Welcome Guest ( Log In | Register )

4 Pages V « < 2 3 4  
Closed TopicStart new topic
> The OpenSSL Heartbleed Exploit And You

 
post Apr 12 2014, 20:39
Post #61
redsecret



Lurker
Group: Lurkers
Posts: 1
Joined: 1-November 09
Level 219 (Godslayer)


did the site revoked its previous certificate at the same time the cert was reissued?

This post has been edited by redsecret: Apr 12 2014, 20:41
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 13 2014, 16:25
Post #62
xmagus



Big, Bad and Horny
*******
Group: Members
Posts: 1,042
Joined: 16-July 12
Level 424 (Godslayer)


The answer is to use a password manager, at least until Steve Gibson's SQRL comes into its own, then?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 13 2014, 16:51
Post #63
hzqr



Savagely Still
********
Group: Gold Star Club
Posts: 4,672
Joined: 13-May 09
Level 462 (Dovahkiin)


Heartbleed is (was?) a server-side implementation flaw; a password-manager on the client side is not going to help much (unless you intend to change password very frequently, in which case it may help keeping track of them)
Also...

QUOTE(xmagus @ Apr 13 2014, 14:25) *
Steve Gibson

[attrition.org] Mandatory attrition link
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 15 2014, 01:29
Post #64
treesloth



नो व्हिनिन्ग अल्लोवेद
********
Group: Catgirl Camarilla
Posts: 3,527
Joined: 6-January 13
Level 500 (Ponyslayer)


Thanks for the heads-up Tenboro, guess I will be filing my taxes the old-fashioned way until the the USA govt fixes their junk.

[www.bbc.com] http://www.bbc.com/news/technology-27028101
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 15 2014, 02:06
Post #65
j1776



Newcomer
*
Group: Gold Star Club
Posts: 40
Joined: 22-June 10
Level 32 (Journeyman)


Here's a few ideas that might help:

My most important accounts use MFA (Multi-Factor Authentication)

That means either a Personal image/phrase or a 6 digit number sent by SMS in addition to the password in order to log in.


I use LastPass to generate strong passwords and their $12 annual subscription to access my passwords in the cloud.

I also know an onscreen keyboard is not vulnerable to keystroke loggers, because all they get are mouse clicks.

Finally when choosing an answer to a challenge question, I don't use information that can be easily looked up such as the high school I attended or an employer.

I'm hoping this throws a few chairs in the way of the bad guys.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 15 2014, 02:17
Post #66
blue penguin



in umbra, igitur, pugnabimus
***********
Group: Gold Star Club
Posts: 10,046
Joined: 24-March 12
Level 500 (Godslayer)


QUOTE(j1776 @ Apr 15 2014, 01:06) *
sent by SMS

(IMG:[invalid] style_emoticons/default/rolleyes.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 15 2014, 03:36
Post #67
EsotericSatire



Look, Fat.
***********
Group: Catgirl Camarilla
Posts: 12,672
Joined: 31-July 10
Level 500 (Ponyslayer)


There have been instances where authenticator output has been intercepted, I think it either requires a bug in the way the numbers are generated or root-kits to be installed in the past.

If an attacker or Indian Microsoft tech support scammer have remote access using an onscreen keyboard won't do much.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 15 2014, 05:03
Post #68
j1776



Newcomer
*
Group: Gold Star Club
Posts: 40
Joined: 22-June 10
Level 32 (Journeyman)


QUOTE(blue penguin @ Apr 15 2014, 02:17) *


I don't use Windows, so there goes remote access or rootkits.

They would have to intercept that code, best way is to take my phone.

But then that would be the least of my problems.

I'm open to better ideas.

This post has been edited by j1776: Apr 15 2014, 05:58
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 15 2014, 05:48
Post #69
j1776



Newcomer
*
Group: Gold Star Club
Posts: 40
Joined: 22-June 10
Level 32 (Journeyman)


QUOTE(EsotericSatire @ Apr 15 2014, 03:36) *

There have been instances where authenticator output has been intercepted, I think it either requires a bug in the way the numbers are generated or root-kits to be installed in the past.

If an attacker or Indian Microsoft tech support scammer have remote access using an onscreen keyboard won't do much.


Well providing I use Windows for my important internet work. (IMG:[invalid] style_emoticons/default/smile.gif)

I've had years of knowing how to secure Windows, but even then, it's a crook magnet. There are teams of professional hackers who do this 24/7 and Windows is their target. Cryptolocker finally got me to change.
I wasn't hit by it, but I know it's time to get out of Dodge. (IMG:[invalid] style_emoticons/default/mellow.gif)

I still use my Dell laptop, but I keep important files and business away from it.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 16 2014, 03:40
Post #70
j1776



Newcomer
*
Group: Gold Star Club
Posts: 40
Joined: 22-June 10
Level 32 (Journeyman)


Now it's Android devices. But there's an app that can check your phone.

[www.huffingtonpost.com] http://www.huffingtonpost.com/2014/04/15/h..._n_5153812.html

This post has been edited by j1776: Apr 16 2014, 03:40
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 17 2014, 02:05
Post #71
noneya



BRAVO! OH BRAVO!!!
*******
Group: Gold Star Club
Posts: 1,965
Joined: 24-September 09
Level 455 (Godslayer)


Im surprised folks just read that news today from this pages comments.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 18 2014, 03:20
Post #72
COBRARocky



Newcomer
*
Group: Members
Posts: 20
Joined: 7-April 11


damn. this is scary.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 18 2014, 11:29
Post #73
cielzero



Newcomer
*
Group: Members
Posts: 20
Joined: 10-January 13
Level 10 (Novice)


Well, only hope someone can fix it.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 20 2014, 06:19
Post #74
Sticky_Kitty



Newcomer
*
Group: Members
Posts: 20
Joined: 8-October 11
Level 58 (Expert)


I don't understand any of this. It only flips my paranoia switch ON.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 20 2014, 14:27
Post #75
Maddox1521



Newcomer
*
Group: Members
Posts: 27
Joined: 17-April 14


What
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 29 2014, 15:06
Post #76
laughhe



Newcomer
*
Group: Members
Posts: 23
Joined: 2-January 12
Level 32 (Apprentice)


The internet is not exactly a safe haven... so the more reason for us to be exercise caution and change your passwords! :S
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 29 2014, 23:01
Post #77
WashOxide



Newcomer
*
Group: Members
Posts: 24
Joined: 29-August 10


Fine, I didn't like my dumb smart phone anyways, it was probably long past time to change it.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Apr 30 2014, 13:13
Post #78
Freedomno1



Casual Poster
***
Group: Members
Posts: 124
Joined: 25-January 10
Level 363 (Godslayer)


Forgot to mention there was a way to detect heartbleed in the wild now
Can source check code on Github
[filippo.io] https://filippo.io/Heartbleed/
User is offlineProfile CardPM
Go to the top of the page
+Quote Post


4 Pages V « < 2 3 4
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


Lo-Fi Version Time is now: 6th July 2025 - 12:44