# Heartbleed Openssl Bug

**URL:** https://forums.speedlife.net/t/heartbleed-openssl-bug/268950
**Category:** NYSpeed Off Topic
**Created:** [April 7, 2014, 5:26pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950 "2014-04-07T17:26:50Z")
**Posts on this page:** 20
**Page:** 2

<div class="post-metadata">

### Author: ![TradersBASE](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/tradersbase/32/5321_2.png) [@TradersBASE](https://forums.speedlife.net/u/TradersBASE)
#### Post date: [April 8, 2014, 10:56am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/21 "2014-04-08T10:56:20Z")

</div>

> [@LZ](#):
>
> PfSense is vulnerable we have been testing a bunch of stuff this morning… This is going to be super useful on internal security assessments for years

Should I be concerned based on our proximity? 😛

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 8, 2014, 11:22am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/22 "2014-04-08T11:22:48Z")

</div>

> [@boxxa](#):
>
> Mad skills. Such wow.
> 
> Everything that uses the secure web traffic browsing. Banks, IM, Website sessions, etc. If you have a vulnerable version of OpenSSL, your keys are compromised and have to reissue certs and a ton of other crap. Pretty much this broke the internet.

I want to figure out how people were getting a complete private key back out…if they just keep a SSL/TLS session open or just keep creating new ones.

> [@TradersBASE](#):
>
> Should I be concerned based on our proximity? 😛

its all good player

---

<div class="post-metadata">

### Author: ![Mankthetank19](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/mankthetank19/32/5295_2.png) [@Mankthetank19](https://forums.speedlife.net/u/Mankthetank19)
#### Post date: [April 8, 2014, 11:26am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/23 "2014-04-08T11:26:47Z")

</div>

It is in progress

---

<div class="post-metadata">

### Author: ![rugsr](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/rugsr/32/7474_2.png) [@rugsr](https://forums.speedlife.net/u/rugsr)
#### Post date: [April 8, 2014, 12:59pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/24 "2014-04-08T12:59:56Z")

</div>

> [@boxxa](#):
>
> Pretty much this broke the internet.

Sooooooooo now what?

This?  
[ATTACH=CONFIG]32238[/ATTACH]

---

<div class="post-metadata">

### Author: ![boxxa](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/boxxa/32/5045_2.png) [@boxxa](https://forums.speedlife.net/u/boxxa)
#### Post date: [April 8, 2014, 1:12pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/25 "2014-04-08T13:12:15Z")

</div>

> [@rugsr](#):
>
> Sooooooooo now what?
> 
> This?  
> [ATTACH=CONFIG]32238[/ATTACH]

more like this

Short 50,000ft overview:

Websites use SSL to encrypt connections. This relies on a secure key that the site uses to generate certificate that tells people, yes, this is the site you are looking for so you know going to your banks website, you are actually at your banks website and not someone trying to fake it.

Someone found a way to use this protocol and not only see what you are passing through it and decrypt usernames and passwords, but also dump that private key so essentially, could sign certificates and make their own websites that appear to be legit.

---

<div class="post-metadata">

### Author: ![rugsr](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/rugsr/32/7474_2.png) [@rugsr](https://forums.speedlife.net/u/rugsr)
#### Post date: [April 8, 2014, 1:36pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/26 "2014-04-08T13:36:46Z")

</div>

Wth. So how can one prevent this? How do I stop some middle aged man in a shirt and time sitting in a outdoor cafe from stealing my money?

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 8, 2014, 1:52pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/27 "2014-04-08T13:52:30Z")

</div>

> [@rugsr](#):
>
> Wth. So how can one prevent this? How do I stop some middle aged man in a shirt and time sitting in a outdoor cafe from stealing my money?

Completely separate issue

The issue here is the code that was written to handle SSL had bug that let attackers read a bunch of random memory off the vulnerable servers…It will be end up being patched on all major sites in the next few days.

---

<div class="post-metadata">

### Author: ![Gus](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/gus/32/5112_2.png) [@Gus](https://forums.speedlife.net/u/Gus)
#### Post date: [April 8, 2014, 2:01pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/28 "2014-04-08T14:01:25Z")

</div>

Most of the US government is still on XP. The client we consult for just upgraded to Win 7 per EOL for XP. So many Government applications incompatible on Windows 7 it’s NOT even funny. …yeah it is

---

<div class="post-metadata">

### Author: ![Mankthetank19](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/mankthetank19/32/5295_2.png) [@Mankthetank19](https://forums.speedlife.net/u/Mankthetank19)
#### Post date: [April 8, 2014, 4:29pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/29 "2014-04-08T16:29:57Z")

</div>

Update about Yahoo:

April 2nd post about yahoo efforts of encryption - [http://yahoo.tumblr.com/](http://yahoo.tumblr.com/)

Latest update provided by yahoo:

> **[Heartbleed bug takes bite out of encryption, affects Yahoo and others](http://www.siliconbeat.com/2014/04/08/heartbleed-bug-takes-bite-out-of-encryption-affects-yahoo-and-others/)**
>
> Note: This post has an updated Yahoo statement below. Amid security and privacy concerns galore — plus tech companies’ plans and promises to better protect their users — comes a …

**Update:** Yahoo has sent us a new statement. “Our team has successfully made the appropriate corrections across the main Yahoo properties (Yahoo Homepage, Yahoo Search, Yahoo Mail, Yahoo Finance, Yahoo Sports, Yahoo Food, Yahoo Tech, Flickr and Tumblr) and we are working to implement the fix across the rest of our sites right now.”

