Page 1 of 2 1 2 LastLast
Results 1 to 20 of 23
  1. #1
    Banned.

    Join Date
    Jun 2008
    Posts
    6,514
    BG Level
    8
    FFXI Server
    Phoenix

    Heartbleed Bug AKA Internet Apocalypse 2014 AKA CHANGE ALL THE PASSWORDS (EXCEPT PORN MAYBE)

    Security flaw in OpenSSL encryption means that up to 66% of the websites in the world are affected by this. They're calling it the biggest internet security threat ever. FYI it's been there for over 2 years and they just found it recently. Changing your password is only recommended for websites that have taken action to remove the security threat. Therefore, outside of the big popular websites, you'll have to contact the website/server and ask them if your information is in danger. Banks are not affected, but if your password is the same as something else, you should change those too.

    Here's How To Protect Yourself From The Massive Security Flaw That's Taken Over The Internet

    The Heartbleed Hit List: The Passwords You Need to Change Right Now

    Testing site for vulnerability

  2. #2
    BG Content
    Join Date
    Oct 2005
    Posts
    69,492
    BG Level
    10
    FFXIV Character
    Six Souls
    FFXIV Server
    Gilgamesh
    FFXI Server
    Quetzalcoatl
    WoW Realm
    Malorne
    Blog Entries
    9

    It only affects servers that haven't been patched with the April 7th update, but it is still recommended to change passwords.

  3. #3
    Nidhogg
    Join Date
    Apr 2007
    Posts
    3,895
    BG Level
    7

    Ah, fuck it at this point. Five hundred websites, at least 5 passwords, so so so many accounts. Dumb it down for me, should I really be worried about my nudies in my email? Fuck it.

  4. #4
    Banned.

    Join Date
    Jun 2008
    Posts
    6,514
    BG Level
    8
    FFXI Server
    Phoenix

    Depends on which email system you use, but this bug has been around for 2 years. So potentially, yes.

  5. #5
    hey
    hey is offline
    listen!
    Join Date
    Apr 2011
    Posts
    7,234
    BG Level
    8
    FFXI Server
    Sylph

    I like on that hit list when they say they have no reason to believe any data was compromised, even though there would never be any evidence of it if it had been.

  6. #6
    Resident Moogle
    Join Date
    Mar 2007
    Posts
    13,185
    BG Level
    9
    FFXI Server
    Asura

    A reminder that password managers are awesome and you should be using one. Easiest way to keep track of which sites you have accounts on.

    Still a horrible wake-up call for web servers across the world though

  7. #7
    Hyperion Cross
    Join Date
    Jan 2007
    Posts
    8,885
    BG Level
    8
    FFXIV Character
    Kai Bond
    FFXIV Server
    Gilgamesh

    Quick odd question but just trying to get my head around it.

    This only affects sites using SSL (sites that have https in the url) right? So sites with no encryption are fine (such as BG)?

  8. #8
    hey
    hey is offline
    listen!
    Join Date
    Apr 2011
    Posts
    7,234
    BG Level
    8
    FFXI Server
    Sylph

    Quote Originally Posted by The Stig View Post
    Quick odd question but just trying to get my head around it.

    This only affects sites using SSL (sites that have https in the url) right? So sites with no encryption are fine (such as BG)?
    Yes. Not all sites using ssl either, just ones using any openssl version from the last 2 years or so. Older versions, or other ssl libraries are unaffected. However it's likely that most sites are.

  9. #9
    Hyperion Cross
    Join Date
    Jan 2007
    Posts
    8,885
    BG Level
    8
    FFXIV Character
    Kai Bond
    FFXIV Server
    Gilgamesh

    Thanks, that's great thanks for confirming. The severe doubts/worry/panic of people here got myself paranoid despite being self-assured that logically a lot of our stuff is unaffected (1: I checked through the tools available, 2: we use IIS, 3: openssl is a bit more unix based).

    No one wants to trust me for some reason

  10. #10
    hey
    hey is offline
    listen!
    Join Date
    Apr 2011
    Posts
    7,234
    BG Level
    8
    FFXI Server
    Sylph

    Not everything is affected, but probably like half of everything using ssl is/was. It's pretty serious.

  11. #11
    Pandemonium
    Join Date
    Jul 2008
    Posts
    4,875
    BG Level
    7
    FFXI Server
    Bismarck

    Quote Originally Posted by Kaisha View Post
    A reminder that password managers are awesome and you should be using one. Easiest way to keep track of which sites you have accounts on.
    This is why I thought it was rather hilarious when I saw that LastPass was one of those affected.

