Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Team California
 
speeder's Avatar
 
Join Date: Jul 2001
Location: los angeles, CA.
Posts: 41,195
Garage
"Heartbug" virus question:

Do I now have to change my PW on every site that has the padlock icon on address bar, like ebay/paypal, etc...?

Is it too late? Did the boogeyman in Russia, or wherever, already steal all my info?

Enquiring minds want to know.

Old 04-09-2014, 06:13 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
It'll be legen-waitforit
 
stealthn's Avatar
 
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,979
No only some sites are affected. OpenSSL sites, it's been in the wild a long time so they would have got what they needed by now
Old 04-09-2014, 07:28 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 55,915
No point in changing your password until you have confirmed that the site has "fixed the glitch". If the site hasn't updated to mitigate the bug, and you change your password, then you are potentially just giving them your new password.
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 04-09-2014, 07:29 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Registered
 
Paul_Heery's Avatar
 
Join Date: Dec 2001
Location: Elsewhere, CT
Posts: 2,122
Garage
If you are concerned about the sites you visit, Qualsys has updated their SSL test to check for Heartbleed vulns.

https://www.ssllabs.com/ssltest/index.html
Old 04-10-2014, 02:15 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
You do not have permissi
 
john70t's Avatar
 
Join Date: Aug 2001
Location: midwest
Posts: 39,850
There's supposedly a civilian version of Stuxnet virus which can jump air gaps:
BadBios Virus: 5 Fast Facts You Need to Know | HEAVY
The “BadBIOS” virus that jumps airgaps and takes over your firmware – what’s the story? | Naked Security

Ultimate power corrupts, ultimately.
Old 04-10-2014, 05:46 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
Registered
 
mikester's Avatar
 
Join Date: Mar 2002
Location: My House
Posts: 5,345
Send a message via AIM to mikester
Quote:
Originally Posted by Paul_Heery View Post
If you are concerned about the sites you visit, Qualsys has updated their SSL test to check for Heartbleed vulns.

https://www.ssllabs.com/ssltest/index.html
Love those guys. Excellent link - thanks for that.

Basically if a site is using this version of OpenSSL for their encryption then someone can listen for the traffic, copy it, decrypt it and your username and password for that password might be in it.

If it is, well you could have given access to your bank to someone.

This is why two-factor authentication is so important for things that matter. If you had a regular password and then a one time password from somewhere else then getting the one password would not compromise you. The one time password you also have changes every time and you have some 'thing' either an app on your computer/smart device or a fob that creates the one time password. They would get that password which isn't good for more than one login.

Anyway.

I hate it when encryption bugs happen.
__________________
-The Mikester

I heart Boobies
Old 04-10-2014, 07:09 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
Run smooth, run fast
 
Heel n Toe's Avatar
 
Join Date: Aug 2008
Location: South Carolina
Posts: 13,447
C|NET's list of top 100 sites that have been patched...

...along with those that haven't... and those that supposedly were never vulnerable:

Heartbleed bug: Check which sites have been patched - CNET

__________________
- John
"We had a band powerful enough to turn goat piss into gasoline."
Old 04-13-2014, 11:36 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
Reply


 


All times are GMT -8. The time now is 09:00 AM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.