Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

Heartbleed

Heartbleed causes massive online scare - but don't change your passwords just yet

Google sites such as GMail and YouTube are clear, the company says.

A NEW SECURITY bug has sparked online panic, with experts saying that users of a large number of sites should change their passwords – but not right away.

Heartbleed is a security flaw in OpenSSL technology, an implementation of a protocol that is used to protect data across the web.

Around two-thirds of the web uses OpenSSL and the Heartbleed bug has been present for around two years.

The bug can, in theory, allow anyone access the information of people who used affected sites and there is not much that can be done by users just yet. It is up to individual websites to upgrade to a version of OpenSSL that is unaffected.

It’s unclear whether any information has been stolen as a result of Heartbleed, but security experts are particularly worried about the bug because it went undetected for more than two years.

Google sites such as GMail and YouTube are clear, the company says, but a large amount of other websites are still affected.

Yahoo, which has more than 800 million users around the world, said Tuesday that most of its popular services — including sports, finance and Tumblr — had been fixed, but work was still being done on other products that it didn’t identify.

PastedImage-18556

A GitHub list compiled by a user outlines around 10,000 sites and whether they are or are not affected.

It is recommended that users of sites that have passwords search the list for their bank, email and important account providers. Ultimately, you’ll need to change your passwords, but that won’t do any good until the sites you use adopt the fix. It’s also up to the internet services affected by the bug to let users know of the potential risks and encourage them to change their passwords.

Read: ‘Heartbleed’ security bug leaves encrypted web servers at risk

Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article. Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

Close
57 Comments
    Install the app to use these features.
    Mute Mike O Neill
    Favourite Mike O Neill
    Report
    Apr 10th 2014, 8:31 AM

    Redtube! Oh no!

    121
    Install the app to use these features.
    Mute Pierce2020
    Favourite Pierce2020
    Report
    Apr 10th 2014, 8:22 AM

    Oh no, now they can look at pictures of my wife’s birthday, for shame internet, for shame.

    67
    Install the app to use these features.
    Mute Mike Myers
    Favourite Mike Myers
    Report
    Apr 10th 2014, 8:27 AM

    You do know most people use their computers for more than pics of their wives posing with bingo wings

    79
    Install the app to use these features.
    Mute Pierce2020
    Favourite Pierce2020
    Report
    Apr 10th 2014, 8:34 AM

    They don’t it’s the number one usage.

    81
    See 4 more replies ▾
    Install the app to use these features.
    Mute Brian Dataface Cavanagh
    Favourite Brian Dataface Cavanagh
    Report
    Apr 10th 2014, 8:41 AM

    I think thats other peoples wives

    40
    Install the app to use these features.
    Mute Mike Myers
    Favourite Mike Myers
    Report
    Apr 10th 2014, 8:43 AM

    Id say your wifes pics are ok. There aint no one that deviant

    21
    Install the app to use these features.
    Mute Brian Dataface Cavanagh
    Favourite Brian Dataface Cavanagh
    Report
    Apr 10th 2014, 8:47 AM

    Bit innocent?

    10
    Install the app to use these features.
    Mute Niall Flynn
    Favourite Niall Flynn
    Report
    Apr 10th 2014, 8:02 PM

    XD So True up with bingo wings down with the rest XD

    1
    Install the app to use these features.
    Mute Declan Byrne
    Favourite Declan Byrne
    Report
    Apr 10th 2014, 8:19 AM

    Got to love how the IT security industry causes fear to spend money. Over hyped this alert.

    37
    Install the app to use these features.
    Mute Declan Byrne
    Favourite Declan Byrne
    Report
    Apr 10th 2014, 8:35 AM

    Anyone like to explain the red thumbs? Sorry if I upset IT security folk with the truth .

    25
    Install the app to use these features.
    Mute Fionnan Burke
    Favourite Fionnan Burke
    Report
    Apr 10th 2014, 8:40 AM

    Conspiracy theorists are hilarious. Given that the fix for this bug can be applied without immediate cost (excluding the cost of man hours), I don’t see how it could be claimed that the IT Security industry are trying to drum up money. But hey, maybe they should keep their mouth shut and leave the vulnerabilities undeclared, that’d be a lot better

    53
    See 21 more replies ▾
    Install the app to use these features.
    Mute Brian Dataface Cavanagh
    Favourite Brian Dataface Cavanagh
    Report
    Apr 10th 2014, 8:44 AM

    I didnt red thumb it but if a site doesn’t update their protocols then they are effected by loss in traffic and revenue. It doesnt cost us anything.

