News / Science & Technology

'Heartbleed' Flaw Endangers Encrypted Data Online

FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
A glitch in software meant to encrypt and protect online transactions has potentially exposed millions of passwords, credit card numbers and other sensitive bits of information to potential theft by computer hackers.
 
Security researchers at Google and Internet security firm Codenomicon revealed the breakdown, known as "Heartbleed", on Tuesday. The glitch was in a vulnerable version of software known as OpenSSL.  
 
OpenSSL software is meant to protect online accounts for emails, instant messaging and a wide range of electronic commerce.
 
Heartbleed is of particular concern because it went undetected for more than two years, making it difficult for people to know if they’ve been compromised. Security researchers are advising people to consider changing their online passwords.
 
“The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software,” according to the website Heartbleed.com, which was set up by Codenomicon. “This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content.”
 
Codenomicon said it had tested its own services “from an attacker’s perspective" and successfully stolen “usernames and passwords, instant messages, emails and business critical documents” all “without leaving a trace.”
 
The discovery of the bug prompted the U.S. Department of Homeland Security to issue a warning computer users and systems administrators to see whether they’re using OpenSSL.
 
Codenomicon is advising service providers and users to “install the fix as it becomes available for the operating systems, networked appliances and software they use.”

Experts say Heartbleed is serious and of concern to all Internet users, but that before changing passwords, check to see that the bug has been patched.

"Many are calling for an immediate change to passwords - a call to action I fully endorse with one caveat," said Christopher Burgess, CEO of Prevendra, Inc., an Internet security firm. "If the entity with whom you are about to change your password has not updated their SSL, you are changing your password into an insecure environment.  I advocate checking for the update from your vendor - once they confirm, then change the password to a strong password."

Burgess added that it's important to remember that the problem isn't on your device or machine, but rather on the servers supporting websites we visit each day.

You can check if a website has updated its servers by visiting this Heartbleed testing site.

You May Like

Tunnel Bombs Highlight Savagery of Aleppo Fight

Rebels have used tunneling tactic near government buildings, command posts or supply routes to set off explosives; they detonated their largest bomb this week under Syria's intelligence headquarters More

Sierra Leone Launches New Initiative to Stop Ebola Spread

Government hopes Infection and Prevention Control Units, IPC, will help protect patients and healthcare workers More

UN Official: Fight Against Terrorism Must Not Violate Human Rights

UN High Commissioner for Human Rights says efforts by states to combat terrorism are resulting in large scale rights violations against the very citizens they claim to defend More

This forum has been closed.
Comments
     
There are no comments in this forum. Be first and add one

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Video Claims to Show Shia Forces in Iraq Executing Sunni Boyi
X
Jeff Seldin
March 05, 2015 2:36 AM
A graphic mobile phone video is spreading on the Internet, claiming to show Iraqi forces or Shia militia executing a handcuffed Sunni boy. Experts have yet to verify the video, but already Islamic State followers are publicizing it across social media, playing on deep-rooted sectarian fears. VOA’s Jeff Seldin reports.
Video

Video Video Claims to Show Shia Forces in Iraq Executing Sunni Boy

A graphic mobile phone video is spreading on the Internet, claiming to show Iraqi forces or Shia militia executing a handcuffed Sunni boy. Experts have yet to verify the video, but already Islamic State followers are publicizing it across social media, playing on deep-rooted sectarian fears. VOA’s Jeff Seldin reports.
Video

Video Ukrainian Authorities Struggle to Secure a Divided Mariupol

Since last month's cease-fire went into effect, shelling around the port city of Mariupol has decreased, but it is thought pro-Russian separatists remain poised to attack. For the city’s authorities, a major challenge is gaining the trust of residents, while at the same time rooting out informants who are passing sensitive information to the rebels. Patrick Wells reports for VOA.
Video

Video Volunteer Gauge-Watchers Help Fine-Tune Weather Science

An observation system called CoCoRaHS is working to improve weather science, thanks to thousands of volunteers across the country who measure precipitation in their own backyards, then share their data through the Internet. VOA's Shelley Schlender reports.
Video

Video NASA Spacecraft Approaches a Dwarf Planet

NASA’s Dawn spacecraft will make history on Friday, March 6, when it becomes the first man-made object to orbit a dwarf planet named Ceres. It is located in the asteroid belt between Mars and Jupiter, almost 500 million kilometers from Earth. Among other objectives, Dawn will try to examine two mysterious bright white spots detected on the planet’s surface. VOA’s George Putic has more.
Video

Video Young Muslims Radicalized Online

Young Muslims are being radicalized ‘in their bedrooms’ through direct contact with Islamic State or ISIL fighters via the Internet, according to terror experts. There are growing concerns that authorities and Internet providers are not doing enough to counter online extremism - which analysts say is spread by a prolific network of online supporters around the world. Henry Ridgwell reports from London.
Video

Video African Americans Recall 1960s Fight For Voting Rights

U.S. President Barack Obama and thousands of people will gather in the small southern U.S. city of Selma, Alabama, Saturday, March 7 to commemorate the 50th anniversary of a historic voting rights march that became known as “Bloody Sunday." VOA’s Chris Simkins traveled to Alabama and introduces us to some of the foot soldiers of the voting rights struggles of the 1960s.
Video

Video Positive Messaging Transforms Ethiopia's Image

Ethiopia was once known for famine and droughts. Now, headlines more often point to its fast-growing economy and its emergence as a regional peacemaker. How has Addis Ababa changed the narrative? VOA's Marthe van der Wolf reports.
Video

Video Cyber War Rages Between Iran, US

A newly published report indicates Iran and the United States have increased their cyber attacks on each other, even as their top diplomats are working toward an agreement to guarantee Iran does not develop a nuclear weapon and to free Iran from international sanctions. The development is part of a growing global trend. VOA’s Al Pessin reports from London.
Video

Video Answers Elude Families of MH370 Passengers

For the families on board Malaysia Airlines flight MH370, an airline official’s statement nearly one year ago that the plane had lost contact with air traffic control at 2:40 AM is the only thing that remains confirmed. William Ide reports.

All About America

Circumventing Censorship

An Internet Primer for Healthy Web Habits

As surveillance and censoring technologies advance, so, too, do new tools for your computer or mobile device that help protect your privacy and break through Internet censorship.
More