Author Topic: Heartbleed  (Read 3321 times)

0 Members and 1 Guest are viewing this topic.

Offline Puddsy

  • nice
  • * Elated Elder
  • Thread Starter
  • Posts: 12281
  • Location: RSTLN E
  • "Do you shovel to survive, or survive to shovel?"
Heartbleed
« on: Tue, 08 April 2014, 16:01:38 »
http://heartbleed.com/ explains it better than I can.

Be careful out there friends

The biggest software that is affected (AFAIK) is Valve's steam software.
QFR | MJ2 TKL | "Bulgogiboard" (Keycon 104) | ctrl.alt x GON 60% | TGR Alice | Mira SE #29 | Mira SE #34 | Revo One | z | Keycult No. 1 | First CW87 prototype | Mech27v1 | Camp C225 | Duck Orion V1 | LZ CLS sxh | Geon Frog TKL | Hiney TKL One | Geon Glare TKL



"Everything is worse, but in a barely perceptible and indefinable way" -dollartacos, after I came back from a break | "Is Linkshine our Nixon?" -NAV | "Puddsy is the Puddsy of keebs" -ns90

Offline codyeatworld

  • * Destiny Supporter
  • Posts: 944
  • Location: Bay Area, California
Re: Heartbleed
« Reply #1 on: Tue, 08 April 2014, 16:05:39 »
ctrlalt.io has already been patched :D
Very serious bug though.

TLDR
"Heartbleed (CVE-2014-0160) is a vulnerability in OpenSSL that allows any remote user to dump some of the contents of the server’s memory."




Offline SpAmRaY

  • NOT a Moderator
  • * Certified Spammer
  • Posts: 14667
  • Location: ¯\(°_o)/¯
  • because reasons.......
Re: Heartbleed
« Reply #2 on: Tue, 08 April 2014, 16:11:12 »
http://heartbleed.com/ explains it better than I can.

Be careful out there friends

The biggest software that is affected (AFAIK) is Valve's steam software.

So the internet has been hacked :eek:

Offline IvanIvanovich

  • Mr. Silk Underwear
  • Posts: 8199
  • Location: USA
Re: Heartbleed
« Reply #3 on: Tue, 08 April 2014, 16:57:06 »
Whoops! Someone discovered the NSA's backdoor to everything.

Offline rowdy

  • HHKB Hapster
  • * Erudite Elder
  • Posts: 21175
  • Location: melbourne.vic.au
  • Missed another sale.
Re: Heartbleed
« Reply #4 on: Tue, 08 April 2014, 17:35:19 »
My heart bleeds for everyone who is affected.
"Because keyboards are accessories to PC makers, they focus on minimizing the manufacturing costs. But that’s incorrect. It’s in HHKB’s slogan, but when America’s cowboys were in the middle of a trip and their horse died, they would leave the horse there. But even if they were in the middle of a desert, they would take their saddle with them. The horse was a consumable good, but the saddle was an interface that their bodies had gotten used to. In the same vein, PCs are consumable goods, while keyboards are important interfaces." - Eiiti Wada

NEC APC-H4100E | Ducky DK9008 Shine MX blue LED red | Ducky DK9008 Shine MX blue LED green | Link 900243-08 | CM QFR MX black | KeyCool 87 white MX reds | HHKB 2 Pro | Model M 02-Mar-1993 | Model M 29-Nov-1995 | CM Trigger (broken) | CM QFS MX green | Ducky DK9087 Shine 3 TKL Yellow Edition MX black | Lexmark SSK 21-Apr-1994 | IBM SSK 13-Oct-1987 | CODE TKL MX clear | Model M 122 01-Jun-1988

Ị̸͚̯̲́ͤ̃͑̇̑ͯ̊̂͟ͅs̞͚̩͉̝̪̲͗͊ͪ̽̚̚ ̭̦͖͕̑́͌ͬͩ͟t̷̻͔̙̑͟h̹̠̼͋ͤ͋i̤̜̣̦̱̫͈͔̞ͭ͑ͥ̌̔s̬͔͎̍̈ͥͫ̐̾ͣ̔̇͘ͅ ̩̘̼͆̐̕e̞̰͓̲̺̎͐̏ͬ̓̅̾͠͝ͅv̶̰͕̱̞̥̍ͣ̄̕e͕͙͖̬̜͓͎̤̊ͭ͐͝ṇ̰͎̱̤̟̭ͫ͌̌͢͠ͅ ̳̥̦ͮ̐ͤ̎̊ͣ͡͡n̤̜̙̺̪̒͜e̶̻̦̿ͮ̂̀c̝̘̝͖̠̖͐ͨͪ̈̐͌ͩ̀e̷̥͇̋ͦs̢̡̤ͤͤͯ͜s͈̠̉̑͘a̱͕̗͖̳̥̺ͬͦͧ͆̌̑͡r̶̟̖̈͘ỷ̮̦̩͙͔ͫ̾ͬ̔ͬͮ̌?̵̘͇͔͙ͥͪ͞ͅ