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 8, 2014, 5:05pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/30 "2014-04-08T17:05:47Z")

</div>

It’s cool Yahoo took that long I wonder how many passwords were lost

---

<div class="post-metadata">

### Author: ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)
#### Post date: [April 8, 2014, 6:41pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/31 "2014-04-08T18:41:42Z")

</div>

Yahoo accounts are compromised in droves pretty much all day every day anyway lol

---

<div class="post-metadata">

### Author: ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)
#### Post date: [April 9, 2014, 4:31am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/32 "2014-04-09T04:31:04Z")

</div>

> [@LZ](#):
>
> It’s cool Yahoo took that long I wonder how many passwords were lost

Yeah, it’s pretty ridiculous that it took them so long to address this.

I see it’s finally hitting mainstream media today…

[http://www.cnn.com/2014/04/08/tech/web/heartbleed-openssl/index.html?hpt=hp\_t2](http://www.cnn.com/2014/04/08/tech/web/heartbleed-openssl/index.html?hpt=hp_t2)

---

<div class="post-metadata">

### Author: ![TradersBASE](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/tradersbase/32/5321_2.png) [@TradersBASE](https://forums.speedlife.net/u/TradersBASE)
#### Post date: [April 9, 2014, 5:48am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/33 "2014-04-09T05:48:57Z")

</div>

Which was worse, letting this bug linger or serving up malware via ads?

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 9, 2014, 5:50am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/34 "2014-04-09T05:50:57Z")

</div>

This bug is worse

Tons of people use the same creds for paypal as their yahoo email addresses

---

<div class="post-metadata">

### Author: ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)
#### Post date: [April 9, 2014, 5:53am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/35 "2014-04-09T05:53:01Z")

</div>

> [@JayS](#):
>
> Yeah, it’s pretty ridiculous that it took them so long to address this.
> 
> I see it’s finally hitting mainstream media today…
> 
> [http://www.cnn.com/2014/04/08/tech/web/heartbleed-openssl/index.html?hpt=hp\_t2](http://www.cnn.com/2014/04/08/tech/web/heartbleed-openssl/index.html?hpt=hp_t2)

yeah no kidding. I’m not sure what distro they’re running, but surely they’re doing centralized package/patch and configuration management. That should make it pretty easy to push the patch and restart their web servers.

> [@TradersBASE](#):
>
> Which was worse, letting this bug linger or serving up malware via ads?

They’re both bad

---

<div class="post-metadata">

### Author: ![TradersBASE](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/tradersbase/32/5321_2.png) [@TradersBASE](https://forums.speedlife.net/u/TradersBASE)
#### Post date: [April 9, 2014, 6:03am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/36 "2014-04-09T06:03:15Z")

</div>

> [@LZ](#):
>
> This bug is worse Tons of people use the same creds for paypal as their yahoo email addresses

You now know too much! LOL I think I need to change all my passwords and get off PFsense. 😛

---

<div class="post-metadata">

### Author: ![evane](https://avatars.discourse-cdn.com/v4/letter/e/6bbea6/32.png) [@evane](https://forums.speedlife.net/u/evane)
#### Post date: [April 9, 2014, 6:08am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/37 "2014-04-09T06:08:04Z")

</div>

Probably should change my Yahoo Password… yet again…

Damn them for owning Flickr

---

<div class="post-metadata">

### Author: ![Mankthetank19](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/mankthetank19/32/5295_2.png) [@Mankthetank19](https://forums.speedlife.net/u/Mankthetank19)
#### Post date: [April 9, 2014, 7:39am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/38 "2014-04-09T07:39:34Z")

</div>

Yahoo, Google, Microsoft, Amazon, etc were all affected.

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 9, 2014, 7:41am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/39 "2014-04-09T07:41:10Z")

</div>

Microsofts stuff doesn’t even use OpenSSL unless its was some obscure MS site.

Microsofts Azure doesn’t use OpenSSL and the people who found the bug work for Google :lol:

Yahoo dropped the ball hard on this one

---

<div class="post-metadata">

### Author: ![Mankthetank19](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/mankthetank19/32/5295_2.png) [@Mankthetank19](https://forums.speedlife.net/u/Mankthetank19)
#### Post date: [April 9, 2014, 7:44am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/40 "2014-04-09T07:44:35Z")

</div>

> **[Passwords vulnerable after security flaw found](https://www.usatoday.com/story/tech/2014/04/08/passwords-vulnerable-after-security-flaw-found/7486623/)**
>
> Exploit found in encryption technology used to send sensitive information.

Companies that haven’t made improvements for some time are not as affected as companies who continue to update their encryption. This is why many of the larger tech companies are affected

[Previous page](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950.md?page=1)

[Next page](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950.md?page=3)
