Important Security Advice [UPDATED 2]

The Crewroom for non-FS related stuff, fun and general chat.

Moderators: Guru's, The Ministry

User avatar
TSR2
The Ministry
Posts: 16762
Joined: 17 Jun 2004, 14:32
Location: North Tyneside, UK
Contact:

Important Security Advice [UPDATED 2]

Post by TSR2 »

As you may have heard in the media, a serious security flaw has been discovered in something called OpenSSL. SSL is a typically the little padlock icon you may see when browsing some websites, indicating that the information sent between your browser and the server at the other end is secure. Open SSL is an "Open Source" implementation of SSL and is widely used on all sorts of devices from smart TV's, and NAS boxes to advanced networking equipment and many servers on the internet. The security flaw means that information that is exchanged using Open SSL may not be secure and can be easily intercepted.

There have been many reports in the media today urging people to change their passwords for things like email, banking or for websites that retain you credit card information.

While changing your password is not a bad idea, it will lure people into the false sense of security, in that they will believe they are now secure. This is NOT the case. There is little point in changing your password, UNLESS THE SYSTEM YOU ARE CHANGING IT ON HAS BEEN FIXED. As the vulnerability has only recently been made public, there is no way all of the sites that are exposed to the vulnerability will have been updated to fix the issue. I would suggest that you minimise the number of websites or internet services that contain your personal information or card details, and then check these websites to see if the have the vulnerability using the tool below (or similar). If they have the vulnerability, contact the people responsible and ask them when they expect to have it fixed. After it has been fixed, then change your password. Alternatively, you could delete your information from such sites.

At the bottom of this article is a list of some services and whether or not they are vulnerable at present.

http://www.bbc.co.uk/news/technology-26971363

[EDIT] Sorry guys, just re read what I had said, and just to be clear, if the website you are using is not showing as being vulnerable, you SHOULD change your password as this has either never had the vulnerability, or HAS had it fixed. As there is no way to tell which of the former is the case, better play safe and change your password.

https://www.ssllabs.com/ssltest/

Please note: This is only an issue where the site uses SSL.
Ben.:tunes:

ImageImageImage

User avatar
gordon-in-aberdeen
Vulcan
Vulcan
Posts: 409
Joined: 13 May 2008, 12:57
Location: Stones' throw from old Montrose Air Station (well, 4 miles anyway:-)

Re: Important Security Advice

Post by gordon-in-aberdeen »

Cheers for that Ben, :thumbsup:

Just one thing, did you mean to leave a link to something to help test it on sites you mentioned?
and then check these websites to see if the have the vulnerability using the tool below (or similar)


Just wondered, no link visible here if there was supposed to be one *-)

:thumbsup: again ben, I'll go back under my rock now :hide:
TTFN, Gordon
"To err is human, but to ARR is most definitely Pirate... "

User avatar
TSR2
The Ministry
Posts: 16762
Joined: 17 Jun 2004, 14:32
Location: North Tyneside, UK
Contact:

Re: Important Security Advice

Post by TSR2 »

Hi Gordon,

completely for got to post the link. I'll amend the first post in a minute. Meanwhile, here is the bbc article...
http://m.bbc.co.uk/news/technology-26954540
Ben.:tunes:

ImageImageImage

User avatar
airboatr
Red Arrows
Red Arrows
Posts: 6839
Joined: 25 Oct 2007, 07:17

Re: Important Security Advice

Post by airboatr »

Thanks Ben,

User avatar
Airspeed
The Reds & Concorde
The Reds & Concorde
Posts: 10372
Joined: 14 Sep 2011, 03:46
Location: Central Victorian Highlands, Dja Dja Wurrung Country, Australia
Contact:

Re: Important Security Advice [UPDATED]

Post by Airspeed »

Thanks Ben,
Ran this on my bank, passed OK., but it could not rate my SP/mail.

EDIT 10:46 pm local time... this was on the 7pm news tonight, saying just what Ben did - no use changing your password. The providers have to fix it.
But Ben was first ;)
Cheers, Mike.
Perspective determines interpretation.
Image

http://airspeedsflyingvisit.threadwings ... index.html

User avatar
TSR2
The Ministry
Posts: 16762
Joined: 17 Jun 2004, 14:32
Location: North Tyneside, UK
Contact:

Re: Important Security Advice [UPDATED]

Post by TSR2 »

A quick heads up guys, it seems that GMAIL and Facebook are exposed to this vulnerability. If you use the same password for Gmail and /or Facebook as you do for other sensitive services, you should change your password for the other services now and assume that your Gmail and or Facebook login is compromised.
Ben.:tunes:

ImageImageImage

Vancouver
Concorde
Concorde
Posts: 1476
Joined: 05 Apr 2008, 00:27
Location: CYXX

Re: Important Security Advice [UPDATED]

Post by Vancouver »

I have so many different passwords and PIN numbers these days I have to maintain a little book with them all in it just to stop my brain seizing up. Should I stay awake at night just in case some intruder steals my book? Twas so much easier before computers. I was under the impression they were supposed to make life simpler, that is what Raymond Baxter told us on "Tomorrows World" at any rate.
*-) :wall: :worried:
Alex

User avatar
TSR2
The Ministry
Posts: 16762
Joined: 17 Jun 2004, 14:32
Location: North Tyneside, UK
Contact:

Re: Important Security Advice [UPDATED]

Post by TSR2 »

Definitely Alex. As a rule of thumb try not to put anything on t'internet that you wouldn't want the world to see. Your little black book is the best place to have it, and its not traceable :thumbsup:
Ben.:tunes:

ImageImageImage

J0hn
Concorde
Concorde
Posts: 1175
Joined: 20 Jul 2008, 18:22

Re: Important Security Advice [UPDATED 2]

Post by J0hn »

I keep one, too. I also never use the same password twice. Ever.

Recently I started using a system whereby I will always know or can work out what my password is for any given site, but it's always considered 'very secure' in it's content.

There's a quick list on The Beeb now, showing some major sites and what the score is:

http://www.bbc.co.uk/news/technology-26971363

Look down the page to the table.

Problem is, Google has been patched, but try finding how to change your password! It's like a maze in there, and like me, most people never wanted to have a Google profile in the first place, but had one forced upon them with their YouTube account last year. At least we in the UK don't have to use our real names, like some do.

I've got nought worth stealing anyway! :cheers:

User avatar
TobyV
Vintage Pair
Vintage Pair
Posts: 2866
Joined: 26 Jun 2004, 20:41
Location: Halfway up a hill

Re: Important Security Advice [UPDATED 2]

Post by TobyV »

Thanks for the good advice. I noticed this thread seemed to be some way down the page though. Any chance a mod could pin it at the top? Seems very relevant at the moment (and probably for the next days and weeks before all servers around the world have been patched).

Post Reply