Offline Puddsy

  • nice
  • * Elated Elder
  • Thread Starter
  • Posts: 12281
  • Location: RSTLN E
  • "Do you shovel to survive, or survive to shovel?"
Re: Heartbleed
« Reply #5 on: Tue, 08 April 2014, 19:02:52 »
My heart bleeds for everyone who is affected.

That's why it's such a huge problem.

Quite literally almost every internet user is/was affected. If not directly, than indirectly.
QFR | MJ2 TKL | "Bulgogiboard" (Keycon 104) | ctrl.alt x GON 60% | TGR Alice | Mira SE #29 | Mira SE #34 | Revo One | z | Keycult No. 1 | First CW87 prototype | Mech27v1 | Camp C225 | Duck Orion V1 | LZ CLS sxh | Geon Frog TKL | Hiney TKL One | Geon Glare TKL



"Everything is worse, but in a barely perceptible and indefinable way" -dollartacos, after I came back from a break | "Is Linkshine our Nixon?" -NAV | "Puddsy is the Puddsy of keebs" -ns90

Offline nuclearsandwich

  • Posts: 752
  • Location: Santa Clara Valley, CA
Re: Heartbleed
« Reply #6 on: Tue, 08 April 2014, 19:05:50 »
GitHub's blog post explains a lot of the salient bits as well as what many sites are having to do to mitigate damage. If you notice that you've been signed out of any services over the next few days those services are likely expunging possibly compromised sessions.

EDIT: Full disclosure I work at GitHub but was just a bystander for all the work our operations and infrastructure team did during this whole mess.

Offline Puddsy

  • nice
  • * Elated Elder
  • Thread Starter
  • Posts: 12281
  • Location: RSTLN E
  • "Do you shovel to survive, or survive to shovel?"
Re: Heartbleed
« Reply #7 on: Tue, 08 April 2014, 20:00:59 »
That's a good read. I'll share that around.

You work at github? That's cool! What percent of employees use mech boards?
QFR | MJ2 TKL | "Bulgogiboard" (Keycon 104) | ctrl.alt x GON 60% | TGR Alice | Mira SE #29 | Mira SE #34 | Revo One | z | Keycult No. 1 | First CW87 prototype | Mech27v1 | Camp C225 | Duck Orion V1 | LZ CLS sxh | Geon Frog TKL | Hiney TKL One | Geon Glare TKL



"Everything is worse, but in a barely perceptible and indefinable way" -dollartacos, after I came back from a break | "Is Linkshine our Nixon?" -NAV | "Puddsy is the Puddsy of keebs" -ns90

Offline nuclearsandwich

  • Posts: 752
  • Location: Santa Clara Valley, CA
Re: Heartbleed
« Reply #8 on: Tue, 08 April 2014, 20:18:56 »
That's a good read. I'll share that around.

You work at github? That's cool! What percent of employees use mech boards?

Hilariously most of the mech boards are used by non-engineers. Most folks are fine with the Mac keyboard or the bluetooth board. I don't have any hard numbers since most of the company is remote but the Kinesis is quite popular. One of my coworkers had a Unicomp until he borrowed my Realforce 55g and now he has a Hi Pro. There's also the odd Das Keyboard and Monoprice board and one of my remote coworkers uses some kinda Topre something because I printed some Octocat keycaps with WASD and he couldn't use 'em. I need to bring my Matias and Ergodox back to the office for folks to borrow and start campaigning more...

Offline swill

  • * Elevated Elder
  • Posts: 3365
  • Location: Canada eh
  • builder & enabler
    • swillkb.com
Re: Heartbleed
« Reply #9 on: Tue, 08 April 2014, 21:12:48 »
http://heartbleed.com/ explains it better than I can.

Be careful out there friends

The biggest software that is affected (AFAIK) is Valve's steam software.

Ya, we have been getting everything updated at work as well...

