Written in 2014 during the Heartbleed vulnerability, which has long since been patched. The password advice still stands; the urgency does not.
Security alert that impacts you
Over the last couple of days we have been following reports of a major vulnerability in internet security known as the Heartbleed bug. We believe this to be a serious risk that potentially impacts anyone who uses the internet.
We see this threat as a very real reminder to every one of us to change all of our internet passwords — including internet banking passwords. We encourage you to change all of your important internet passwords today, as we cannot advise exactly which websites are affected. What we do know is that any secure website that you have used over the past two years could possibly be impacted.
You can check whether a particular website is affected at filippo.io/Heartbleed.
What is Heartbleed?
Heartbleed is a flaw in OpenSSL — the widely used encryption software that protects the padlock icon you see in your browser on HTTPS sites. The bug allowed attackers to read small chunks of a server’s memory, which could include usernames, passwords, credit card numbers, and even the encryption keys that secure communications. The vulnerability existed for approximately two years before it was discovered and disclosed in April 2014, meaning a large number of sites were potentially exposed for an extended period.
What you should do right now
- Change your passwords on all important accounts: email, banking, social media, and any other accounts containing personal or financial information.
- Change the password to your website’s content management system (WordPress, DotNetNuke, etc.) or online store (Magento, WooCommerce, OsCommerce, ZenCart).
- Check each website using the Heartbleed test tool before you change your password — if the site is still vulnerable, changing your password before they patch it won’t help.
- After a site confirms it has been patched, update your password for that site.
- Consider using a password manager going forward to maintain strong, unique passwords for every account.
Further reading
- Users urged to change passwords after major flaw — News.com.au
- heartbleed.com
- OpenSSL Security Advisory
If you have any questions, please don’t hesitate to give Blue Platypus a call.