FYI Heartbleed fallout: Slowing the web to a crawl

visionlogic

Guru? Nope
Joined
Oct 11, 2009
Messages
117
Reaction score
33
Last Friday Web services company CloudFlare issued an open challenge to hackers to see if Heartbleed could be used to do something really dangerous - steal the security certificates of websites. Within hours several participating hackers had accomplished the feat. Now hundreds of thousands of websites will, along with patching the Heartbleed bug itself, have to revoke and reissue their security certificates. Since many browsers download and maintain revocation lists of these certificates these browsers will now have to continually check and re-download the now growing massive, hundreds of megabyte lists.

Full story: Heartbleed is about to get worse, and it will slow the Internet to a crawl
 

atsak

Guru
Joined
Sep 7, 2009
Messages
2,385
Reaction score
439
It was necessary to patch it immediately if you were a sysadmin, nothing more. Same as every other security risk that's identified monthly.
 

magna.vis

Guru
Joined
May 22, 2013
Messages
85
Reaction score
32
I have to disagree, this one was fairly widespread, and potentially presented, in clear text, a large amount of information. I do believe there are varying degrees of severity to vulnerabilities, don't you?
 

atsak

Guru
Joined
Sep 7, 2009
Messages
2,385
Reaction score
439
Yes, but the public at large was over informed on this. And by the way the internet didn't slow to a crawl. You can't or rather shouldn't tell the general public certain things because the lack the fundamentals to understand how to interpret things properly. It results in a massive outflow of resources to answer questions which are not relevant and become sensationalized in the press (because the press are idiots). Put simply this was a critical security flaw. It required immediate action by system administrators to patch it. Thus far the only information I know was stolen was here in Canada; the Canada Revenue Agency servers were exploited by a script kiddie who used the code released a day after the announcement by the black hat community to grab about 900 social insurance numbers because they had not patched it in time (ie SSN's to US folks, Taxpayer ID's to much of the rest of the world). They caught him a day or two later.

Having said that, a lack of transparency in general public information to prevent hysteria is often misused as an excuse to trample on rights (a la the NSA etc) so it is a bit of a dangerous thing to be sure. In this case though the information was transparent, but delivered in a typically sensationalist way by the press.

In other words, I am saying that you have to put the right information into the right people's hands at the right time. Similar risks (like the one with RDP services on Windows and several browser vulnerabilities) have not been so over sensationalized despite risking similar information. Consider your audience has often been my mantra.

It is OK to disagree though about the value of the way the information was disseminated IMO - I guess we all have different views about this kind of thing.
 

Members online

Forum statistics

Threads
25,811
Messages
167,759
Members
19,240
Latest member
nikko
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Top