Resend my activation email : Register : Log in 
BCF: Bike Chat Forums


The Heartbleed list: Passwords you need to change right now.

Reply to topic
Bike Chat Forums Index -> Politics & Current Affairs
View previous topic : View next topic  
Author Message

Lord Percy
World Chat Champion



Joined: 03 Aug 2012
Karma :

PostPosted: 15:53 - 10 Apr 2014    Post subject: The Heartbleed list: Passwords you need to change right now. Reply with quote

Biggest Internet security blunder ever, apparently.

Basically your passwords were possibly exposed for websites including Google, Yahoo, Apple, eBay and plenty more.

https://mashable.com/2014/04/09/heartbleed-bug-websites-affected/?utm_cid=mash-com-Tw-main-link

edit: just seen this in the geek zone forum but some people (eg myself) might not look there that often, so here it is as a 'current affair' too...
 Back to top
View user's profile Send private message You must be logged in to rate posts

Ste
Not Work Safe



Joined: 01 Sep 2002
Karma :

PostPosted: 16:01 - 10 Apr 2014    Post subject: Reply with quote

You mean you don't change your passwords regularly anyway? Shocked
 Back to top
View user's profile Send private message Visit poster's website You must be logged in to rate posts

Rogerborg
nimbA



Joined: 26 Oct 2010
Karma :

PostPosted: 16:58 - 10 Apr 2014    Post subject: Reply with quote

MINECRAFT! Shocked
____________________
Biking is 1/20th as dangerous as horse riding.
GONE: HN125-8, LF-250B, GPz 305, GPZ 500S, Burgman 400 // RIDING: F650GS (800 twin), Royal Enfield Bullet Electra 500 AVL, Ninja 250R because racebike
 Back to top
View user's profile Send private message You must be logged in to rate posts

Benno
World Chat Champion



Joined: 06 May 2012
Karma :

PostPosted: 17:39 - 10 Apr 2014    Post subject: Reply with quote

OKCupid...now I can tell all those feminists it wasn't really me all along and get them to sleep with me
____________________
I'm autistic. That means I'm smarter than you.
 Back to top
View user's profile Send private message You must be logged in to rate posts
- This post is not being displayed because the poster has bad karma. Unhide this post / all posts.

daemonoid
World Chat Champion



Joined: 27 Jun 2008
Karma :

PostPosted: 10:31 - 11 Apr 2014    Post subject: Reply with quote

mpd72 wrote:
I wonder if this is how all the BT Yahoo logins have been compromised over the last 2 or so years? I have several customers who have BTYahoo web based email addresses at home and have to change the password several times a year, due to their logins being used to send out url based spam.

I did also wonder if the timing of this had anything to do with XP end of support, which happened a couple of days ago? This flaw has been around for 2 years, but was only discovered just after Microsoft want everyone to buy new copies of Windows.....mmmm

Is it just the SSL server end which needs patching, or do the PC's need a security update too?


It's an openSSL bug - https://www.openssl.org/ nothing to do with windows XP and for the most part it's only server side software that's affected - https://mashable.com/2014/04/08/major-security-encryption-bug-heartbleed/

Notice how MS is clear of all of this because they have their own SSL implementation:
https://mashable.com/2014/04/09/heartbleed-bug-websites-affected/?utm_cid=mash-com-Tw-main-link

Yahoo could've been a target, but why anyone who knew about this before it was public would target them for email spam is beyond me. You can get into a whole load of other things, including online shops and a number of banks.
____________________
current: ducati monster 750
past: hyosung gt250r, bajaj pulsar 180, hyosung gt 125 comet
@thomasgarrard | www.straitjkt.com | www.racingseven.com
 Back to top
View user's profile Send private message Send e-mail Visit poster's website You must be logged in to rate posts

daemonoid
World Chat Champion



Joined: 27 Jun 2008
Karma :

PostPosted: 11:43 - 11 Apr 2014    Post subject: Reply with quote

Here's a simple explanation...

https://imgs.xkcd.com/comics/heartbleed_explanation.png
____________________
current: ducati monster 750
past: hyosung gt250r, bajaj pulsar 180, hyosung gt 125 comet
@thomasgarrard | www.straitjkt.com | www.racingseven.com
 Back to top
View user's profile Send private message Send e-mail Visit poster's website You must be logged in to rate posts
- This post is not being displayed because the poster has bad karma. Unhide this post / all posts.

