[ EPU Foyer ] [ Lab and Grill ] [ Bonus Theater!! ] [ Rhetorical Questions ] [ CSRANTronix ] [ GNDN ] [ Subterranean Vault ] [ Discussion Forum ] [ Gun of the Week ]

Eyrie Productions, Unlimited

Subject: "Heartbleeed?"     Previous Topic | Next Topic
Printer-friendly copy    
Conferences The Forum Itself Topic #82
Reading Topic #82
JeanneHedge
Charter Member
933 posts
Apr-11-14, 08:44 PM (EDT)
Click to EMail JeanneHedge Click to send private message to JeanneHedge Click to view user profileClick to add this user to your buddy list  
"Heartbleeed?"
 
   While I realize this forum is most probably low priority for any hackers, are there any concerns related to the Heartbleed bug here?


Jeanne



Jeanne Hedge
http://www.jhedge.com
"Never give up, never surrender!"


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top

  Subject     Author     Message Date     ID  
Heartbleeed? [View All] JeanneHedge Apr-11-14 TOP
  RE: Heartbleeed? Gryphonadmin Apr-11-14 1
     RE: Heartbleeed? MuninsFire Apr-11-14 2
         RE: Heartbleeed? TheOtherSean Apr-11-14 3
             RE: Heartbleeed? MuninsFire Apr-12-14 4
         RE: Heartbleeed? Terminus Est Apr-12-14 5
             RE: Heartbleeed? SpottedKitty Apr-12-14 6
                 RE: Heartbleeed? MuninsFire Apr-12-14 7
                     RE: Heartbleeed? Terminus Est Apr-13-14 8
                     RE: Heartbleeed? Senji Apr-13-14 9
                         RE: Heartbleeed? laudre Apr-14-14 10
                         RE: Heartbleeed? MuninsFire Apr-14-14 11

Conferences | Topics | Previous Topic | Next Topic
Gryphonadmin
Charter Member
22411 posts
Apr-11-14, 08:52 PM (EDT)
Click to EMail Gryphon Click to send private message to Gryphon Click to view user profileClick to add this user to your buddy list  
1. "RE: Heartbleeed?"
In response to message #0
 
   >While I realize this forum is most probably low priority for any
>hackers, are there any concerns related to the Heartbleed bug here?

Ironically, I don't think the Forum is even secure enough that a fault in a security protocol is an issue. I know Dave reset the server's host key for SSH/SFTP purposes, though.

--G.
-><-
Benjamin D. Hutchins, Co-Founder, Editor-in-Chief, & Forum Mod
Eyrie Productions, Unlimited http://www.eyrie-productions.com/
zgryphon at that email service Google has
Ceterum censeo Carthaginem esse delendam.


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top
MuninsFire
Member since Mar-27-07
457 posts
Apr-11-14, 11:28 PM (EDT)
Click to EMail MuninsFire Click to send private message to MuninsFire Click to view user profileClick to add this user to your buddy list  
2. "RE: Heartbleeed?"
In response to message #1
 
   Infosec guy here.

Basically, no problem here.

This site:

http://possible.lv/tools/hb/?domain=www.eyrie-productions.com

provides a test for the heartbleed issue, and has proven reliable enough over the past week for me to recommend it.

There's a pretty good explanation for heartbleed and what it means for you here: http://r000t.com/what-heartbleed-means-to-you/

Basically, the advice I've been giving my clients and other people whom I'm responsible for is to be careful, make sure your browser checks for certificate revocation, and change all your passwords--because you should be changing them on a regular basis anyway.

Do NOT click on any email links to reset passwords; log into the site manually and change it there. There will be hundreds of phishing emails from this event.

If you have any questions, feel free to ask me; you can email me at my username at the gmails if you wish.

In Xanadu did Kubla Khan
A stately pleasure-dome decree
Where Alph, the sacred river, ran
Through caverns measureless to man
Down to a sunless sea


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top
TheOtherSean
Member since Jul-7-08
246 posts
Apr-11-14, 11:37 PM (EDT)
Click to EMail TheOtherSean Click to send private message to TheOtherSean Click to view user profileClick to add this user to your buddy list  
3. "RE: Heartbleeed?"
In response to message #2
 
   Heartbleed: This is probably the only thing that's ever made me glad my web applications at work are hosted by IIS on a Windows server. :)

--
The Other Sean - Don't accept substitutes!
Quis Custodiet Ipsos Custodes?


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top
MuninsFire
Member since Mar-27-07
457 posts
Apr-12-14, 00:10 AM (EDT)
Click to EMail MuninsFire Click to send private message to MuninsFire Click to view user profileClick to add this user to your buddy list  
4. "RE: Heartbleeed?"
In response to message #3
 
   Yeah, was talking with someone the other day who hosts via Tomcat, and we were amused that this is perhaps the only time ever that Java has been the MORE secure option.

In Xanadu did Kubla Khan
A stately pleasure-dome decree
Where Alph, the sacred river, ran
Through caverns measureless to man
Down to a sunless sea


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top
Terminus Est
Member since Nov-5-04
573 posts
Apr-12-14, 01:10 PM (EDT)
Click to EMail Terminus%20Est Click to send private message to Terminus%20Est Click to view user profileClick to add this user to your buddy list  
5. "RE: Heartbleeed?"
In response to message #2
 
   This describes the bug in layman-friendly stick figure art and terms.


