Heartbleed

Miscellaneous. No spam or advertisements, constructive discussion encouraged.
Tell
Commander
Commander
Posts:859
Joined:Thu Dec 06, 2012 6:59 pm
IGN:tell276
Location:East USA
Heartbleed

Post by Tell » Wed Apr 09, 2014 3:51 pm

Is the forum affected by it? Also I just learned that you might want to change your minecraft password.
Image

Prototype
Developer
Posts:2968
Joined:Fri Dec 07, 2012 1:25 am
Affiliation:NSCD
IGN:Currently:Small_Bear
Location:Yes

Re: Heartbleed

Post by Prototype » Wed Apr 09, 2014 4:05 pm

I should probably do that.
Spoiler:
Image
Mistake Not... wrote: This isn't rocket science, *!
Image

Spoiler:
Image

User avatar
Tau
Admin
Posts:750
Joined:Mon Dec 10, 2012 9:58 am
Affiliation:Futureville Mafia
IGN:TehPwnzor7306
Location:Ancapistan

Re: Heartbleed

Post by Tau » Wed Apr 09, 2014 4:56 pm

No, the forum is safe from SSL exploits - it doesn't even use SSL.
Image
Vinyl wrote:"RP" and gaming and homosexuality is what's keeping [the forum] afloat.

Chairman_Tiel
Rear Admiral
Rear Admiral
Posts:1890
Joined:Sat Dec 01, 2012 9:39 am
Affiliation:GLORIOUS REPUBLIC

Re: Heartbleed

Post by Chairman_Tiel » Wed Apr 09, 2014 5:03 pm

SSL*

SSH is something else entirely :P

And yes, it is affected. Apache uses OpenSSL, which is where the vulnerability lies. You'll want to update it when a patched version is out.
[spoiler]Image[/spoiler]

User avatar
Tau
Admin
Posts:750
Joined:Mon Dec 10, 2012 9:58 am
Affiliation:Futureville Mafia
IGN:TehPwnzor7306
Location:Ancapistan

Re: Heartbleed

Post by Tau » Wed Apr 09, 2014 5:58 pm

Tiel wrote:SSL*

SSH is something else entirely :P
Sorry, I had just woken up from a nap.

And as far as I know, none of the website - even the login page - is actually secured in any meaningful way. I'll update everything, though, just because I should.
Image
Vinyl wrote:"RP" and gaming and homosexuality is what's keeping [the forum] afloat.

Shadowcatbot
Vice Admiral
Vice Admiral
Posts:2623
Joined:Thu Dec 06, 2012 9:46 pm
Affiliation:Nivanshae
IGN:_Shadowcat_
Location:Munching on important looking wires.

Re: Heartbleed

Post by Shadowcatbot » Fri Apr 11, 2014 5:10 pm

According to a random persons blog I saw earlier heart bleed works by dumping the servers recent memory to the hacker, so reasonably speaking changing your password would have higher chance of giving it to the hacker.

Il preper the laz0rs for when you all start advertising Canadian despots
Last edited by Shadowcatbot on Fri Apr 11, 2014 5:14 pm, edited 1 time in total.
In yo ceiling, stealin yo wires



Do not open. Ever. At all. Enter at your own risk to life and limb.
Trigger warning
Bot gore warning
Memetic biohazard
Error bait
Spoiler:
[Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted]

Ivan2006
Fleet Admiral
Fleet Admiral
Posts:3021
Joined:Fri Dec 07, 2012 12:10 pm
Affiliation:[redacted]
IGN:Ivan2006
Location:In a universe.
Contact:

Re: Heartbleed

Post by Ivan2006 » Fri Apr 11, 2014 5:13 pm

Shadowcat wrote:According to a random persons blog I saw earlier heart bleed works by dumping the servers recent memory to the hacker, so reasonably speaking changing your password would have higher chance of giving it to the hacker.
Except if you're changing it on services that got the security update that fixes Heartbleed.
Quotes:
Spoiler:
CMA wrote:IT'S MY HOT BODY AND I DO WHAT I WANT WITH IT.
Tiel wrote:hey now no need to be rough
Daynel wrote: you can talk gay and furry to me any time
CMA wrote:And I can't fuck myself, my ass is currently occupied

Shadowcatbot
Vice Admiral
Vice Admiral
Posts:2623
Joined:Thu Dec 06, 2012 9:46 pm
Affiliation:Nivanshae
IGN:_Shadowcat_
Location:Munching on important looking wires.

Re: Heartbleed

Post by Shadowcatbot » Fri Apr 11, 2014 5:17 pm

Ivan2006 wrote:
Shadowcat wrote:According to a random persons blog I saw earlier heart bleed works by dumping the servers recent memory to the hacker, so reasonably speaking changing your password would have higher chance of giving it to the hacker.
Except if you're changing it on services that got the security update that fixes Heartbleed.
But how do you know it got updated? What if the service itself was hacked? What if the update is really a fake update that's a hack that steals your DNA so they can clone you an steal your identity.

