Fiesta Fan Forums

Fiesta Fan Forums (http://www.fiestafan.com/forums/index.php)
-   M O S (http://www.fiestafan.com/forums/forumdisplay.php?f=25)
-   -   Heartbleed (http://www.fiestafan.com/forums/showthread.php?t=33324)

Vasu 04-11-2014 11:19 PM

Heartbleed
 
Do any of us know whether FF uses OpenSSL for it's security? And whether it's likely to be fixed? In other news, you guys should all probably change your Facebook password, and probably also your Google password. Also Tumblr, Pinterest, Instagram, Yahoo Mail.

Here's a nice tracking page:

http://mashable.com/2014/04/09/heart...ites-affected/

For those of you wondering what all of this is about, xkcd has the simplest explanation I've seen:

http://imgs.xkcd.com/comics/heartbleed_explanation.png

Ralath 04-12-2014 02:30 AM

That comic was still confusing.

Vasu 04-12-2014 02:39 AM

Well the bug in SSL essentially allowed anyone to access whatever was in the server's RAM or main memory at the time. Now any processing that a computer does involved moving data from your normal file system to the RAM.

Now imagine there's a file 'supersecret.txt' on my Dropbox that I just accessed. The files contents are copied to main memory on the way to me. The contents of the file itself remain restricted to me, but whatever is within the main memory isn't really associated with my file any more once I'm done. It's just unstructured data sitting there, and can be overwritten at any time.

However, someone exploiting this bug can get it to spit out whatever is in the main memory and it will, because the server doesn't see the bunch of 1s and 0s as belonging to your file any more. And so any sensitive data may have been obtained. It's a crapshoot, but there's a chance of it happening.

Not all major websites used OpenSSL, but it is pretty widely used, so a lot of servers have been putting up patches for the flaw. Obviously changing your password is useless if the company itself hasn't patched their server.

Ivramire 04-12-2014 11:44 AM

Just spent about an hour waterproofing my passwords and making them all unique. Heartbleed's serious stuff.

Vasu 04-12-2014 04:39 PM

Quote:

Originally Posted by Ivramire (Post 468917)
Just spent about an hour waterproofing my passwords and making them all unique. Heartbleed's serious stuff.

I use a common root word for my passwords which are modified based on the name of the website I visit. If a human looks at them in plaintext, it's pretty obvious, but it should stand up to machine analysis haha.

EDIT: I found a better checking tool:
https://lastpass.com/heartbleed/

Entropy 04-12-2014 07:42 PM

Quote:

Originally Posted by Vasu (Post 468914)
Do any of us know whether FF uses OpenSSL for it's security?

FF doesn't use OpenSSL.

Also, passwords are hashed before they are sent to the server and are salted and hashed again before being stored. Your passwords are safe even if someone does get in. Even I can't figure out what they are.

Vasu 04-12-2014 10:36 PM

Hm, good to know, but that's probably standard procedure anyway. The danger is with the server's private keys being leaked via this bug. But it's a moot point anyway since we don't use OpenSSL.

Hessah 04-13-2014 11:07 AM

Oh man I have to relearn all my passwords...

Ivramire 04-13-2014 12:47 PM

All my passwords are now random strings of letters and numbers, like addgag9a8duge7wg. I'm using a password-manager (Lastpass) with a strong master password to manage it all for me.

Lirange 04-13-2014 04:00 PM

I'll take my chances hehe

Blaaaaaaaah 04-13-2014 10:07 PM

Living life on the edge huh. reflected by your LoL gameplay.

Hessah 04-13-2014 10:38 PM

Quote:

Originally Posted by Ivramire (Post 468930)
All my passwords are now random strings of letters and numbers, like addgag9a8duge7wg. I'm using a password-manager (Lastpass) with a strong master password to manage it all for me.

This LastPass concept is so new.. I'm still trying to understand how that is safe?!

So the idea is that you don't have to remember any passwords anymore? What happens if you log into, say FB, from different computers, will LastPass carry over to other computers?

Lirange 04-13-2014 10:44 PM

Quote:

Originally Posted by Blaaaaaaaah (Post 468932)
Living life on the edge huh. reflected by your LoL gameplay.

Yep, both my password and gameplay are unpredictable.

Ralath 04-14-2014 12:10 AM

ugh I'm trying to reset my Tumblr account password because apparently had the Heartbleed bug, but I can't even remember my own password...

Ivramire 04-14-2014 02:25 AM

Quote:

Originally Posted by Hessah (Post 468933)
This LastPass concept is so new.. I'm still trying to understand how that is safe?!

So the idea is that you don't have to remember any passwords anymore? What happens if you log into, say FB, from different computers, will LastPass carry over to other computers?