    14
    Install the app to use these features.
    Mute Declan Byrne
    Favourite Declan Byrne
    Report
    Apr 10th 2014, 8:46 AM

    Ok the bug can be fixed with no cost agreed however most companies will do an immediate security review of their perimeter and intrusion detection systems. Along comes IT security vendor and goes you need this and this and this .

    10
    Install the app to use these features.
    Mute Declan Byrne
    Favourite Declan Byrne
    Report
    Apr 10th 2014, 8:48 AM

    I disagree most sites will lose no traffic as most users will not have a clue of the site is vulnerable or not.

    6
    Install the app to use these features.
    Mute Fionnan Burke
    Favourite Fionnan Burke
    Report
    Apr 10th 2014, 8:56 AM

    Of course most decent companies will do a security review. That would be the most sensible thing to do. I don’t see how this relates to the IT Security sector drumming up money though. And most large companies would (or should) have in-house security staff on their payroll anyway

    16
    Install the app to use these features.
    Mute Declan Byrne
    Favourite Declan Byrne
    Report
    Apr 10th 2014, 9:02 AM

    The review is nearly always done in conjunction with a security company.

    2
    Install the app to use these features.
    Mute Emilio
    Favourite Emilio
    Report
    Apr 10th 2014, 9:10 AM

    The update is virtually free and there is no way of finding out what data was leaked because of the nature of the bug.

    Sure the NSA was using it very happily I bet.

    9
    Install the app to use these features.
    Mute David Molloy
    Favourite David Molloy
    Report
    Apr 10th 2014, 9:19 AM

    There is an associated cost in fact and a benefit to security companies. Any site that was affected could have had encryption keys for SSL leaked (the bit that gives secure traffic over https) which means that, even after fixing, future traffic is still vulnerable. Hence companies will need to purchase and install new security certificates regardless of whether they know if they have been compromised as this vulnerability leaves no logs or trace.

    Apologies for the nerd overload this early in the morning.

    4
    Install the app to use these features.
    Mute Barry O'Brien
    Favourite Barry O'Brien
    Report
    Apr 10th 2014, 9:26 AM

    Declan, you are seriously underestimating the consequences of this bug. Security companies are as affected by this as are other companies, and security companies don’t stand to make profit from this. In fact, it will cost security companies money to fix vulnerabilities that may exist in the their own security solutions.

    Brian… “It doesnt cost us anything.” It does if it’s your data being stolen from the provider.

    David, any reputable CA will revoke certs and sign new ones for free. Otherwise the trust model would be broken. The only vendor I know of that is refusing to do this is StartSSL, who wouldn’t be the most reputable anyway.

    8
    Install the app to use these features.
    Mute Fionnan Burke
    Favourite Fionnan Burke
    Report
    Apr 10th 2014, 9:54 AM

    Yes, in some case the security may involve assistance from security consultants but as has been said below, there is virtually no cause to be charged for new certificates, since it is a flaw in the certificate infrastructure. My (prolonged) point here is that this isn’t a conspiracy by the security sector. They took the time, and probably money to identify this bug. They should be praised for finding it, not accused of looking for extra money. The researchers involved are ridiculously intelligent people, I could only hope to have a fraction of their technical ability someday.

    6
    Install the app to use these features.
    Mute Forest Master
    Favourite Forest Master
    Report
    Apr 10th 2014, 12:42 PM

    @ Declan – you should quit while you only look like a partial idiot, and not a full blown moron.

    5
    Install the app to use these features.
    Mute Declan Byrne
    Favourite Declan Byrne
    Report
    Apr 10th 2014, 1:23 PM

    Barry I understand the potential consequences but the overall risk is not high. Even the sans dont have it as red in their threat level.

    1
    Install the app to use these features.
    Mute Declan Byrne
    Favourite Declan Byrne
    Report
    Apr 10th 2014, 1:26 PM

    When you have worked as long as me in some of the worlds biggest companies in IT security then you can call me an idiot.

    1
    Install the app to use these features.
    Mute Declan Byrne
    Favourite Declan Byrne
    Report
    Apr 10th 2014, 1:30 PM

    Some day you may work for me :-) in security.

    1
    Install the app to use these features.
    Mute Forest Master
    Favourite Forest Master
    Report
    Apr 10th 2014, 1:34 PM

    Wow – you work in IT. How exciting. zzzzzzzzz

    2
    Install the app to use these features.
    Mute Barry O'Brien
    Favourite Barry O'Brien
    Report
    Apr 10th 2014, 1:45 PM

    Overall risk is not high? Are you on drugs? Any application using the vulnerable version of OpenSSL (which is a lot of applications) can have their memory scraped. I seriously doubt you work in IT Security if you don’t understand the significant risk in that.

    And of course SANS don’t list it as red. Have you ever actually looked at what the ISC classifications actually mean? https://isc.sans.edu/infocon.html

    1
    Install the app to use these features.
    Mute Forest Master
    Favourite Forest Master
    Report
    Apr 10th 2014, 1:46 PM

    Careful, Barry – you may end up working for ‘Declan the IT security bigshot’ some day!

    3
    Install the app to use these features.
    Mute Barry O'Brien
    Favourite Barry O'Brien
    Report
    Apr 10th 2014, 1:49 PM

    “worked as long as me in some of the worlds biggest companies in IT security”
    “Some day you may work for me :-) in security.”

    Declan, what job did you actually have in the “security” companies? Because I don’t believe you for a second. The level of incompetence you have shown in this thread is astounding for someone who claims to work in IT security.

    1
    Install the app to use these features.
    Mute Niall Flynn
    Favourite Niall Flynn
    Report
    Apr 10th 2014, 8:03 PM

    Where in the Square? ;)

    1
    Install the app to use these features.
    Mute Michael Connolly
    Favourite Michael Connolly
    Report
    Apr 10th 2014, 11:13 PM

    I’d tend to agree with you Declan, most users would not be aware so why should they be cautious. How many people have stopped using ATM machines because their card can be cloned and pin discovered and this is a very well publicised and much understood issue for years.

    1
    Install the app to use these features.
    Mute Bob Goodbear
    Favourite Bob Goodbear
    Report
    Apr 11th 2014, 1:40 AM

    I was thinking the very same Declan

    1
    Install the app to use these features.
    Mute Bob Goodbear
    Favourite Bob Goodbear
    Report
    Apr 11th 2014, 1:43 AM

    Re: sites loosing traffic. In the most part they won’t.

    1
    Install the app to use these features.
    Mute Mark Lillis
    Favourite Mark Lillis
    Report
    Apr 10th 2014, 8:30 AM

    Great feature from the Journal where by if you type your password in the comment box is shows up encrypted.

    *************

    Works very well.

    32
    Install the app to use these features.
    Mute James Murphy
    Favourite James Murphy
    Report
    Apr 10th 2014, 8:54 AM

    **********

    18
    Install the app to use these features.
    Mute Leopold Dedalus
    Favourite Leopold Dedalus
    Report
    Apr 10th 2014, 8:59 AM

    Congratulations you are the 999,999th person to comment on the Journal! Give me all your bank and credit card details to claim your prize!

    50
    See 3 more replies ▾
    Install the app to use these features.
    Mute Emilio
    Favourite Emilio
    Report
    Apr 10th 2014, 9:07 AM

    Oh really?

    someonethinksweareallfools999!!

    16
    Install the app to use these features.
    Mute Mark Lillis
    Favourite Mark Lillis
    Report
    Apr 10th 2014, 9:23 AM

    @Emilio

    That password is obviously fake.

    The are no uppercase characters and 2 exclamation marks together!!
    Do you think we are all fools?

    16
    Install the app to use these features.
    Mute Emilio
    Favourite Emilio
    Report
    Apr 10th 2014, 11:48 AM

    But I got me numbers in it!

    3
    Install the app to use these features.
    Mute Mike Myers
    Favourite Mike Myers
    Report
    Apr 10th 2014, 8:33 AM

    Love how the journal uses a pic naming a porno site and a torrent site. Who employs these people?

    20
    Install the app to use these features.
    Mute Niall Flynn
    Favourite Niall Flynn
    Report
    Apr 10th 2014, 8:05 PM

    In fairness these sites are used by millions, but yeah creating accounts on them, who knows why?

    1
    Install the app to use these features.
    Mute Paul Roche
    Favourite Paul Roche
    Report
    Apr 10th 2014, 9:52 AM

    Considering the cost of SSL certs, and that Heartbleed vulnerability has been present for 2 years, what’s the position where cert providers have been selling something useless?

    18
    Install the app to use these features.
    Mute Barry O'Brien
    Favourite Barry O'Brien
    Report
    Apr 10th 2014, 10:03 AM

    The CA’s are not responsible for the choice of library that people use in their SSL/TLS deployment. The effectiveness of the CA system is another discussion unrelated to this issue. After all, this bug affects CA-signed and self-signed certs equally if you are using OpenSSL.

