Previous in Forum: Distribution Linear in Excel   Next in Forum: API 5B Threads
Close
Close
Close
14 comments
Rate Comments: Nested
Guru

Join Date: Oct 2008
Posts: 42355
Good Answers: 1693

HeartBleed Checker

04/10/2014 2:38 PM

Speaking of malware that can hurt you, you might want to look at this. It is not foolproof, my organization's URL came back as "unable to verify"

http://filippo.io/Heartbleed/

How to protect yourself from the Heartbleed bug

http://www.latimes.com/business/technology/la-fi-tn-heartbleed-test-check-safe-sites-20140409,0,2218732.story#ixzz2yVgjuuUy

Register to Reply
Interested in this topic? By joining CR4 you can "subscribe" to
this discussion and receive notification when new comments are added.

Good Answers:

These comments received enough positive votes to make them "good answers".
Member

Join Date: Jun 2012
Posts: 9
Good Answers: 1
#1

Re: HeartBleed Checker

04/10/2014 3:11 PM

Additional option: Qualys has added a Heartbleed check to their SSL test feature: https://www.ssllabs.com/ssltest/

Register to Reply
Guru
United States - Member - Hobbies - Fishing - New Member Hobbies - Target Shooting - New Member Hobbies - RC Aircraft - New Member Engineering Fields - Aerospace Engineering - New Member

Join Date: May 2009
Location: Saint Helens, Oregon
Posts: 2216
Good Answers: 70
#2

Re: HeartBleed Checker

04/10/2014 4:46 PM

Scary! cr4.globalspec.com comes back from SLL Labs as "No secure protocols supported" and filippo saying it "timed out"?

This is the first I've heard about the Heartbleed bug, thanks Lyn for the info.

__________________
Confucius once said, “ Ability will never catch up with the demand for it".
Register to Reply
3
Guru
Engineering Fields - Electrical Engineering - Been there, done that. Engineering Fields - Control Engineering - New Member

Join Date: Dec 2008
Location: Long Island NY
Posts: 15600
Good Answers: 981
#3
In reply to #2

Re: HeartBleed Checker

04/10/2014 5:19 PM

No surprise about CR4 not being secure. There really is no need for tight security here. Whenever one logs into a "secure" website to enter a credit card number, to remotely control a machine, retrieve e-mail or anything deemed needing more than casual security, this is when a lock appears in a web browser indicating that SSL encryption is being applied. This ubiquitous system is what has been compromised. The weak link is not on people's (user's) computers. The weak link is in the cloud or merchant's providers.

My advice for everyone is to NOT or at the very least limit your access to any secure website until at least this weekend. Give the providers time to patch this hole. I plan on no sooner than this Monday systematically signing onto every merchant and secure site I frequent and every one that my browser history tells me I securely signed into and change my password. In a month or two I plan on repeating this process. This is the only thing we as users can do at this time.

I applaud and encourage any administrator of an SSL site to contact all users once they patch their hole.

__________________
"Don't disturb my circles." translation of Archimedes last words
Register to Reply Good Answer (Score 3)
Guru

Join Date: Mar 2007
Location: Etherville
Posts: 12362
Good Answers: 115
#5
In reply to #3

Re: HeartBleed Checker

04/10/2014 5:39 PM

Forgot to mention when I just posted, but very good points.

__________________
For sale - Signature space. Apply on self addressed postcard..
Register to Reply Off Topic (Score 5)
Guru

Join Date: Mar 2007
Location: Etherville
Posts: 12362
Good Answers: 115
#4
In reply to #2

Re: HeartBleed Checker

04/10/2014 5:37 PM

Heartbleed only hit the news hear yesterday, but when I checked it up it seems to have been well know for a while.

Look on the positive side - if any of us make any posts we later regret, we can just explain to admin that we were hacked. Banks have been interestingly quiet on their individual vulnerability.

I've not yet read any of the links others have given, but I think there may be some media hysterics going on. If anyone is compromised, then it's probably happened quite some time back. Rushing to change passwords may be the worst thing to do.

Changing passwords frequently is well established and publicized advice, but I wonder how many of us do so ? Anybody working in larger organizations will, if they are well run, get routine demands that they change their access codes. Nope, I don't do so, but that is perhaps an entirely separate discussion.

Just my tuppence, but when the alarm sounds it's worth spending some time deciding which (if any) direction to run.

__________________
For sale - Signature space. Apply on self addressed postcard..
Register to Reply
Guru

Join Date: Mar 2012
Location: Out of your mind! Not in sight!
Posts: 4424
Good Answers: 108
#11
In reply to #4

Re: HeartBleed Checker

04/10/2014 11:16 PM

If you are lucky your bank is not using OpenSSL. There is more protocols out there and the commercial version should not have this vulnerabilty.

__________________
Common Sense Dictates
Register to Reply
Guru

Join Date: Oct 2008
Posts: 42355
Good Answers: 1693
#6

Re: HeartBleed Checker

04/10/2014 5:59 PM

What amazes me is that all these sites that claim to be secure are full of it.

