If you have yet to hear or read about the Heartbleed bug, you probably will soon. And no, it has nothing to do with your health. Well!—not medically, anyways.
![]() |
| [Photo Source: Codemonicon] |
The doom and gloom brigade, however, can justly say that this has the potential to bring internet security to its knees as internet commerce and online banking, in addition to popular social media sites, are vulnerable to attacks. Worst still, the solution is not as simple as changing your password.
So, what happened anyways?
The discovery of a widespread security bug affecting sites running SSL encryption was announced on Monday, 07 April 2014. Dubbed the Heartbleed bug, the vulnerability was discovered by software security firm Codenomicon and by Neel Metha at Google Security, and is "located in the implementation of the TLS/DTLS (transport layer security protocols) heartbeat extension [1]" of the popular open source OpenSSL cryptographic library.
According to LastPass.com, the bug "causes a vulnerability in the OpenSSL cryptographic library, which is used by roughly two-thirds of all websites on the Internet."
So, what does this mean?
We are all affected by this revelation. Some half a million popular, well trusted websites have been deemed vulnerable; and, as of 16:00 UTC 08 April 2014, includes Yahoo [2][3][4], BarclaysCardUs.com [2], and Nasa [5]. (Yes! Some of our favorite porn sites are affected, too.)
