Page 1 of 1

OpenSSL 1.01+ compromised - FYI

Posted: Tue Apr 08, 2014 12:13 pm
by polynurb
FYI

http://heartbleed.com/

https://twitter.com/ivanristic/status/4 ... 5625922560

(german) http://derstandard.at/1395364560582/SSL ... et-das-Web

you can test urls here:

http://filippo.io/Heartbleed/

that is quite a story.. it also means that A LOT of encrypted data from the past, if recorded, can now be potentially decrypted.

the https server for my internet-banking is vurnerable too..

Re: OpenSSL 1.01+ compromised - FYI

Posted: Tue Apr 08, 2014 5:05 pm
by Bubbaloo
I'm sure the NSA is exploiting this already.

Re: OpenSSL 1.01+ compromised - FYI

Posted: Thu Apr 10, 2014 4:44 pm
by glebe digital
I doubt 'heartbleed' is actually a bug as such........OpenSSL was the brainchild of RSA Security Inc, a company well-known for incorporating backdoors (developed by the NSA) into its products. So don't sweat it; when one door closes another opens......cue en-masse netting of a huge cache of new passwords today. lolz

Re: OpenSSL 1.01+ compromised - FYI

Posted: Fri Apr 11, 2014 10:35 am
by polynurb

Re: OpenSSL 1.01+ compromised - FYI

Posted: Sun Apr 13, 2014 12:08 pm
by glebe digital
@polynurb

"Never believe anything until it has been officially denied."
Otto von Bismarck

:D