Pennsylvania Firearm Owners Association
Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: Heartbleed bug

  1. #1
    Join Date
    Jan 2014
    Location
    Hunlock Creek, Pennsylvania
    (Luzerne County)
    Age
    79
    Posts
    433
    Rep Power
    6866005

    Default Heartbleed bug

    I do not know if this will affect this board or not.
    NOT a joke.




    http://heartbleed.com/

  2. #2
    Join Date
    Jan 2007
    Location
    Pittsburgh, Pennsylvania
    (Allegheny County)
    Posts
    33,638
    Rep Power
    21474887

    Default Re: Heartbleed bug

    I wonder if I could use one of those online foreign language translators for that?
    I called to check my ZIP CODE!....DY-NO-MITE!!!

  3. #3
    Join Date
    Oct 2013
    Location
    'burbs, Pennsylvania
    (Bucks County)
    Posts
    788
    Rep Power
    21474847

    Default Re: Heartbleed bug

    Here’s a tool my daughter who works with 'futers sent me. Use it to check individual sites (make sure to be very exact such as testing mail.yahoo.com instead of just Yahoo.com):

    http://filippo.io/Heartbleed/

    I've checked my key sites and they are clean.

    OTOH, I can't get it to work with PAFOA.

  4. #4
    Join Date
    Jan 2014
    Location
    Hunlock Creek, Pennsylvania
    (Luzerne County)
    Age
    79
    Posts
    433
    Rep Power
    6866005

    Default Re: Heartbleed bug

    OTOH, I can't get it to work with PAFOA.
    Guns scare it.

  5. #5
    Join Date
    Aug 2011
    Location
    Moscow, Pennsylvania
    (Lackawanna County)
    Posts
    4,029
    Rep Power
    21474853

    Default Re: Heartbleed bug

    Ni its not and unfortunately its a hit too late. Its been in the wild fr quite some time. Now everyone is scrambling to patch it. When it was announced it wasnt such a big deal and then blew up overnight as the brevity of it hit home. I had over 40 emails relating to this alone this morning.

  6. #6
    Join Date
    Aug 2011
    Location
    Moscow, Pennsylvania
    (Lackawanna County)
    Posts
    4,029
    Rep Power
    21474853

    Default Re: Heartbleed bug

    Its not sites like pafoa that you need to be worried about. Its sites that have access to persinably identifiable information or bank account and routing numbers etc. No one wants your username and password. They want what is going to make money.

  7. #7
    Join Date
    Oct 2011
    Location
    Pittsburgh, Pennsylvania
    (Allegheny County)
    Posts
    578
    Rep Power
    3042247

    Default Re: Heartbleed bug

    Unfortunately the patch is not enough to know your site is secure. If a web pirate already seized the private key from the server it is not safe to use until the certificates have also been replaced.

    I am waiting on a bunch of replacement certificates

  8. #8
    Join Date
    Oct 2013
    Location
    'burbs, Pennsylvania
    (Bucks County)
    Posts
    788
    Rep Power
    21474847

    Default Re: Heartbleed bug

    Quote Originally Posted by NathanB View Post
    Its not sites like pafoa that you need to be worried about. Its sites that have access to persinably identifiable information or bank account and routing numbers etc. No one wants your username and password. They want what is going to make money.
    True as long as you use different logins and passwords for finance and social media.

  9. #9
    Join Date
    Feb 2010
    Location
    Downingtown
    (Chester County)
    Posts
    281
    Rep Power
    26278

    Default Re: Heartbleed bug

    It's indeed a major deal. I work for financial services company and we patched for it on Monday night as soon as we got wind of it. We also pulled all of our SSL certificates and Keys and reissued them, since there is no way to know if your site has been compromised. Giant pain in the ass, but you have to assume that you have been hit.

    https://bugs.debian.org/cgi-bin/bugr...cgi?bug=743883
    Last edited by rockstrongo; April 9th, 2014 at 10:05 PM. Reason: add link to exploit.

  10. #10
    Join Date
    May 2010
    Location
    moved to warmer weather..., Tennessee
    Posts
    1,232
    Rep Power
    1719203

    Default Re: Heartbleed bug

    I had a major panic attack when I heard the news as I have an online site for my practice. Fortunately, they don't use the vulnerable SSL/TSL but I changed all passwords just in case.

    I also don't keep SS# and financial info so that reduces the risk.

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •