ALL YOUR PASSWORDS ARE AT RISK

Discussion in 'General Off-Topic' started by Wheelie, Apr 8, 2014.

  1. Wheelie

    Wheelie
    Expand Collapse

    Joined:
    Feb 1, 2013
    Messages:
    270
    I put this on the Rigs of Rods forums as well, and, just to cover all of my bases, I thought I'd post it here too:

    Within the last hour or so, a serious bug in the OpenSSL software, labeled "Heartbleed", became known. The gist of it is this: on any website using OpenSSL, all of your personal data that has been encrypted is completely available to external sources.

    I'm probably getting most of everything wrong, so you can read more here:

    http://heartbleed.com/

    If you want to make sure you stay safe, then change your passwords so that they are not all the same.
     
    #1 Wheelie, Apr 8, 2014
    Last edited: Apr 9, 2014
  2. Kitteh5

    Kitteh5
    Expand Collapse

    Joined:
    Oct 24, 2012
    Messages:
    275
    Thanks Wheelie, but which websites use OpenSSL?
     
  3. shockwaffleman

    shockwaffleman
    Expand Collapse

    Joined:
    Aug 15, 2013
    Messages:
    152

    (imported from here)
     
  4. kubus765

    kubus765
    Expand Collapse

    Joined:
    Jul 1, 2013
    Messages:
    97
    at first I read "all your password are belong to us"
     
  5. rsb0204

    rsb0204
    Expand Collapse

    Joined:
    Aug 23, 2013
    Messages:
    129
    And this is why you never use you real info for anything online, weather you trust the site or not.
     
  6. Fundador

    Fundador
    Expand Collapse

    Joined:
    May 21, 2013
    Messages:
    595
    Not really sure what to do about this, it seem Pointless changing my password untill it gets universally fixed.
     
    #6 Fundador, Apr 8, 2014
    Last edited: Apr 8, 2014
  7. Cwazywazy

    Cwazywazy
    Expand Collapse

    Joined:
    Dec 1, 2012
    Messages:
    1,245
    Not really sure what anyone would want to do with my password for this site..
     
  8. logoster

    logoster
    Expand Collapse

    Joined:
    Sep 5, 2012
    Messages:
    2,083

    download the game, and mods? (provided your order is linked with your account)
     
  9. Potato

    Potato
    Expand Collapse

    Joined:
    Feb 19, 2013
    Messages:
    1,160
    I use the same password for everything (i know not smart). I need to change them all up.
     
  10. deject3d

    deject3d
    Expand Collapse

    Joined:
    Sep 3, 2013
    Messages:
    252


    - from stackoverflow.

    it's not a direct risk to invidivual users, but a motivated attacker could eventually find their way into a website that uses SSL and *then* steal user data.

    beamng.com doesn't have any ssl (good one, tdev) so it shouldn't be attackable.
     
  11. logoster

    logoster
    Expand Collapse

    Joined:
    Sep 5, 2012
    Messages:
    2,083
    how is not having a secure connection a good thing? (at the not having ssl being a good one on tdev, inb4 anyone says something about this bug, the openssl team has already fixed it, and is rolling out the update)
     
  12. orangelazer

    orangelazer
    Expand Collapse

    Joined:
    Aug 31, 2013
    Messages:
    78
    two memes to describe what i fought when i saw the title:eek:... mother-of-god-meme_large.jpg 807312.jpg
     
  13. Wheelie

    Wheelie
    Expand Collapse

    Joined:
    Feb 1, 2013
    Messages:
    270
    Alright, yes, the title is a but overdramatic, but it's true: over two thirds of all websites on the internet that need the capabilities use it as a platform. Until all of those are universally updated/patched, all of your personal information on these websites are extremely vulnerable to attack.
     
  14. deject3d

    deject3d
    Expand Collapse

    Joined:
    Sep 3, 2013
    Messages:
    252
    it's just ironic. tdev used to work in security but this website doesn't have any sort of SSL. just in this one case was SSL a bad thing to have.

    the OpenSSL team can roll out the update as soon as they want, but it's up to individual system administrators to actually adopt the update and make sure their systems are up to date. and LOTS of people will be running outdated versions for weeks. people still run outdated and insecure versions of windows XP all over the world, despite microsoft rolling out security fixes.

    the bug is already out there and will affect systems for weeks, months, years to come.

    @ orangelazer: i wish everyone made it so easy for me to figure out if they should be on my ignore list
     
  15. logoster

    logoster
    Expand Collapse

    Joined:
    Sep 5, 2012
    Messages:
    2,083

    you mean openssl would have been a bad thing to have, there are obviously other ssl systems

    also, how would you know where tdev used to work?
     
  16. deject3d

    deject3d
    Expand Collapse

    Joined:
    Sep 3, 2013
    Messages:
    252
    sure, but openssl is free and used a lot. a lot. most websites use it.
    linkedin
     
  17. Car crusher

    Car crusher
    Expand Collapse

    Joined:
    Nov 17, 2013
    Messages:
    199
    Unfortunately heartbleed is a real threat, hence I needed to sign out from soundcloud as a result of it:

    - - - Updated - - -

    Well at least soundcloud took measures.
     

    Attached Files:

    • image.jpg
    • image.jpg
    #17 Car crusher, Apr 10, 2014
    Last edited: Apr 10, 2014
  18. HadACoolName

    HadACoolName
    Expand Collapse

    Joined:
    Aug 3, 2013
    Messages:
    1,932
    This, my facebook & my email have the same password. Heh heh

    Im to lazy to change anything.
     
  19. Rokzy rules

    Rokzy rules
    Expand Collapse

    Joined:
    Dec 31, 2013
    Messages:
    379
    Same everything but my Gmail uses the same password as this :rolleyes:
     
  20. HadACoolName

    HadACoolName
    Expand Collapse

    Joined:
    Aug 3, 2013
    Messages:
    1,932
    LAZYNESS 4 LIFE :cool:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice