foreign fighters who want to join Islamic State militants fighting for control of the Syrian border city of Kobani. But porous borders and border guards who can be bribed make illegal border crossings quite easy. Zlatica Hoke has more.
Video

Video China Political Meeting Seeks to Improve Rule of Law

China’s communist leaders will host a top level political meeting this week, called the Fourth Plenum, and for the first time in the party’s history, rule of law will be a key item on the agenda. Analysts and Chinese media reports say the meetings could see the approval of long-awaited measures aimed at giving courts more independence and include steps to enhance an already aggressive and high-reaching anti-corruption drive. VOA’s Bill Ide has more from Beijing.
Video

Video After Decades of Pressure, Luxembourg Drops Bank Secrecy Rules

European Union finance ministers have reached a breakthrough agreement that will make it more difficult for tax cheats to hide their money. The new legislation, which had been blocked for years by countries with a reputation as tax havens, was approved last week after Luxembourg and Austria agreed to lift their vetoes. But as Mil Arcega reports, it doesn’t mean tax cheats have run out of places to keep their money hidden.
Video

Video Kobani Refugees Welcome, Turkey Criticizes, US Airdrop

Residents of Kobani in northern Syria have welcomed the airdrop of weapons, ammunition and medicine to Kurdish militia who are resisting the seizure of their city by Islamic State militants. The Turkish government, however, has criticized the operation. VOA’s Scott Bobb reports from southeastern Turkey, across the border from Kobani.
Video

Video US ‘Death Cafes’ Put Focus on the Finale

In contemporary America, death usually is a topic to be avoided. But the growing “death café” movement encourages people to discuss their fears and desires about their final moments. VOA’s Jerome Socolovsky reports.
Video

Video Ebola Orphanage Opens in Sierra Leone

Sierra Leone's first Ebola orphanage has opened in the Kailahun district. Hundreds of children orphaned since the beginning of the Ebola outbreak face stigma and rejection with nobody to care for them. Adam Bailes reports for VOA about a new interim care center that's aimed at helping the growing number of children affected by Ebola.

All About America

AppleAndroid