Author Topic: Looks like I'm a victim of the Heartbleed SSL bug!  (Read 579 times)

0 Members and 1 Guest are viewing this topic.

Offline rumborak

  • DT.net Veteran
  • ****
  • Posts: 26664
Looks like I'm a victim of the Heartbleed SSL bug!
« on: April 11, 2014, 09:08:03 AM »
I had been on the phone 2 days ago with Barclaycard because their site was vulnerable to the bug, but they had not done anything, not even put a note on the site to notify users to change their password (now they have).

Well, this morning I got a call from them, they detected 2 fraudulent charges on my credit card. The big one (a flight with a Brazilian airline) didn't go through at all, so luckily nothing really happened.

Keep an eye on your money for the next few weeks, folks!
"I liked when Myung looked like a women's figure skating champion."

Offline El Barto

  • Rascal Atheistic Pig
  • DTF.org Alumni
  • ****
  • Posts: 30740
  • Bad Craziness
Re: Looks like I'm a victim of the Heartbleed SSL bug!
« Reply #1 on: April 11, 2014, 09:18:50 AM »
I don't understand why Barclays would use OpenSSL. Kirk can correct me on this if I'm wrong, but I thought OpenSSL was the free open-source thing that people use who don't have their own proprietary encryption schemes or aren't concerned enough about security to bother buying something more robust. Nothing against open source encryption products, TrueCrypt is still an excellent free, open-source product. Just seems like all financial institutions would be using something a little more specialized.

edit: Oh, and people get fraudulent charges on their cards/checking all the time. Certainly happened plenty before this latest screwup. I wouldn't necessarily say that it's because of Heartbleed that you got hacked. In fact Heartbleed is probably the less likely scenario.
Argument, the presentation of reasonable views, never makes headway against conviction, and conviction takes no part in argument because it knows.
E.F. Benson

Offline rumborak

  • DT.net Veteran
  • ****
  • Posts: 26664
Re: Looks like I'm a victim of the Heartbleed SSL bug!
« Reply #2 on: April 11, 2014, 09:21:59 AM »
OpenSSL is used by Apache web servers for example, and it's used by 60% of all web servers in the world. TrueCrpyt is something very different.
"I liked when Myung looked like a women's figure skating champion."

Offline El Barto

  • Rascal Atheistic Pig
  • DTF.org Alumni
  • ****
  • Posts: 30740
  • Bad Craziness
Re: Looks like I'm a victim of the Heartbleed SSL bug!
« Reply #3 on: April 11, 2014, 09:24:36 AM »
I'm aware that TC is a completely different thing. I was just citing it as an example of excellent open-source encryption, on the assumption that OpenSSL was open-source, as well.
Argument, the presentation of reasonable views, never makes headway against conviction, and conviction takes no part in argument because it knows.
E.F. Benson

Offline rumborak

  • DT.net Veteran
  • ****
  • Posts: 26664
Re: Looks like I'm a victim of the Heartbleed SSL bug!
« Reply #4 on: April 11, 2014, 09:26:13 AM »
I think OpenSSL is actually even higher-quality than TrueCrypt. But, bugs is bugs, and they don't stop at commercial software.
"I liked when Myung looked like a women's figure skating champion."

Offline El Barto

  • Rascal Atheistic Pig
  • DTF.org Alumni
  • ****
  • Posts: 30740
  • Bad Craziness
Re: Looks like I'm a victim of the Heartbleed SSL bug!
« Reply #5 on: April 11, 2014, 10:28:35 AM »
I think OpenSSL is actually even higher-quality than TrueCrypt. But, bugs is bugs, and they don't stop at commercial software.
Fair enough. Bugs is bugs, indeed, and they'll always pop up.

One thing I might surmise though is that larger companies that develop or have developed proprietary software might have some advantage since an exploit isn't going to be as common and useful. Hacking OpenSSL is going to get you a ton of mileage. While Citibanks's encryption might not even be as good as OpenSSL's, there are likely a helluva lot less people, less motivated to spend time scouring it.
Argument, the presentation of reasonable views, never makes headway against conviction, and conviction takes no part in argument because it knows.
E.F. Benson

Offline rumborak

  • DT.net Veteran
  • ****
  • Posts: 26664
Re: Looks like I'm a victim of the Heartbleed SSL bug!
« Reply #6 on: April 11, 2014, 10:37:08 AM »
I think you're confusing internal encryption methods with the SSL handshake that was at fault here. I mean, I don't think it gets much more "big gun" then Google, and their Gmail servers were affected by it.
"I liked when Myung looked like a women's figure skating champion."

Offline El Barto

  • Rascal Atheistic Pig
  • DTF.org Alumni
  • ****
  • Posts: 30740
  • Bad Craziness
Re: Looks like I'm a victim of the Heartbleed SSL bug!
« Reply #7 on: April 11, 2014, 11:04:43 AM »
I'm not confusing the two, but your point about Google is well taken. It would certainly seem that a lot more large companies were using this than I had surmised.
Argument, the presentation of reasonable views, never makes headway against conviction, and conviction takes no part in argument because it knows.
E.F. Benson