Greetings and Thanks for Visiting.

Showing posts with label Geeksplaining. Show all posts
Showing posts with label Geeksplaining. Show all posts

Tuesday, April 8, 2014

Heartbleed Bug and The Day the Internet Shat Its Pants

No comments:

If you have yet to hear or read about the Heartbleed bug, you probably will soon. And no, it has nothing to do with your health. Well!—not medically, anyways.

[Photo Source: Codemonicon]
As the news of this recent web security bug makes the rounds on television, news sites, and social media, it will be tempting to shutout all the doomsayers and the techno-babble. Unfortunately, we don't have that luxury. It does not help that all the tech talk can be confusing, especially for the less than tech savvy Joe Schmos such as myself.

The doom and gloom brigade, however, can justly say that this has the potential to bring internet security to its knees as internet commerce and online banking, in addition to popular social media sites, are vulnerable to attacks. Worst still, the solution is not as simple as changing your password.


So, what happened anyways?

The discovery of a widespread security bug affecting sites running SSL encryption was announced on Monday, 07 April 2014.  Dubbed the Heartbleed bug, the vulnerability was discovered by software security firm Codenomicon and by Neel Metha at Google Security, and is "located in the implementation of the TLS/DTLS (transport layer security protocols) heartbeat extension [1]" of the popular open source OpenSSL cryptographic library.

According to LastPass.com, the bug "causes a vulnerability in the OpenSSL cryptographic library, which is used by roughly two-thirds of all websites on the Internet." 


So, what does this mean?

We are all affected by this revelation. Some half a million popular, well trusted websites have been deemed vulnerable; and, as of 16:00 UTC 08 April 2014, includes Yahoo [2][3][4], BarclaysCardUs.com [2], and Nasa [5]. (Yes! Some of our favorite porn sites are affected, too.)