Showing posts with label Heartbleed. Show all posts
Showing posts with label Heartbleed. Show all posts

Saturday, June 07, 2014

Heartbleed 2 only affects Android users - but it's a wake-up call



I don't know if OOTJ readers saw the news about the new problems spotted in OpenSSL code. Dubbed at first, Heartbleed 2, it has later been called the Handshake Bug, because it affects how your computer performs the "handshake" protocol when it contacts a server. See News at CNN here. The author at CNN refers to an earlier article which brought up the issue that this critical piece of software, used by businesses worldwide, is maintained by a small band of volunteers, only one of whom can devote full time attention to the task. This is a different take on the matter, which I saw turned in a different light. But according to the more recent article, businesses are suddenly seeing the importance of this software which they have used for free for years, and are donating mazoodles of cash to help fund some better maintenance of the program.

Can you say Tragedy of the Commons? Only sort of. Like most things tech, there is not a limited amount of pie. Everybody using the program is not degrading the program, or using it up like a finite resource -- the grass on the commons eaten by everybody's sheep. However, you had a problem of everybody being free riders and the volunteers who were [happily, one supposes] maintaining the program, only had so much free time to give to the effort. Interesting problem of the modern world.

So, in the emergency moment, at least, large corporations are making donations to the OpenSSL Software Foundation, in response to an open letter from Foundation president Steve Marquess. This organization underwrites the voluntary, collaborative efforts to maintain and improve OpenSSL. Marquess is looking for both donations of money and of staff time.

Thursday, April 10, 2014

Internet Security Alert: Heartbleed

OOTJ readers may already have read about Heartbleed, the newest Internet security problem. But just in case you have not heard about this, here is your heads up. The Boston Globe today offered an article by Hiawatha Bray, their wonderful tech columnist, who concludes that "The Heartbleed scare is as bad as it sounds."

Heartbleed is a security glitch at the heart of the security of the Internet, that came about through sloppy coding, in an update of the OSSL software that provides the encryption for about two thirds of Internet sites worldwide. Encryption means the software that scrambles your data as it leaves your computer so it travels safely over the Internet. Only the target network should be able to decrypt the data you sent. So, if you are buying something from an Internet vendor, you send your name, address, credit card number over the web, feeling secure with that https:// in front of the URL. That is what the additional "s" is telling you - that the information is being decrypted between your computer and theirs, for secure transactions.

But a little bit of bad code (OSSL is Open Source, collaboratively coded), in 2012 (!) introduced a serious security lapse in how OSSL has been working. The "secure" data stored at the OSSL-secured servers can be searched and retrieved by hackers. Somebody at Google and at a Finnish security company discovered the problem and announced it this past Monday. A security researcher, for instance, was able to retrieve a name and password from Yahoo mail. Hiawatha Bray did a little checking:
Yahoo says it has fixed the problem on its servers. Meanwhile, other major Internet companies are also offering reassurances. I pinged Amazon.com, Facebook, tax preparation company Intuit Inc., and the Internal Revenue Service. All replied that their computers are not vulnerable to the Heartbleed problem.
He then points out that nobody has reported that their bank accounts have been emptied over the past two years while Heartbleed was laying out there waiting to be exploited. On the other hand, Bray also notes that spy agencies like the NSA or China's Ministry of State Security could have been using Heartbleed as a backdoor for some time and nobody would know. Unlike other hacking access points, Heartbleed leaves no marks!

So, the recommendations of security experts? For at least a few days until the Heartbleed code problem is repaired and replaced at all relevant websites,

1. Do not do any shopping or enter personal information on websites.
2. Wait a few days for Heartbleed to be repaired, then change all your passwords, at least for websites that collect personal information, and
3. Remove all the cookies from your computer, at least the ones for websites that collect personal information.

Image of the bleeding heart flowers is from the Wikimedia Commons, a photo by Pharaoh Hound, who posted it under the the Creative Commons Attribution-ShareAlike 3.0 License. The photo is of the flowers of a pink Bleeding Heart (Dicentra spectabilis)- I couldn't bear to put up the more anatomical bleeding hearts I found out there! Thank you, Pharaoh Hound!