    14
    Install the app to use these features.
    Mute Barry O'Brien
    Favourite Barry O'Brien
    Report
    Apr 10th 2014, 10:08 AM

    And it’s not completely useless if your server will only use ciphers supporting Perfect Forward Secrecy as even if the private key is compromised, captured sessions cannot be decrypted.

    7
    See 3 more replies ▾
    Install the app to use these features.
    Mute Paul Roche
    Favourite Paul Roche
    Report
    Apr 10th 2014, 10:20 AM

    Thanks Barry,
    Good tip for PFS…

    5
    Install the app to use these features.
    Mute 1 Human Being
    Favourite 1 Human Being
    Report
    Apr 10th 2014, 1:27 PM

    There will be a problem with routers as well as most routers have OpenSSL. So get on to your ISP to update software or if there is a software patch needed for them.

    2
    Install the app to use these features.
    Mute Paul Roche
    Favourite Paul Roche
    Report
    Apr 10th 2014, 1:35 PM

    I first learned about Heartbleed from reading thejournal.ie – now I find out that routers are vulnerable.
    Thanks 1 Human Being…

    1
    Install the app to use these features.
    Mute Frank Brady
    Favourite Frank Brady
    Report
    Apr 10th 2014, 8:27 AM

    This all seems a lot like The Millennium bug affair.I think vested interests are at work

    11
    Install the app to use these features.
    Mute Emilio
    Favourite Emilio
    Report
    Apr 10th 2014, 9:10 AM

    No it does not. You are clueless.

    21
    Install the app to use these features.
    Mute Barry O'Brien
    Favourite Barry O'Brien
    Report
    Apr 10th 2014, 9:29 AM

    The reason the Millennium Bug didn’t cause the chaos predicted was because of the insane amount of time, money, and resources, spent fixing it in advance. If the fuss wasn’t made it wouldn’t have been fixed and then chaos would have ensued.

    And there is absolutely no similarity between this and the Millennium Bug. At all.

    16
    See 5 more replies ▾
    Install the app to use these features.
    Mute Mark O'Hagan
    Favourite Mark O'Hagan
    Report
    Apr 10th 2014, 10:34 AM

    The Millennium Bug was a myth that was converted into a money-making scam by certain people in the IT industry.

    5
    Install the app to use these features.
    Mute Mary Kavanagh
    Favourite Mary Kavanagh
    Report
    Apr 10th 2014, 10:41 AM

    Absolutely, Barry. The media whipped up a huge fear campaign and when the problem didn’t arise the people who fixed it got all the opprobrium. Should have been the messenger that got shot in that instance!

    4
    Install the app to use these features.
    Mute Emilio
    Favourite Emilio
    Report
    Apr 10th 2014, 11:47 AM

    The millenium bug was real. Systems that had the bug would have presented a whole rosary of issues from minor malfunctions to total breakdowns. They had to be replaced or patched and they were.

    7
    Install the app to use these features.
    Mute Anton
    Favourite Anton
    Report
    Apr 10th 2014, 12:47 PM

    You don’t have a clue about IT, do you? Thousands of developers in thousands of companies spent huge amounts of time and effort making sure the Millennium Bug was patched, before it became an issue.

    The only reason there were no major systems crashes was because they were so good at their jobs.

    5
    Install the app to use these features.
    Mute Mary Kavanagh
    Favourite Mary Kavanagh
    Report
    Apr 10th 2014, 1:03 PM

    By messenger I mean the media.

    1
    Install the app to use these features.
    Mute Sharon Reid
    Favourite Sharon Reid
    Report
    Apr 10th 2014, 11:44 AM

    A supplier got hacked this morning, whixh then sent a “invoice” to me, my IT are working to save my pc right now, no joke. :(

    1
    Install the app to use these features.
    Mute Partysauras Rex
    Favourite Partysauras Rex
    Report
    Apr 10th 2014, 11:53 AM

    This makes no sense

    12
    Install the app to use these features.
    Mute Michael Connolly
    Favourite Michael Connolly
    Report
    Apr 11th 2014, 12:54 AM

    Site: http://www.thejournal.ie
    Server software: nginx/1.0.5
    Was vulnerable: Likely (known use OpenSSL)
    SSL Certificate: Possibly Unsafe (created 1 year ago at Mar 2 14:35:29 2013 GMT)
    Assessment: Wait for the site to update before changing your password

    1
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.
JournalTv
News in 60 seconds