thewayne: (Cyranose)
[personal profile] thewayne
There's a concept called a man in the middle attack, you can think of it as someone listening in on your phone call so they here both sides of the conversation. In the way the internet works, it's doable, but not as easily. Well, this bug makes it kind of easy.

If you're able to position yourself between two computers that are both using certain versions of OpenSSL for encryption and privacy, then the middle man has the ability to intercept the encrypted packets when they're trying to establish the secure session and tell both hosts, silently, to switch to a weaker form of crypto. A form that presumably the middle man knows how to break.

So if you updated your OpenSSL software for Heartbleed, now you get to update it again.

OpenSSL is used a lot, but is not universal on the internet. One place where it is used heavily: Android smartphones and presumably tablets.

http://www.wired.com/2014/06/heartbleed-redux-another-gaping-wound-in-ssl-uncovered/

Date: 2014-06-20 12:48 am (UTC)
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)
From: [personal profile] silveradept
Patched within a little while of discovery, I'm guessing. While that's still plenty of opportunity for nefarious deeds, including all the time the bug existed, the expedience is appreciated, compared to more monolithic entities.

May 2025

S M T W T F S
    1 23
45678910
1112 131415 1617
18 19 20 212223 24
25262728 2930 31

Most Popular Tags

Page Summary

Style Credit

Expand Cut Tags

No cut tags
Page generated Jun. 6th, 2025 12:24 pm
Powered by Dreamwidth Studios