News / Science & Technology

'Heartbleed' Flaw Endangers Encrypted Data Online

FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
FILE - A photo shows network cables connected to a server at the CeBIT Computer and IT Far in Hanover, northern Germany.
A glitch in software meant to encrypt and protect online transactions has potentially exposed millions of passwords, credit card numbers and other sensitive bits of information to potential theft by computer hackers.
 
Security researchers at Google and Internet security firm Codenomicon revealed the breakdown, known as "Heartbleed", on Tuesday. The glitch was in a vulnerable version of software known as OpenSSL.  
 
OpenSSL software is meant to protect online accounts for emails, instant messaging and a wide range of electronic commerce.
 
Heartbleed is of particular concern because it went undetected for more than two years, making it difficult for people to know if they’ve been compromised. Security researchers are advising people to consider changing their online passwords.
 
“The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software,” according to the website Heartbleed.com, which was set up by Codenomicon. “This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content.”
 
Codenomicon said it had tested its own services “from an attacker’s perspective" and successfully stolen “usernames and passwords, instant messages, emails and business critical documents” all “without leaving a trace.”
 
The discovery of the bug prompted the U.S. Department of Homeland Security to issue a warning computer users and systems administrators to see whether they’re using OpenSSL.
 
Codenomicon is advising service providers and users to “install the fix as it becomes available for the operating systems, networked appliances and software they use.”

Experts say Heartbleed is serious and of concern to all Internet users, but that before changing passwords, check to see that the bug has been patched.

"Many are calling for an immediate change to passwords - a call to action I fully endorse with one caveat," said Christopher Burgess, CEO of Prevendra, Inc., an Internet security firm. "If the entity with whom you are about to change your password has not updated their SSL, you are changing your password into an insecure environment.  I advocate checking for the update from your vendor - once they confirm, then change the password to a strong password."

Burgess added that it's important to remember that the problem isn't on your device or machine, but rather on the servers supporting websites we visit each day.

You can check if a website has updated its servers by visiting this Heartbleed testing site.

You May Like

Video Positive Messaging Helps Revamp Ethiopia's Image

In country once connected with war, poverty, famine, headlines now focus on fast-growing economy, diplomatic reputation More

Russian Activist Thinks Kremlin Ordered Nemtsov's Death

Alexei Navalny says comments of Russian liberals who think government wasn't involved are 'nonsense.' More

Video Land Disputes Rise Amid Uganda Oil Boom

Investors appear to be cashing in by selling parcels of land to multiple buyers More

This forum has been closed.
Comments
     
There are no comments in this forum. Be first and add one

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
NASA Spacecraft Approaches a Dwarf Planeti
X
George Putic
March 04, 2015 8:51 PM
NASA’s Dawn spacecraft will make history on Friday, March 6, when it becomes the first man-made object to orbit a dwarf planet named Ceres. It is located in the asteroid belt between Mars and Jupiter, almost 500 million kilometers from Earth. Among other objectives, Dawn will try to examine two mysterious bright white spots detected on the planet’s surface. VOA’s George Putic has more.
Video

Video NASA Spacecraft Approaches a Dwarf Planet

NASA’s Dawn spacecraft will make history on Friday, March 6, when it becomes the first man-made object to orbit a dwarf planet named Ceres. It is located in the asteroid belt between Mars and Jupiter, almost 500 million kilometers from Earth. Among other objectives, Dawn will try to examine two mysterious bright white spots detected on the planet’s surface. VOA’s George Putic has more.
Video

Video Young Muslims Radicalized Online

Young Muslims are being radicalized ‘in their bedrooms’ through direct contact with Islamic State or ISIL fighters via the Internet, according to terror experts. There are growing concerns that authorities and Internet providers are not doing enough to counter online extremism - which analysts say is spread by a prolific network of online supporters around the world. Henry Ridgwell reports from London.
Video

Video African Americans Recall 1960's Fight For Voting Rights

U.S. President Barack Obama and thousands of people will gather in the small southern U.S. city of Selma, Alabama, Saturday, March 7th to commemorate the 50th anniversary of a historic voting rights march that became known as “Bloody Sunday." VOA’s Chris Simkins traveled to Alabama and introduces us to some of the foot soldiers of the voting rights struggles of the 1960’s.
Video

Video Positive Messaging Transforms Ethiopia's Image

Ethiopia was once known for famine and droughts. Now, headlines more often point to its fast-growing economy and its emergence as a regional peacemaker. How has Addis Ababa changed the narrative? VOA's Marthe van der Wolf reports.
Video

Video Cyber War Rages Between Iran, US

A newly published report indicates Iran and the United States have increased their cyber attacks on each other, even as their top diplomats are working toward an agreement to guarantee Iran does not develop a nuclear weapon and to free Iran from international sanctions. The development is part of a growing global trend. VOA’s Al Pessin reports from London.
Video

Video Answers Elude Families of MH370 Passengers

For the families on board Malaysia Airlines flight MH370, an airline official’s statement nearly one year ago that the plane had lost contact with air traffic control at 2:40 AM is the only thing that remains confirmed. William Ide reports.
Video

Video Land Disputes Arise Amid Uganda Oil Boom

Ugandan police say there has been a sharp increase in land disputes, with 10 new cases being reported each day. The claims come amid an oil boom as investors appear to be cashing in by selling parcels of land to multiple buyers. Meanwhile, the people who have been living on the land for decades are chased away, sometimes with a heavy hand. VOA's Serginho Roosblad reports.
Video

Video In Russia, Many Doubt Opposition Leader's Killer Will Be Found

The funeral has been held in Moscow for Boris Nemtsov, the opposition leader who was assassinated late Friday just meters from the Kremlin. Nemtsov joins a growing list of outspoken critics of Russia under the leadership of President Vladimir Putin who are believed to have been murdered for their work. VOA’s Daniel Schearf reports from Moscow.
Video

Video Simulated Astronauts Get Taste of Mars, in Hawaii

For generations, people have dreamed of traveling to Mars to explore Earth's closest planetary neighbor. VOA's Mike O'Sullivan reports that while space agencies like NASA are planning manned missions to the planet, some volunteers in Hawaii are learning how humans will cope with months in isolation on a Mars base.
Video

Video Destruction of Iraq Artifacts Shocks Archaeologists

The city of Mosul was once one of the most culturally rich and religiously diverse cities in Iraq. That tradition is under attack by members of the Islamic State who have made Mosul their capital city. The Mosul Museum is the latest target of the group’s campaign of terror and destruction, and is of grave concern to archaeologists around the world. VOA’s Kane Farabaugh reports.
Video

Video Smartphones May Help in Diagnosing HIV

Diagnosing infections such as HIV requires expensive clinical tests, making the procedure too costly for many poor patients or those living in remote areas. But a new technology called lab-on-a-chip may make the tests more accessible to many. VOA’s George Putic reports.
Video

Video Afghan Refugees Complain of Harassment in Pakistan

Afghan officials have expressed concern over reports of a crackdown on Afghan refugees in Pakistan following the Peshawar school attack in December. Reports of mass arrests and police harassment coupled with fear of an uncertain future are making life difficult for a population that fled its homeland to escape war. VOA’s Ayesha Tanzeem reports from Islamabad.

All About America

Circumventing Censorship

An Internet Primer for Healthy Web Habits

As surveillance and censoring technologies advance, so, too, do new tools for your computer or mobile device that help protect your privacy and break through Internet censorship.
More