  12. #12
    Brown Recluse
    Sweaty Dick Punching Enthusiast

    Join Date
    May 2006
    Posts
    28,144
    BG Level
    10
    FFXI Server
    Unicorn

    I just ran through the list and pornhub and xvideos are safe. Just an FYI

    World of tanks is a different story lol

  13. #13
    Leader of the Brain Eating Space Monkeys
    Join Date
    Dec 2009
    Posts
    425
    BG Level
    4
    FFXI Server
    Ramuh

    Quote Originally Posted by Dimmauk View Post
    I just ran through the list and pornhub and xvideos are safe. Just an FYI
    oh thank god!

  14. #14
    A. Body
    Join Date
    Apr 2007
    Posts
    3,939
    BG Level
    7

    wait, why do you guys have log ins to those...?

    EDIT: just worried I'm missing out on some great porn and only have access to a partial library.

  15. #15
    Ridill
    Join Date
    Jul 2008
    Posts
    11,251
    BG Level
    9

    Quote Originally Posted by 6souls View Post
    It only affects servers that haven't been patched with the April 7th update, but it is still recommended to change passwords.
    While it only effects said servers, the greater issue is if the servers that are doing the updating are legit. Seeing as you can steal certificates using this bug it complicates a shit load. Basically even if the servers have patched, until they issue new certs, updating passwords isn't going to do shit if someone is using this in the wild.

    Also the vuln checker may not work properly up there. Troy Hunt tweeted earlier showing how he checked the same site twice and had 2 different results spit back to him.

    wait, why do you guys have log ins to those...?
    lol this. Only account I have is to video.anonib since you have to have one to view some vids.

    A reminder that password managers are awesome and you should be using one. Easiest way to keep track of which sites you have accounts on.
    Google Chrome even has a password generator option for when it detects forms. You have to enable it by going into chrome://flags/ and turning it on. Pretty good if you use Chrome to save passwords, allowing you to use large passwords that a simple facebook scan/dictionary attack won't break

  16. #16
    Black Belt
    Join Date
    Apr 2005
    Posts
    5,923
    BG Level
    8
    FFXI Server
    Bahamut

    Quote Originally Posted by Penthesilea View Post
    wait, why do you guys have log ins to those...?
    So you can make a list of your favorite videos without trying to remember which of the 6000 "Foot Job Threesome Interacial Bukakke" videos it was. You can do that with a free login, at least on Xhamster and pornhub.

  17. #17
    Brown Recluse
    Sweaty Dick Punching Enthusiast

    Join Date
    May 2006
    Posts
    28,144
    BG Level
    10
    FFXI Server
    Unicorn

    Need to add AKA YOUR PORN IS SAFE to the title

  18. #18
    Relic Shield
    Join Date
    Apr 2010
    Posts
    1,544
    BG Level
    6
    FFXIV Character
    Azull Abaddon
    FFXIV Server
    Cactuar
    FFXI Server
    Leviathan

    xkcd, which you should read anyways, seems to have the best summary of how the fuck this happens that I have seen.
    http://xkcd.com/1354/

  19. #19
    Ridill
    Join Date
    Jul 2008
    Posts
    11,251
    BG Level
    9

    http://en.wikipedia.org/wiki/Data_validation

    https://www.owasp.org/index.php/Inpu...on_Cheat_Sheet

    This sort of shit happens all the time, but this is on a huge scale. Also like the comic states, it dispenses random sections of 16kb worth of memory, so I guess you can HOPE your shit wasn't in memory at the time of an attack if it was used in the wild! haha

    Here's something else fun for people to do that are using windows if you want to fuck around with your memory!

    http://carnal0wnage.attackresearch.c...z-via-bat.html

    http://blog.gentilkiwi.com/securite/mimikatz/minidump

  20. #20
    Banned.

    Join Date
    Jun 2008
    Posts
    6,514
    BG Level
    8
    FFXI Server
    Phoenix

    900 Social Insurance Numbers stolen from Revenue Canada

    Not sure how they know these were compromised. I thought the exploit didn't leave a trail. Also, I have a feeling this was incompetence, as it sounds like the information was stolen AFTER the exploit was made public, which means someone did it right before they patched it up.

Page 1 of 2 1 2 LastLast

Similar Threads

  1. Who is making all of the current changes to the site
    By Dense in forum General Discussion
    Replies: 1
    Last Post: 2007-04-19, 05:19