Im-a-Ridah
World Chat Champion



Joined: 20 Oct 2006
Karma :

PostPosted: 14:04 - 11 Apr 2014    Post subject: Reply with quote

mpd72 wrote:

The BT Yahoo thing has happened a few times over the last couple of years, I have customers who get hit every few months. Every so often thousands of their account logins get compromised and used to send spam. Around 1 in 10 email from BT accounts is malicious.

There's clearly some money to be made in sending out large scale spam, otherwise people wouldn't go to all the effort in the first place.

https://www.pcpro.co.uk/news/security/382462/one-in-ten-emails-from-bt-accounts-is-malicious


They're probably clicking dodgy links or attachments in emails.
 Back to top
View user's profile Send private message Send e-mail You must be logged in to rate posts

daemonoid
World Chat Champion



Joined: 27 Jun 2008
Karma :

PostPosted: 14:18 - 11 Apr 2014    Post subject: Reply with quote

mpd72 wrote:
The BT Yahoo thing has happened a few times over the last couple of years, I have customers who get hit every few months. Every so often thousands of their account logins get compromised and used to send spam. Around 1 in 10 email from BT accounts is malicious.

There's clearly some money to be made in sending out large scale spam, otherwise people wouldn't go to all the effort in the first place.

https://www.pcpro.co.uk/news/security/382462/one-in-ten-emails-from-bt-accounts-is-malicious


Yeah, no doubt about that. It's just that the heartbleed bug gives you access to so much bigger scams.

Spam has happened way before and will continue way after this bug, but it's most likely, as Ridah says, auto compromised accounts - tricking people into giving their details. Even better, the fact that you're already sending spam means you can send out dodgy mails to ask unsuspecting users for their details.

I think the huge numbers coming from BT is because BT users are the least educated users. They haven't made any choices to get themselves connected, just stuck with the same old people who've provided their phone since forever.
____________________
current: ducati monster 750
past: hyosung gt250r, bajaj pulsar 180, hyosung gt 125 comet
@thomasgarrard | www.straitjkt.com | www.racingseven.com
 Back to top
View user's profile Send private message Send e-mail Visit poster's website You must be logged in to rate posts
- This post is not being displayed because the poster has bad karma. Unhide this post / all posts.

daemonoid
World Chat Champion



Joined: 27 Jun 2008
Karma :

PostPosted: 15:44 - 11 Apr 2014    Post subject: Reply with quote

mpd72 wrote:
There's more to this BT Yahoo account issue than people being tricked into giving away their details - have a quick Google. Some of the customers I've seen who's accounts have been compromised didn't even know what the email account password was as it was configured in Outlook, not needing a webmail login.

https://www.telegraph.co.uk/finance/newsbysector/epic/btdota/10089355/BT-dumps-Yahoo-email-after-hacking-claims.html

Someone from within the company has also tipped off The Register, that BT were allowing unsecured HTTP rather than HTTPS connections to their webmail.

https://www.bbc.co.uk/news/technology-26480381


Perhaps there is a lot more to the BT/yahoo thing than scam logins. You've highlighted the bit that shows it's not the heartbleed exploit/bug leading to it though - http... essentially they were transmitting usernames & passwords unencrypted. Heartbleed is vulnerability over https (ssl) that allows the memory of the server to be viewed as per the xkcd comic above.
____________________
current: ducati monster 750
past: hyosung gt250r, bajaj pulsar 180, hyosung gt 125 comet
@thomasgarrard | www.straitjkt.com | www.racingseven.com
 Back to top
View user's profile Send private message Send e-mail Visit poster's website You must be logged in to rate posts

shereen
World Chat Champion



Joined: 15 Mar 2011
Karma :

PostPosted: 18:57 - 11 Apr 2014    Post subject: Reply with quote

I linked this on facebook and one of my friends said not to change them yet until the sites had been patched...

Is he talking shit?
____________________
"The Internet is the first thing that humanity has built that humanity doesn't understand, the largest experiment in anarchy that we have ever had"
 Back to top
View user's profile Send private message Send e-mail You must be logged in to rate posts

Rogerborg
nimbA



Joined: 26 Oct 2010
Karma :

PostPosted: 19:19 - 11 Apr 2014    Post subject: Reply with quote

shereen wrote:
I linked this on facebook and one of my friends said not to change them yet until the sites had been patched.

Change password.
sleep(604800);
Change password.
____________________
Biking is 1/20th as dangerous as horse riding.
GONE: HN125-8, LF-250B, GPz 305, GPZ 500S, Burgman 400 // RIDING: F650GS (800 twin), Royal Enfield Bullet Electra 500 AVL, Ninja 250R because racebike
 Back to top
View user's profile Send private message You must be logged in to rate posts

shereen
World Chat Champion



Joined: 15 Mar 2011
Karma :

PostPosted: 19:27 - 11 Apr 2014    Post subject: Reply with quote

Rogerborg wrote:
shereen wrote:
I linked this on facebook and one of my friends said not to change them yet until the sites had been patched.

