Made with Love

To all members.

Mine is the first chapter of "Portrait of the artist as a Young Man" by James Joyce.
Signing in takes forever though.
 
Silvio Burlusconi said:
Mine is the first chapter of "Portrait of the artist as a Young Man" by James Joyce.
Signing in takes forever though.

:rofl!:
 
Silvio Burlusconi said:
Mine is the first chapter of "Portrait of the artist as a Young Man" by James Joyce.
Signing in takes forever though.

Funny, mine too, but I did mine in Latin. Funky & Music
 
'Heartbleed' bug gives hackers secret access to data.

Guys change your passwords ASAP!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

SAN FRANCISCO -- An alarming lapse in Internet security has exposed millions of passwords, credit card numbers and other sensitive bits of information to potential theft by computer hackers who may have been secretly exploiting the problem before its discovery.

The breakdown revealed this week affects the encryption technology that is supposed to protect online accounts for emails, instant messaging and a wide range of electronic commerce.
Security researchers who uncovered the threat, known as "Heartbleed," are particularly worried about the breach because it went undetected for more than two years.

All the story below

https://www.ctvnews.ca/sci-tech/heartbleed-bug-gives-hackers-secret-access-to-data-1.1767582
 
Bangon said:
'Heartbleed' bug gives hackers secret access to data.

Guys change your passwords ASAP!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

SAN FRANCISCO -- An alarming lapse in Internet security has exposed millions of passwords, credit card numbers and other sensitive bits of information to potential theft by computer hackers who may have been secretly exploiting the problem before its discovery.

The breakdown revealed this week affects the encryption technology that is supposed to protect online accounts for emails, instant messaging and a wide range of electronic commerce.
Security researchers who uncovered the threat, known as "Heartbleed," are particularly worried about the breach because it went undetected for more than two years.

All the story below

https://www.ctvnews.ca/sci-tech/heartbleed-bug-gives-hackers-secret-access-to-data-1.1767582


The Canada Revenue Agency shut down their website today due to security risks.

 
This needs to be put in perspective. The vulnerability is only on sites running two specific versions of OpenSSL, which is used to encrypt client-server communications. Sites like HUBGFE are not vulnerable. Also, there is a very easy fix for the site admins, which takes less than a minute to implement.

Heartbleed was announced on Monday and almost all sites were safe by the time the news hit the big media sites.

Yahoo.com was one of the sites that was vulnerable (Google, Youtube, Twitter, Facebook etc were not). CRA shut down their site as a precaution, I suspect, as they are not running a vulnerable version of OpenSSL as far as I can see.
 
Taking care of the issue only prevents future vulnerabilities. Who knows what has been probed or captured before that point?

And as consumers we should also be very, very concerned, particularly for sites which don't use PFS. In that case, if someone gains access to a key they can decrypt any previously captured data.

This looks to me as the worst breach I have ever seen with very far reaching consequences
 
LastPass Heartbleed checker


With news breaking on Monday, April 7th that the Heartbleed bug causes a vulnerability in the OpenSSL cryptographic library, which is used by roughly two-thirds of all websites on the Internet, we want to update our community on how this bug may have impacted LastPass and clarify the actions we're taking to protect our customers. LastPass recommends everyone with a Yahoo.com account, OkCupid.com or Github.com account changes their password.

https://lastpass.com/heartbleed/
 
900 SINs stolen from CRA website due to Heartbleed

The Canada Revenue Agency says approximately 900 social insurance numbers were stolen from its system due to the Heartbleed bug.
The "malicious breach of taxpayer data" occurred over a six-hour period, the agency said in a press release Monday.

"We are currently going through the painstaking process of analyzing other fragments of data, some that may relate to businesses, that were also removed," CRA commissioner Andrew Treusch said in the statement.


Those affected will receive a registered letter to inform them of the breach. A 1-800 number has been set up to provide them with further information, including what steps they will need to take.


The RCMP is investigating the breach, Treusch said.


Public access to the CRA website was restored Sunday after the agency shut it down Wednesday morning. It meant Canadians were unable to file their taxes online or access their accounts.


Due to the shutdown, the deadline to file taxes has been extended to May 5.

https://www.torontosun.com/2014/04/14/900-sins-stolen-from-cra-website-due-to-heartbleed
 
Brother said:
900 SINs stolen from CRA website due to Heartbleed

The Canada Revenue Agency says approximately 900 social insurance numbers were stolen from its system due to the Heartbleed bug.
The "malicious breach of taxpayer data" occurred over a six-hour period, the agency said in a press release Monday.

"We are currently going through the painstaking process of analyzing other fragments of data, some that may relate to businesses, that were also removed," CRA commissioner Andrew Treusch said in the statement.


Those affected will receive a registered letter to inform them of the breach. A 1-800 number has been set up to provide them with further information, including what steps they will need to take.


The RCMP is investigating the breach, Treusch said.


Public access to the CRA website was restored Sunday after the agency shut it down Wednesday morning. It meant Canadians were unable to file their taxes online or access their accounts.


Due to the shutdown, the deadline to file taxes has been extended to May 5.

https://www.torontosun.com/2014/04/14/900-sins-stolen-from-cra-website-due-to-heartbleed


If they say 900 then it means 2000. But what can the culprits do with it?.
 
NSX said:
If they say 900 then it means 2000. But what can the culprits do with it?.

With SSH credentials they can get root access to the servers. Then everything is vulnerable. Once they are on the server, they can vacuum everything, or be selective.

The exploit was wide open on most servers for at least a day, sometimes two, depending on how efficient the sysadms were.
 
NSX said:
If they say 900 then it means 2000. But what can the culprits do with it?.

It's called identity theft. Your social insurance number is the key that unlocks the door to all your personal info. The thief can use your ID, pretending to be you and do a lot of damage.

Apparently they knew about the hack for 3 days before they reported it to the public.
 
Back
Top Bottom