News / Science & Technology

'Heartbleed' Flaw Endangers Encrypted Data Online

FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
A glitch in software meant to encrypt and protect online transactions has potentially exposed millions of passwords, credit card numbers and other sensitive bits of information to potential theft by computer hackers.
 
Security researchers at Google and Internet security firm Codenomicon revealed the breakdown, known as "Heartbleed", on Tuesday. The glitch was in a vulnerable version of software known as OpenSSL.  
 
OpenSSL software is meant to protect online accounts for emails, instant messaging and a wide range of electronic commerce.
 
Heartbleed is of particular concern because it went undetected for more than two years, making it difficult for people to know if they’ve been compromised. Security researchers are advising people to consider changing their online passwords.
 
“The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software,” according to the website Heartbleed.com, which was set up by Codenomicon. “This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content.”
 
Codenomicon said it had tested its own services “from an attacker’s perspective" and successfully stolen “usernames and passwords, instant messages, emails and business critical documents” all “without leaving a trace.”
 
The discovery of the bug prompted the U.S. Department of Homeland Security to issue a warning computer users and systems administrators to see whether they’re using OpenSSL.
 
Codenomicon is advising service providers and users to “install the fix as it becomes available for the operating systems, networked appliances and software they use.”

Experts say Heartbleed is serious and of concern to all Internet users, but that before changing passwords, check to see that the bug has been patched.

"Many are calling for an immediate change to passwords - a call to action I fully endorse with one caveat," said Christopher Burgess, CEO of Prevendra, Inc., an Internet security firm. "If the entity with whom you are about to change your password has not updated their SSL, you are changing your password into an insecure environment.  I advocate checking for the update from your vendor - once they confirm, then change the password to a strong password."

Burgess added that it's important to remember that the problem isn't on your device or machine, but rather on the servers supporting websites we visit each day.

You can check if a website has updated its servers by visiting this Heartbleed testing site.

You May Like

Obama: I Will Do 'Everything I Can' to Close Guantanamo

US president says prison continues 'to inspire jihadists and extremists around the world' More

Sierra Leone Educates on Safe Ebola Burials

Also, country is improving at rapid response to isolated outbreaks, but health workers need to be even faster, officials say More

Christmas Gains Popularity in Vietnam

Increasingly wealthy Vietnamese embrace holiday due to its non-religious glamor, commercial appeal More

This forum has been closed.
Comments
     
There are no comments in this forum. Be first and add one

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
US Decision on Cuba Underscores Divisions Among Miami Cubansi
X
Sharon Behn
December 19, 2014 9:34 PM
For decades, older, more conservative Cubans have been gathering at Café Versailles on the corner of Calle Ocho to eat Cuban food and talk politics. After hearing of President Barack Obama’s decision, a number of them gathered in front of the café with posters to protest. VOA's Sharon Behn reports on the situation.
Video

Video US Decision on Cuba Underscores Divisions Among Miami Cubans

For decades, older, more conservative Cubans have been gathering at Café Versailles on the corner of Calle Ocho to eat Cuban food and talk politics. After hearing of President Barack Obama’s decision, a number of them gathered in front of the café with posters to protest. VOA's Sharon Behn reports on the situation.
Video

Video Three Cities Bid for Future Obama Presidential Library

President Barack Obama still has two years left in his term in office, but the effort to establish his post-presidential library is already underway. The bid for the Obama Presidential Library is down to four locations in three states -- New York, Hawaii, and Illinois. As VOA’s Kane Farabaugh reports, each of them played an important part in the president’s life before he reached the White House.
Video

Video Cuba Deal is Major Victory for Pope’s Diplomatic Initiatives

Pope Francis played a key role in brokering the US-Cuba deal that was made public earlier this week. It is the most stunning success so far in a series of peacemaking efforts by the pontiff. VOA religion reporter Jerome Socolovsky has more.
Video

Video Fears of More Political Gridlock in 2015

2014 proved to be a difficult year politically for President Barack Obama and a very good year for the U.S. Republican Party. Republican gains in the November midterm elections gave them control of the Senate and House of Representatives for the next two years -- setting the stage for more confrontation and gridlock in the final two years of the Obama presidency. VOA National Correspondent Jim Malone has a preview from Washington.
Video

Video Sudan School Becomes Target of Aerial Attacks

The school dropout rate is at an all-time high in Sudan's South Kordofan state because many schools have been destroyed during the three-year civil war between the government and SPLA-N rebel forces. Adam Bailes visited Sudan's Nuba Mountains' region and reports many children are simply too scared to go to school
Video

Video VOA Reporter Tours Devastated Peshawar School

Islamist militants wearing military uniforms and strapped with explosives attacked a military run school Tuesday in the northwestern Pakistani city of Peshawar. At least 141 people were killed in the horrific attack, most of them young students. VOA reporter Ayaz Gul visited the devastated school and attended the funeral of the principal who courageously tried to save her students from the deadly attack.
Video

Video Nigerians Fleeing Boko Haram Languish in Camp Near Capital

In its five-year effort to impose Islamic law in northeastern Nigeria, the Boko Haram extremist group has killed thousands of people and forced hundreds of thousands to flee. Some of those who ran for their lives now live in squalor on the edges of the capital, Abuja. Chris Stein reports for VOA.
Video

Video Aceh Rebuilt Decade After Tsunami, But Scars Remain

On December 26, 2004 there was an earthquake in the Indian Ocean so powerful it caused the Earth’s axis to wobble a few centimeters. Onshore on the island of Sumatra, the resulting tsunami was devastating. A decade later, VOA Correspondent Steve Herman reports from Banda Aceh, Indonesia, where although there is little remaining evidence of the physical devastation, the psychological scars among survivors remain.

All About America

AppleAndroid