thewayne: (Cyranose)
[personal profile] thewayne
There's a concept called a man in the middle attack, you can think of it as someone listening in on your phone call so they here both sides of the conversation. In the way the internet works, it's doable, but not as easily. Well, this bug makes it kind of easy.

If you're able to position yourself between two computers that are both using certain versions of OpenSSL for encryption and privacy, then the middle man has the ability to intercept the encrypted packets when they're trying to establish the secure session and tell both hosts, silently, to switch to a weaker form of crypto. A form that presumably the middle man knows how to break.

So if you updated your OpenSSL software for Heartbleed, now you get to update it again.

OpenSSL is used a lot, but is not universal on the internet. One place where it is used heavily: Android smartphones and presumably tablets.

http://www.wired.com/2014/06/heartbleed-redux-another-gaping-wound-in-ssl-uncovered/

Date: 2014-06-20 12:48 am (UTC)
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)
From: [personal profile] silveradept
Patched within a little while of discovery, I'm guessing. While that's still plenty of opportunity for nefarious deeds, including all the time the bug existed, the expedience is appreciated, compared to more monolithic entities.

June 2025

S M T W T F S
123456 7
8910 11121314
15161718192021
22232425262728
2930     

Most Popular Tags

Page Summary

Style Credit

Expand Cut Tags

No cut tags
Page generated Jun. 13th, 2025 06:55 pm
Powered by Dreamwidth Studios