Change password.
sleep(604800);
Change password.


Huh? Laughing
____________________
"The Internet is the first thing that humanity has built that humanity doesn't understand, the largest experiment in anarchy that we have ever had"
 Back to top
View user's profile Send private message Send e-mail You must be logged in to rate posts

Rogerborg
nimbA



Joined: 26 Oct 2010
Karma :

PostPosted: 20:52 - 11 Apr 2014    Post subject: Reply with quote

Change it now.
Wait a week.
Change it again.
____________________
Biking is 1/20th as dangerous as horse riding.
GONE: HN125-8, LF-250B, GPz 305, GPZ 500S, Burgman 400 // RIDING: F650GS (800 twin), Royal Enfield Bullet Electra 500 AVL, Ninja 250R because racebike
 Back to top
View user's profile Send private message You must be logged in to rate posts

krarkol
World Chat Champion



Joined: 17 Oct 2012
Karma :

PostPosted: 13:51 - 12 Apr 2014    Post subject: Reply with quote

If you change it before the new security is in place, they'll already have your password rendering the new security useless Wink
____________________
Bandit 600 - deaded
 Back to top
View user's profile Send private message You must be logged in to rate posts

anthony_r6
World Chat Champion



Joined: 31 Mar 2011
Karma :

PostPosted: 19:32 - 12 Apr 2014    Post subject: Reply with quote

They have to be looking for the information. The media is acting like everything on the internet has been compromised. If they haven't taken your information yet, you're good. If they have, change your password, and they'll effectively have to re-take the information for it to be a concern.

So changing it now is probably a good idea.

Also, the BT Yahoo mail thing is true. I've had mine compromised several times and I haven't click on anything I wasn't expecting. I have come across other people with similar issues, too.

I don't think BT have even considered it an issue.
____________________
Ted : "Maybe he's agoraphobic."
Dougal : "Jack scared of fighting? I don't think so, Ted."
 Back to top
View user's profile Send private message You must be logged in to rate posts

dydey90
World Chat Champion



Joined: 01 Oct 2013
Karma :

PostPosted: 12:57 - 17 Apr 2014    Post subject: Reply with quote

HAHAHAHAHAHA

Quote:
Hotmail / Outlook

No

No

No

Microsoft services were not running OpenSSL, according to LastPass.


Finally something that didn't affect hotmail!

...Oh wait that's because there isn't any security at all.

Anyway, I think the only thing that would affect me is Facebook and there's not much they can do with that. Facebook security means that you need a security code to sign in on a new device anyway.
____________________
This post is probably not serious and shouldn't be taken literally.
Past: CBR125,ER6f NINJA 650, ZZR600 Current: VFR750
 Back to top
View user's profile Send private message You must be logged in to rate posts

pa_broon74
World Chat Champion



Joined: 28 Mar 2006
Karma :

PostPosted: 13:07 - 17 Apr 2014    Post subject: Reply with quote

If facebook is at risk, they can have at mine, good luck trying to scam anyone out of anything posing as an Official Chilean Government Hooker who used to work at Victoria's Secret.

Smile
____________________
Didn't catch anything.
 Back to top
View user's profile Send private message You must be logged in to rate posts

Im-a-Ridah
World Chat Champion



Joined: 20 Oct 2006
Karma :

PostPosted: 17:42 - 17 Apr 2014    Post subject: Reply with quote

Doesn't make any difference WRT to police and government

Under Part 3 of Regulation of Investigatory Powers Act (RIPA) you've got to give them your password anyway or go to jail Laughing

Bye bye rights Clapping
 Back to top
View user's profile Send private message Send e-mail You must be logged in to rate posts
Old Thread Alert!

The last post was made 11 years, 141 days ago. Instead of replying here, would creating a new thread be more useful?
  Display posts from previous:   
This page may contain affiliate links, which means we may earn a small commission if a visitor clicks through and makes a purchase. By clicking on an affiliate link, you accept that third-party cookies will be set.

Post new topic   Reply to topic    Bike Chat Forums Index -> Politics & Current Affairs All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum

Read the Terms of Use! - Powered by phpBB © phpBB Group
 

Debug Mode: ON - Server: birks (www) - Page Generation Time: 0.10 Sec - Server Load: 4.11 - MySQL Queries: 13 - Page Size: 122.08 Kb