Category Archives: Internet

Heartbleed followup

Fallout from the Heartbleed vulnerability continues.

The list of major web sites affected by this issue (and in most cases advising their users to change their passwords) is expanding rapidly. It includes Instagram, Tumblr, DropBox, and many others.

The list of affected software is also growing.

Ars Technica’s ongoing coverage includes the disturbing news that the Heartbleed vulnerability may have been exploited months before patch and Researchers find thousands of potential targets for Heartbleed OpenSSL bug.

Security researchers at the University of Michigan scanned the Internet looking for vulnerable web sites, and found plenty, which they list in their Heartbleed Bug Health Report.

Numerous tools for detecting Heartbleed vulnerability have appeared on the web, including this one at filippo.io. Use these tools with caution, since some will almost certainly turn out to be scams of some kind.

The XKCD web comic has joined in the fun:

XKCD's take on the Heartbleed problem.
XKCD’s take on the Heartbleed problem.

Extremely critical security bug affects most of the Internet

A bug in the OpenSSL cryptography software running on most of the world’s servers has opened a window into random server data that was never meant to be exposed.

This newly-discovered vulnerability – now known as ‘Heartbleed’ – has apparently existed for at least two years. It’s unclear whether the bug was known to (and used by) nefarious persons to gather supposedly secure information during that time.

Patches for affected operating systems and other software that uses OpenSSL were made available almost immediately after the bug was discovered by researchers. Anyone running a Linux server is strongly advised to update the OpenSSL library ASAP.

Services that use OpenSSL to provide security are separately assessing the risk to their customers and issuing their own advisories and recommendations. For instance, Yahoo Mail is known to be vulnerable. Mojang, makers of the popular game Minecraft, advise all players to change their passwords. Ars Technica is also advising all its users to change their passwords.

This bug is so important that it has its own web page, which provides an overview of the issue and makes general recommendations.

Update 2014Apr10: The LastPass web site has some helpful information about major sites that have been affected by Heartbleed and recommends changing your passwords for those sites. They also provide a site check that allows you to determine whether a particular site was affected by Heartbleed.

Microsoft steps in a huge steaming pile of privacy issues

In yet another of the endless examples of why companies shouldn’t let lawyers make decisions, Microsoft has undone whatever goodwill they might have had from customers who value the privacy of their email.

A Microsoft employee apparently leaked Windows 8 information to a reporter. In typical big-corporation fashion, this leak caused the software giant to go into full-on freakout mode. Ignoring common sense entirely, they dug into the reporter’s Hotmail account, looking for clues to the identity of the leaker. Apparently the lawyers were consulted, and the lawyers said, “Go right ahead and look! The Terms of Service for Hotmail mean the law is on our side.” And they’re right. But that doesn’t mean it was a good idea. Now that this incident has come to light, the public backlash is just beginning for Microsoft.

Of course, this problem is not limited to Microsoft. Almost all email services operate this way. Whoever provides the service can access any part of it at any time, even if it’s encrypted as part of the service. The only way to get around this exposure while using a typical email service is to add your own encryption – on both ends of every email exchange – commonly referred to as end-to-end encryption. Lavabit was one of the few email services to offer this kind of security, and they closed down recently rather than comply with access requests from the NSA.

Update 2014Mar29: Microsoft, in damage control mode, has made changes to its privacy policies. A statement by Microsoft General Counsel Brad Smith on the ‘Microsoft on the Issues’ blog makes it clear that they will no longer look at customer data in situations like this. Smith also states that Microsoft will work with the EFF and other digital rights organizations to help avoid problems like this in the future.

Yahoo email accounts compromised

Yahoo announced yesterday that some Yahoo Mail account addresses and passwords were being used in a coordinated attempt to gain access to those accounts. The source of the account information remains unclear, but Yahoo claims that it was not obtained from Yahoo’s services directly.

Yahoo is resetting the passwords of affected accounts and informing the associated account holders.

Since it’s difficult to know, at this point, the full extent of this problem, anyone with a Yahoo Mail account is advised to immediately change its password.

How well do popular sites protect your passwords?

According to a recent study by Dashlane, makers of a web-oriented password manager, Apple.com does the best job of protecting your passwords online.

The study ranked one hundred of the most popular web sites on their ability to encourage or require the use of strong passwords, to assist users in selecting strong passwords, and on their policies in relation to storing and displaying or emailing passwords. Microsoft and NewEgg scored highly, and Major League Baseball scored worst.

If you needed another reason not to visit yahoo.com…

Advertisements containing malware started appearing on yahoo.com on December 30, 2013 – or possibly even earlier. Anyone visiting the site with a browser running an unpatched version of Java risked infecting their computer. If that includes you, a full malware scan of the computer you used should be your next task. One of the following (or both) should do the trick:

ISP horror stories

There’s an interesting hilarious horrifying post over at Ars Technica with some examples of the kind of service we’ve all come to expect in the competition-free world of Internet Service Providers.

Those stories make our ISP (Shaw) look pretty good by comparison with Comcast, Verizon, and Time Warner. Still, our WAN connection has been up and down during the last few days, and I’m still waiting for a service call. It’s up now, but it’s been down for a total of 34 hours in the last week.

Ouch! newsletter: How to shop online securely

The latest installment of the Ouch! newsletter (PDF) from SANS provides tips for safely and securely shopping on the web. Learn how to identify shady web stores and avoid them, how to keep your credit card information secure, and what to do if you suspect fraud.

The Ouch! newsletter is aimed at regular users and the security challenges they face daily. Highly recommended, but if you’re a computing professional, you may not find much there you didn’t already know.