Skip to main content
stian@hugo:~/posts/heartbleed-ssl-vulnerability$ cat heartbleed-ssl-vulnerability.md

Heartbleed SSL Vulnerability

·492 words·3 mins

The “superbug” in OpenSSL named “Heartbleed” is all over the news these days and is causing some confusion and concern for many people. This hole in the SSL encryption was discovered in the start of this week by Google and Code Nomicon, and the hole is a serious one. The problem is, what do you do with this? Here is a very simple simple guide to what I suggest you should do.

filippo_test
1. Verify that your account is now patched from the vulnerability. To do this check your provider (bank, facebook, google or other) with one of the open tools to verify. One such tool is: http://filippo.io/Heartbleed/ Just enter the URL (like accounts.google.com or any other web page) and if the tools says “All good” then you are OK to proceed and change your password. Should this not be the case then wait until they have fixed the site before changing it (you could of course disable your account in the meantime).

These services have allready been fixed and you can safely change your password:

  • Facebook
  • Tumblr
  • Google/Gmail/YouTube
  • Amazon Web Services
  • eBay
  • Dropbox
  • Netflix
  • SoundCloud
  • OKCupid
  • Wunderlist
  • Telenor

Lists are being updated on this page with information and advisory if you need to change password: http://mashable.com/

2. You could (even if the bug is not fixed actually!) enable 2-factor authentication for your services. Main services that have this already is Google, Facebook, Twitter, Microsoft and more.

Google: http://www.google.com/landing/2step/ Facebook: https://www.facebook.com/note.php?note_id=10150172618258920 Twitter: https://blog.twitter.com/2013/getting-started-with-login-verification ¨ Microsoft: http://windows.microsoft.com/en-us/windows/two-step-verification-faq

Most of these services provide an app for Android or Apple phones/devices that you could use for code generation or you would get an SMS on your phone. Using 2-factor authentication protects you more when the passwords are leaked on the Internet as the “stealer” also needs to get your phone to be able to log in. In the future all services must provide some kind of 2 factor I think!

For more information about the bug that has been discovered read this: http://heartbleed.com. If you have a server service using OpenSSL you should immediately take action to close this security hole and preferably also issue for new SSL certificates for your service when the bud is fixed.

Final information, this bug has been patched like crazy by the big authentication providers around the world over the last few days and most of the big services have been patched already and at least I have not heard of anyone exploiting this still. The big concern however is that the bug have been in the “wild” for 2 years and in this time anyone could have found out and exploited this in silence. The way the bug works actually leaves no trace if this had been done and if they never published anything then they are sitting on a huge backdoor into many systems. This is the reason you really have to change your passwords, no matter what…. and again, go enable 2-factor, that is the best protection!

Related

Buying a Tesla?

·843 words·4 mins
Tesla is doing some word-of-mouth advertising of their cars Tesla Model S and in the future Model X. This basically means that people like myself that have a current Model S have the ability to give a current buyer of a new car a rebate of 10 000 NOK off the list price by clicking my link. At the same time I would get a credit of the same on my Tesla-account (for future car purchase, services, accessories or similar). So basically I am asking you, if you are contemplating buying a new Tesla, please click my link and go bananas!

Make Pizza on the Boat

·939 words·5 mins
Last fall we bought ourselves a new boat (old, but new to us!). The boat is a small Norwegian cabincruiser that gives us the ability to stay the weekend in the boat. One our favourite activities to do in the weekends is to make pizza. On the boat it is more complicated to make pizzas but far from impossible. This article is a short description on how do it :)

Building the ultimate quiet HTPC

·715 words·4 mins
I have for years been using a mediacenter PC in my livingroom, it started back in the days of the 4Mbit wireless days (before the wireless standards were approved) and up till today on wired 1Gbit with a NAS and dedicated TV server in the basement. All through the years it has been very important to me to have a noiseless computer, fan noise and CD chippering is just annoying!