Offline dagdrivaren

  • Posts: 18
  • Location: Sweden
Re: Heartbleed
« Reply #10 on: Wed, 09 April 2014, 01:00:00 »
You know what place you're at when a thread discussing one of the most serious bugs the internet has ever seen gets derailed almost instantly into a discussion on mechanical keyboards.  :D
« Last Edit: Wed, 09 April 2014, 01:01:32 by dagdrivaren »
Filco Majestouch 2 Tenkeyless (brown switches)

Offline cultofjosh

  • Posts: 89
  • Location: PA, USA
Re: Heartbleed
« Reply #11 on: Thu, 10 April 2014, 19:30:00 »
I lucked out and only had to rekey 3 certificates. And 1 was self-signed. Easy. For once, RedHat's ancient stable copies of software paid off, only Centos 6.4 and 6.5 needed to be updated.

Offline chibishin

  • Posts: 32
  • sittin around all day listening to classical music
Re: Heartbleed
« Reply #12 on: Fri, 11 April 2014, 15:46:27 »
This should not come as a shock to anyone.

Offline Puddsy

  • nice
  • * Elated Elder
  • Thread Starter
  • Posts: 12281
  • Location: RSTLN E
  • "Do you shovel to survive, or survive to shovel?"
Re: Heartbleed
« Reply #13 on: Fri, 11 April 2014, 15:47:40 »
I mean, it's been around for a while.

I'm not surprised.
QFR | MJ2 TKL | "Bulgogiboard" (Keycon 104) | ctrl.alt x GON 60% | TGR Alice | Mira SE #29 | Mira SE #34 | Revo One | z | Keycult No. 1 | First CW87 prototype | Mech27v1 | Camp C225 | Duck Orion V1 | LZ CLS sxh | Geon Frog TKL | Hiney TKL One | Geon Glare TKL



"Everything is worse, but in a barely perceptible and indefinable way" -dollartacos, after I came back from a break | "Is Linkshine our Nixon?" -NAV | "Puddsy is the Puddsy of keebs" -ns90

Offline chibishin

  • Posts: 32
  • sittin around all day listening to classical music
Re: Heartbleed
« Reply #14 on: Fri, 11 April 2014, 21:43:04 »
given the recent disclosures concerning the NSA, it stands to reason that this may have even been put there by them.

of course, this is just speculation until we have hard evidence.

Offline Puddsy

  • nice
  • * Elated Elder
  • Thread Starter
  • Posts: 12281
  • Location: RSTLN E
  • "Do you shovel to survive, or survive to shovel?"
Re: Heartbleed
« Reply #15 on: Fri, 11 April 2014, 21:45:05 »
Yo, turns out google was affected, change your gmail passwords on Monday.
QFR | MJ2 TKL | "Bulgogiboard" (Keycon 104) | ctrl.alt x GON 60% | TGR Alice | Mira SE #29 | Mira SE #34 | Revo One | z | Keycult No. 1 | First CW87 prototype | Mech27v1 | Camp C225 | Duck Orion V1 | LZ CLS sxh | Geon Frog TKL | Hiney TKL One | Geon Glare TKL



"Everything is worse, but in a barely perceptible and indefinable way" -dollartacos, after I came back from a break | "Is Linkshine our Nixon?" -NAV | "Puddsy is the Puddsy of keebs" -ns90

Offline chibishin

  • Posts: 32
  • sittin around all day listening to classical music
Re: Heartbleed
« Reply #16 on: Fri, 11 April 2014, 21:46:13 »
now would be a good time to turn on 2 factor authentication if you aren't using it already

Offline cultofjosh

  • Posts: 89
  • Location: PA, USA
Re: Heartbleed
« Reply #17 on: Sat, 12 April 2014, 13:51:15 »
now would be a good time to turn on 2 factor authentication if you aren't using it already

Good advice regardless of this heartbleed mess. Turn it on anywhere you can. Places I have 2 factor authentication enabled:

outlook.com
gmail/google apps
Amazon AWS
godaddy

Even turn it on for your gaming accounts, even if you don't care about them. Every account hacked gives away some personal information that can be used to try to get into other accounts you own...

And never use the same password for more than 1 account! Use a password safe. For the accounts that you have to have passwords that you can remember, see this classic XKCD:

http://xkcd.com/936/

If you don't need to know the password by heart, use a very long random string and keep it in a password safe. You're also protected against keyloggers this way since you are never actually typing the password - how could you, it's impossible for any sane person to know :)