The idea is that you only have to remember one password, your master password for Lastpass and Lastpass remembers all other passwords for your other sites even if they're random gibberish.

I pretty much never need to log into sites that need my passwords from other computers but if I needed to at some point, I'd just download Lastpass onto that computer's browser and log-in from there. I think that you don't even need to download the extension, just go to the Lastpass site and get the info from there.

Blaaaaaaaah 04-14-2014 03:33 AM

Quote:

Originally Posted by Ivramire (Post 468942)
The idea is that you only have to remember one password, your master password for Lastpass and Lastpass remembers all other passwords for your other sites even if they're random gibberish.

I pretty much never need to log into sites that need my passwords from other computers but if I needed to at some point, I'd just download Lastpass onto that computer's browser and log-in from there. I think that you don't even need to download the extension, just go to the Lastpass site and get the info from there.

There's our problem for us office-bludgers xD

Hessah 04-14-2014 03:43 AM

Quote:

Originally Posted by Blaaaaaaaah (Post 468945)
There's our problem for us office-bludgers xD

Indeed... I was thinking about all the different places I might log into things that requires passwords... and then I realise.. I'm probably a LOT less security conscious than Ivra..

Ivramire 04-14-2014 06:29 AM

I kinda feel like using someone else's computer is kind of like using their toothbrush xD

Hessah 04-14-2014 06:35 AM

HAHAHAHAHAHA

Well that makes me think maybe I'm not THAT bad... Other than my home comp, it's generally just my work comp and mobile / tablet.. but that would still be 4 places that I'll need to install LastPass.. if I go with that...

Lirange 04-14-2014 12:33 PM

Quote:

Originally Posted by Ralath (Post 468937)
ugh I'm trying to reset my Tumblr account password because apparently had the Heartbleed bug, but I can't even remember my own password...

Wth, you're not young enough to have a Tumblr.

Ralath 04-14-2014 07:15 PM

I'M STILL YOuNG! !!

Lirange 04-14-2014 07:57 PM

Heh...

Ralath 04-15-2014 12:07 AM

I Snapchat too.

Lirange 04-15-2014 12:19 AM

Omg. Do you have a WhatsApp too?

Lirange 04-15-2014 12:20 AM

WHO ARE YOU SENDING YOUR NuDES TO?

Blaaaaaaaah 04-15-2014 01:08 AM

I use whatsapp am I young too????

Lirange 04-15-2014 01:16 AM

Maybe I'm just not hip...WHAT'S WRONG WITH TEXTING AND FB MESSAGING?

Hessah 04-15-2014 01:16 AM

I'm sure our parents would love to hear the idea that using whatsapp = young...



^ Sometimes I think Lirange is older than us..

Blaaaaaaaah 04-15-2014 01:30 AM

I still think he's 14.

Lirange 04-15-2014 01:46 AM

Quote:

Originally Posted by Hessah (Post 468965)
I'm sure our parents would love to hear the idea that using whatsapp = young...



^ Sometimes I think Lirange is older than us..

DOES YOUR FAMILY HAVE A WHATSAPP GROUP?
Quote:

Originally Posted by Blaaaaaaaah (Post 468966)
I still think he's 14.

I sometimes look 14

Ralath 04-15-2014 03:37 AM

Quote:

Originally Posted by Lirange (Post 468961)
WHO ARE YOU SENDING YOUR NuDES TO?

i bet you'd like to know.





my parents don't use WhatsApp, but they use WeChat. They invited me to join a group with them but I declined LOL The only reason I would use that app would be to chat with them.

Hessah 04-15-2014 04:17 AM

Quote:

Originally Posted by Lirange (Post 468964)
Maybe I'm just not hip...WHAT'S WRONG WITH TEXTING AND FB MESSAGING?

I assume Lirange prefers the traditional texting and FB message.. he sounds like he's more old fashion than us keke

We do have a family whatsapp chat... so convenient!

I'm even in a cousins whatsapp chat with my hushand's family of cousins.. which is fantastic! I finally got to know his extended family who lives in the states that I hear a lot about.. I admire how close all the cousins are..

Blaaaaaaaah 04-15-2014 04:23 AM

ohh, there's a difference between old-fashioned and old. cos I thought you meant old-mature which is def not the case for lirange 8D

Hessah 04-15-2014 04:26 AM

Oh ok then old-fashion LOLOL

Lirange 04-15-2014 10:54 AM

I'm totes mature.
Seems like my family isn't as communicative as yours Lool.

Blaaaaaaaah 04-15-2014 09:16 PM

maybe when you're older.... hahaha


All times are GMT. The time now is 10:51 PM.

Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.