They lie to get your money, then wait weeks (or longer) to admit that your "secure" information was stolen and probably sold by now.

That's why I so hate "the cloud".

CryptoLocker hijacked my PC at work and encrypted 100's of files. Then they wanted $3000.00 USD for the key to unlock them. Lesson learned, my antivirus was not running in the background at the time. My fault.

Well, thanks to a $50.00 USD external hard drive that was backing my stuff up, I have been able to retrieve 99% of my important (to me) files, after the malware was wiped out.

The beauty is that much of the stuff they encrypted should have been deleted anyway, so I'll never have to worry about retrieving that two year old memo I wrote and sent.

Register to Reply
Guru
Engineering Fields - Electrical Engineering - Been there, done that. Engineering Fields - Control Engineering - New Member

Join Date: Dec 2008
Location: Long Island NY
Posts: 15600
Good Answers: 981
#7
In reply to #6

Re: HeartBleed Checker

04/10/2014 6:45 PM

I completely agree about the absurdity of "the cloud". The only scenario of "the cloud" that makes any type of sense to me is the traveling salesman/executive/specialist that stumbles upon a situation that requires some document that they did not bring with them. This should be an infrequent circumstance instead of SOP. As anyone who casually studies cryptography will tell you, frequent encrypted traffic compromises the encryption technique.

__________________
"Don't disturb my circles." translation of Archimedes last words
Register to Reply
Guru

Join Date: Oct 2008
Posts: 42355
Good Answers: 1693
#8
In reply to #7

Re: HeartBleed Checker

04/10/2014 6:55 PM

OOPS. Make that $300.00 USD.

Sorry.

"Bows and flows of angel hair and ice cream castles in the air
And feather canyons everywhere, I've looked at clouds that way
But now they only block the sun they rain and snow on everyone
So many things I would have done, but clouds got in my way"

JUDY COLLINS
"Both Sides Now"

(Clannad & Paul Young)

Cloud storage is just, "Bows and flows of angel hair and ice cream castles in the air".

Register to Reply
Guru
United States - Member - Hobbies - Fishing - New Member Hobbies - Target Shooting - New Member Hobbies - RC Aircraft - New Member Engineering Fields - Aerospace Engineering - New Member

Join Date: May 2009
Location: Saint Helens, Oregon
Posts: 2216
Good Answers: 70
#12
In reply to #8

Re: HeartBleed Checker

04/11/2014 2:28 AM

Oh, I do remember that that song, maybe too well. Those were the days my friend! I and I agree with you and Red Fred about the cloud. Every time I've been around them, they always rained on my parade! Who was it that said, "If you don't want it to be public, then don't put it on the net". That's why I will not use the the Cloud, but even then, your still not secure. I won't even swipe my card at the gas pump because of skimming, I go in and pay at the counter, pain in the butt at the time, but ..... much cheaper in the long run.

Now, if only the Western States could have some real actual rain clouds pass over us, I won't bitch!!

Thanks again Lynn

__________________
Confucius once said, “ Ability will never catch up with the demand for it".
Register to Reply
Guru

Join Date: Oct 2008
Posts: 42355
Good Answers: 1693
#13
In reply to #12

Re: HeartBleed Checker

04/11/2014 4:01 AM
Register to Reply
Guru

Join Date: Oct 2008
Posts: 42355
Good Answers: 1693
#9

Re: HeartBleed Checker

04/10/2014 8:05 PM

It just gets worser and worser........

Experts Find a Door Ajar in an Internet Security Method Thought Safe

Google; Facebook.

So much for internet security.

Register to Reply
Guru
Engineering Fields - Electrical Engineering - Been there, done that. Engineering Fields - Control Engineering - New Member

Join Date: Dec 2008
Location: Long Island NY
Posts: 15600
Good Answers: 981
#10
In reply to #9

Re: HeartBleed Checker

04/10/2014 10:05 PM

No, this is not worse. This is an echo. This is another report on the Heartbleed breech. They do a better job in this article of explaining the sequence of steps required of all participants to return to a secure internet. Calm down, you'll frighten the horses.

__________________
"Don't disturb my circles." translation of Archimedes last words
Register to Reply
Guru
Engineering Fields - Electrical Engineering - Been there, done that. Engineering Fields - Control Engineering - New Member

Join Date: Dec 2008
Location: Long Island NY
Posts: 15600
Good Answers: 981
#14

Re: HeartBleed Checker

04/11/2014 4:54 PM

For anyone that wants to understand how the heartbleed bug works, this XKCD cartoon does the best explanation I've seen so far. The cartoon is slightly cryptic so one might have to mentally think through the scenario a few times to get the concept.

__________________
"Don't disturb my circles." translation of Archimedes last words
Register to Reply
Register to Reply 14 comments

Good Answers:

These comments received enough positive votes to make them "good answers".
Copy to Clipboard

Users who posted comments:

dj95401 (2); IdeaSmith (1); jweis (1); Kris (2); lyn (4); redfred (4)

Previous in Forum: Distribution Linear in Excel   Next in Forum: API 5B Threads

Advertisement