OpenSSL security vulnerability

ORM

Power Member
Joined
Oct 16, 2013
Messages
756
Reaction score
703
Today some of the websites started strongly recommend to change passwords as there was OpenSSL security vulnerability found. I already experience some issues.

More info: link
 
If you just realized this today you should change all sensitive login information on your server, there's a good chance someone has pulled it.
 
If you just realized this today you should change all sensitive login information on your server, there's a good chance someone has pulled it.

Obsolutely. This thread was created with intention to inform others who werent aware of that
 
You should not only change your passwords but if you run any SSL sites with the vulnerable version of openssl you should re-issue you SSL certificates with a new private key as well as patching your servers.

It is possible that your private key has been stolen in which case the SSL communication with your site is just as good a clear text communication to someone who has your private key since they can decrypt this communication. This would mean that even if your users change their passwords, they could easily be stolen again.
 
Lol, I think it's been for around 3 years already.
Not discovered?
 
This is seriously a bad bug. I will be keen to see how many companies step forward and fess up that they were vulnerable. They really have no choice and need to tell people so they can change their passwords.
 
Back
Top