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top
SpottedKitty
Member since Jun-15-04
605 posts
Apr-12-14, 01:36 PM (EDT)
Click to EMail SpottedKitty Click to send private message to SpottedKitty Click to view user profileClick to add this user to your buddy list  
6. "RE: Heartbleeed?"
In response to message #5
 
   The bug actually works like that? It's not too much of a lies-to-children oversimplification? <headdesk>

--
Unable to save the day: File is read-only.


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top
MuninsFire
Member since Mar-27-07
457 posts
Apr-12-14, 02:08 PM (EDT)
Click to EMail MuninsFire Click to send private message to MuninsFire Click to view user profileClick to add this user to your buddy list  
7. "RE: Heartbleeed?"
In response to message #6
 
   Pretty much, after you strip away some protocol bits, yeah. It's usually not a word like "potato" or "hat" or what have you, but some random numbers your computer generates.

This particular type of problem is nothing new; it's been an issue in programming for decades, but the people (staff of four, total, of which one is full-time) who develop OpenSSL are -extremely- underfunded and don't get a whole lot of time to audit for that kind of bug.

There's a LOT of software that's in extremely widespread use that has the potential to contain bugs this severe due to very similar circumstances.

For instance, for a number of years, THE database of time zone info was maintained almost entirely by one guy.

Things like browsers and word processors--the stuff people use--is sexy. Things like crypto libraries and the other stuff "under the hood" that people don't directly use? Not a lot of attention there.

In Xanadu did Kubla Khan
A stately pleasure-dome decree
Where Alph, the sacred river, ran
Through caverns measureless to man
Down to a sunless sea


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top
Terminus Est
Member since Nov-5-04
573 posts
Apr-13-14, 12:42 PM (EDT)
Click to EMail Terminus%20Est Click to send private message to Terminus%20Est Click to view user profileClick to add this user to your buddy list  
8. "RE: Heartbleeed?"
In response to message #7
 
   I must admit, I'm no programmer - about the best I can lay claim to is some mucking about with object-oriented stuff in a MU* a couple times. So I kind of thought it probably *was* an oversimplification, but hey, it works for me as a general layperson. :)


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top
Senji
Member since Apr-27-07
260 posts
Apr-13-14, 10:01 PM (EDT)
Click to EMail Senji Click to send private message to Senji Click to view user profileClick to add this user to your buddy list  
9. "RE: Heartbleeed?"
In response to message #7
 
   >There's a LOT of software that's in extremely widespread use that has
>the potential to contain bugs this severe due to very similar
>circumstances.

It's not just open/free software either, you see a lot of similar bugs in commercial software; where you don't realise there aren't many devs working on stuff.

>Things like browsers and word processors--the stuff people use--is
>sexy. Things like crypto libraries and the other stuff "under the
>hood" that people don't directly use? Not a lot of attention there.

Sadly being sexy doesn't really help them, because most of the sexy-attention goes into new features and bling, and tends to leave the important core code looking like a pile of spaghetti left by ADHD monkeys as people poke it to put their new thing in.

In general software maintanence and checking is not interesting to most people.

S.

(who loves breaking software)


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top
laudre
Member since Nov-14-06
428 posts
Apr-14-14, 07:48 AM (EDT)
Click to EMail laudre Click to send private message to laudre Click to view user profileClick to add this user to your buddy list Click to send message via AOL IM  
10. "RE: Heartbleeed?"
In response to message #9
 
   > In general software maintanence and checking is not interesting to
>most people.

Well, to be fair, there's a reason for that.


"Mathematics brought rigor to economics. Unfortunately, it also brought mortis."
- Kenneth Boulding


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top
MuninsFire
Member since Mar-27-07
457 posts
Apr-14-14, 09:14 AM (EDT)
Click to EMail MuninsFire Click to send private message to MuninsFire Click to view user profileClick to add this user to your buddy list  
11. "RE: Heartbleeed?"
In response to message #9
 
   Yes, you're entirely correct--nonfree, nonopen software will have just as many bugs, but users will be at the mercy of a single entity to get it fixed, which entity may or may not prioritize security-related bugfixes (and, in some cases, will send the cops after people who report those kind of bugs) and who may demand you upgrade to the 'new version' after paying 'em.

And you are correct also about the nature of the non-fun-parts code, though that's less a concern in non-security-critical infrastructure and may occasionally benefit from professional-quality rewrites and audits.

And this would be why I have, up until very recently, stayed as far from dev work as possible: ops for life! ;-P

In Xanadu did Kubla Khan
A stately pleasure-dome decree
Where Alph, the sacred river, ran
Through caverns measureless to man
Down to a sunless sea


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top

Conferences | Topics | Previous Topic | Next Topic

[ YUM ] [ BIG ] [ ??!? ] [ RANT ] [ GNDN ] [ STORE ] [ FORUM ] GOTW ] [ VAULT ]

version 3.3 © 2001
Eyrie Productions, Unlimited
Benjamin D. Hutchins
E P U (Colour)