Page 1 of 2

Heartbleed

Posted: Wed Apr 09, 2014 3:51 pm
by Tell
Is the forum affected by it? Also I just learned that you might want to change your minecraft password.

Re: Heartbleed

Posted: Wed Apr 09, 2014 4:05 pm
by Prototype
I should probably do that.

Re: Heartbleed

Posted: Wed Apr 09, 2014 4:56 pm
by Tau
No, the forum is safe from SSL exploits - it doesn't even use SSL.

Re: Heartbleed

Posted: Wed Apr 09, 2014 5:03 pm
by Chairman_Tiel
SSL*

SSH is something else entirely :P

And yes, it is affected. Apache uses OpenSSL, which is where the vulnerability lies. You'll want to update it when a patched version is out.

Re: Heartbleed

Posted: Wed Apr 09, 2014 5:58 pm
by Tau
Tiel wrote:SSL*

SSH is something else entirely :P
Sorry, I had just woken up from a nap.

And as far as I know, none of the website - even the login page - is actually secured in any meaningful way. I'll update everything, though, just because I should.

Re: Heartbleed

Posted: Fri Apr 11, 2014 5:10 pm
by Shadowcatbot
According to a random persons blog I saw earlier heart bleed works by dumping the servers recent memory to the hacker, so reasonably speaking changing your password would have higher chance of giving it to the hacker.

Il preper the laz0rs for when you all start advertising Canadian despots

Re: Heartbleed

Posted: Fri Apr 11, 2014 5:13 pm
by Ivan2006
Shadowcat wrote:According to a random persons blog I saw earlier heart bleed works by dumping the servers recent memory to the hacker, so reasonably speaking changing your password would have higher chance of giving it to the hacker.
Except if you're changing it on services that got the security update that fixes Heartbleed.

Re: Heartbleed

Posted: Fri Apr 11, 2014 5:17 pm
by Shadowcatbot
Ivan2006 wrote:
Shadowcat wrote:According to a random persons blog I saw earlier heart bleed works by dumping the servers recent memory to the hacker, so reasonably speaking changing your password would have higher chance of giving it to the hacker.
Except if you're changing it on services that got the security update that fixes Heartbleed.
But how do you know it got updated? What if the service itself was hacked? What if the update is really a fake update that's a hack that steals your DNA so they can clone you an steal your identity.

Never trust a machine! The robot uprising is happening! Except for you proto your cool.

Re: Heartbleed

Posted: Sat Apr 12, 2014 3:36 am
by Archduke Daynel, PhD
Shadowcat wrote:
Ivan2006 wrote:
Shadowcat wrote:According to a random persons blog I saw earlier heart bleed works by dumping the servers recent memory to the hacker, so reasonably speaking changing your password would have higher chance of giving it to the hacker.
Except if you're changing it on services that got the security update that fixes Heartbleed.
But how do you know it got updated? What if the service itself was hacked? What if the update is really a fake update that's a hack that steals your DNA so they can clone you an steal your identity.

Never trust a machine! The robot uprising is happening! Except for you proto your cool.
Proto is not a robot. He has been confirmed to be a motorcycle.

Re: Heartbleed

Posted: Sat Apr 12, 2014 6:28 am
by Ivan2006
Daynel wrote: Proto is not a robot. He has been confirmed to be a motorcycle.
Spoiler:
Image

Re: Heartbleed

Posted: Sat Apr 12, 2014 10:45 am
by Saravanth
Spoiler:
Image

Re: Heartbleed

Posted: Sat Apr 12, 2014 11:13 am
by  ҉ 
Shadowcat wrote:According to a random persons blog I saw earlier heart bleed works by dumping the servers recent memory to the hacker, so reasonably speaking changing your password would have higher chance of giving it to the hacker.
Image

Re: Heartbleed

Posted: Sat Apr 12, 2014 2:32 pm
by Chairman_Tiel
That was actually pretty informative. Thank you.

Re: Heartbleed

Posted: Sat Apr 12, 2014 2:40 pm
by Ivan2006
LJS' comic was propably the most informative description of Heartbleed I ever got.

Re: Heartbleed

Posted: Sat Apr 12, 2014 2:44 pm
by Error
XKCD, for the win.