Never trust a machine! The robot uprising is happening! Except for you proto your cool.
In yo ceiling, stealin yo wires



Do not open. Ever. At all. Enter at your own risk to life and limb.
Trigger warning
Bot gore warning
Memetic biohazard
Error bait
Spoiler:
[Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted][Redacted]

Archduke Daynel, PhD
Rear Admiral
Rear Admiral
Posts:1940
Joined:Thu Dec 06, 2012 1:18 pm
Affiliation:ZIF

Re: Heartbleed

Post by Archduke Daynel, PhD » Sat Apr 12, 2014 3:36 am

Shadowcat wrote:
Ivan2006 wrote:
Shadowcat wrote:According to a random persons blog I saw earlier heart bleed works by dumping the servers recent memory to the hacker, so reasonably speaking changing your password would have higher chance of giving it to the hacker.
Except if you're changing it on services that got the security update that fixes Heartbleed.
But how do you know it got updated? What if the service itself was hacked? What if the update is really a fake update that's a hack that steals your DNA so they can clone you an steal your identity.

Never trust a machine! The robot uprising is happening! Except for you proto your cool.
Proto is not a robot. He has been confirmed to be a motorcycle.
BASH THE FASH CLASS WAR NOW

Ivan2006
Fleet Admiral
Fleet Admiral
Posts:3021
Joined:Fri Dec 07, 2012 12:10 pm
Affiliation:[redacted]
IGN:Ivan2006
Location:In a universe.
Contact:

Re: Heartbleed

Post by Ivan2006 » Sat Apr 12, 2014 6:28 am

Daynel wrote: Proto is not a robot. He has been confirmed to be a motorcycle.
Spoiler:
Image
Quotes:
Spoiler:
CMA wrote:IT'S MY HOT BODY AND I DO WHAT I WANT WITH IT.
Tiel wrote:hey now no need to be rough
Daynel wrote: you can talk gay and furry to me any time
CMA wrote:And I can't fuck myself, my ass is currently occupied

Saravanth
Captain
Captain
Posts:1189
Joined:Wed Dec 19, 2012 11:08 am
IGN:Saravanth

Re: Heartbleed

Post by Saravanth » Sat Apr 12, 2014 10:45 am

Spoiler:
Image
5241

"When I get a hold of a Boeing 777 I will stuff it in the cargo bay my freighter and when I find you I will engage in an invasion of your butt that will make 9/11 look like a picnic, Hexalani swine." -Kobialka, 0531015.M3
"Hyperlite, you *." -Tau, 0446015.M3








Don't tell anybody, but to this day I have a faint hope for Futurecraft, or something similar to it, to happen. Within my lifetime.

 ҉ 
Commodore
Commodore
Posts:1574
Joined:Thu Dec 06, 2012 6:50 am
Affiliation:Kzinti Empire
Location:Kzinhome

Re: Heartbleed

Post by  ҉  » Sat Apr 12, 2014 11:13 am

Shadowcat wrote:According to a random persons blog I saw earlier heart bleed works by dumping the servers recent memory to the hacker, so reasonably speaking changing your password would have higher chance of giving it to the hacker.
Image
;.'.;'::.;:".":;",,;':",;

(Kzinti script, as best as can be displayed in Human characters, translated roughly as "For the Patriarchy!")

Chairman_Tiel
Rear Admiral
Rear Admiral
Posts:1890
Joined:Sat Dec 01, 2012 9:39 am
Affiliation:GLORIOUS REPUBLIC

Re: Heartbleed

Post by Chairman_Tiel » Sat Apr 12, 2014 2:32 pm

That was actually pretty informative. Thank you.
[spoiler]Image[/spoiler]

Ivan2006
Fleet Admiral
Fleet Admiral
Posts:3021
Joined:Fri Dec 07, 2012 12:10 pm
Affiliation:[redacted]
IGN:Ivan2006
Location:In a universe.
Contact:

Re: Heartbleed

Post by Ivan2006 » Sat Apr 12, 2014 2:40 pm

LJS' comic was propably the most informative description of Heartbleed I ever got.
Quotes:
Spoiler:
CMA wrote:IT'S MY HOT BODY AND I DO WHAT I WANT WITH IT.
Tiel wrote:hey now no need to be rough
Daynel wrote: you can talk gay and furry to me any time
CMA wrote:And I can't fuck myself, my ass is currently occupied

Error
Moderator
Posts:4205
Joined:Thu Dec 06, 2012 11:49 am
Affiliation:CNI
IGN:FC_Rangefinder
Location:Sol IIIa, School of Hard Knocks

Re: Heartbleed

Post by Error » Sat Apr 12, 2014 2:44 pm

XKCD, for the win.
Image

Post Reply