According to reports on the internet...

orange

Veteran and General Yakker
Joined
Jul 6, 2010
Messages
17,704
Tagline
Broken beyond repair but highly affable
#1
The internet is screwed.

Well, supposedly. The Heartbleed Open SSL (that's https to you and I) exploit has been so bad for two whole years that now half a million sites are going to have to have their security certificates REVOKED and reissued after being patched...WHEE!

So, does everybody know all your shit? I seriously doubt it but the techies have to have their wet dream and WHO SAYS it was ever secure anyway?

Good! Google gets it in the nuts! Couldn't be happier.
 

orange

Veteran and General Yakker
Joined
Jul 6, 2010
Messages
17,704
Tagline
Broken beyond repair but highly affable
#3
I'll tell you what the new XP or other OS exploit seems to be...

I'm geting attacked when I'm not even online...this one was rated severe and came via port 80. Looked like a possible piggyback prefix on an existing domain but I did not check that domain.

No shit, they are coming from nowhere.
 

Gepetto

Administrator
Staff member
Joined
May 15, 2011
Messages
13,536
Location
Sterling, MA
Tagline
Old 'Arn Enthusiast
#4
The internet is screwed.

Well, supposedly. The Heartbleed Open SSL (that's https to you and I) exploit has been so bad for two whole years that now half a million sites are going to have to have their security certificates REVOKED and reissued after being patched...WHEE!

So, does everybody know all your shit? I seriously doubt it but the techies have to have their wet dream and WHO SAYS it was ever secure anyway?

Good! Google gets it in the nuts! Couldn't be happier.
Google, Microsoft and Apple do not employ OpenSSL.
 

orange

Veteran and General Yakker
Joined
Jul 6, 2010
Messages
17,704
Tagline
Broken beyond repair but highly affable
#5
Are you sure? You Tube and all of Google, Outlook.com email addresses all use https and with the way Outlook.com's email keeps going down...

Of that list, only apple.com does not have the https suffix.
 

Gepetto

Administrator
Staff member
Joined
May 15, 2011
Messages
13,536
Location
Sterling, MA
Tagline
Old 'Arn Enthusiast
#6
Are you sure? You Tube and all of Google, Outlook.com email addresses all use https and with the way Outlook.com's email keeps going down...

Of that list, only apple.com does not have the https suffix.
https prefix does not necessarily signify use of OpenSSL. It signifies that it is an encrypted site link. OpenSSL is one open source program/method of performing the encryption to the national/industry standard. Google, MS and Apple have their own equivalents. I am sure there are other SSL program/methods out there too.

Open source is where the problem is right now. That SSL program/method has a security flaw. That is what you get for free...
 

orange

Veteran and General Yakker
Joined
Jul 6, 2010
Messages
17,704
Tagline
Broken beyond repair but highly affable
#8
But I already know it was rather flawed and left to rot for two years like a GM recall. Old news to me now. The real problem is that it sounds like hackers are going back to just randomly pounding on your ports, especially 80.
 

Gepetto

Administrator
Staff member
Joined
May 15, 2011
Messages
13,536
Location
Sterling, MA
Tagline
Old 'Arn Enthusiast
#9
But I already know it was rather flawed and left to rot for two years like a GM recall. Old news to me now. The real problem is that it sounds like hackers are going back to just randomly pounding on your ports, especially 80.
No. The problem here has nothing to do with Port80. The problem here is that freely shared source code opens up the keys to the kingdom to hackers that want to examine your code architecture and find weaknesses to exploit.

Microsoft has it totally right, it's my source code, I paid dearly to develop it and NO YOU CANNOT LOOK AT IT OR HAVE IT!.

Example:

You have some deep dark family secret. Nobody knows about it except you and it stays a deep dark family secret. Until you write it down on a pieces of paper and staple it to all the town telephone poles :)

That is what Open Source software amounts to.
 

orange

Veteran and General Yakker
Joined
Jul 6, 2010
Messages
17,704
Tagline
Broken beyond repair but highly affable
#10
I would be even more worried about the crackpot people that write the software and ask you to donate to their coffee fund but are not forthcoming on support.
 

orange

Veteran and General Yakker
Joined
Jul 6, 2010
Messages
17,704
Tagline
Broken beyond repair but highly affable
#11
UPDATE! I'm happy to announce that only YAHOO! is screwed up...oh and Photobucket.

The rest of the internet is alive and living next to the freeway.
 

Lazarus Short

Veteran and General Yakker
Joined
Mar 10, 2012
Messages
14,293
Location
Independence, MO
Tagline
I'm the Red Knight, by grant of the Black
#12
That's nice - I keep getting download notices from Adobe to upgrade my flash player, but it won't finish. Then McAfee bugs me about security, but my Mac guru describes their product as "a steaming pile of dung." Then Apple wants me to call an 877 number. My days on Safari may be coming to an end I may need to stop splitting my time between Safari and Firefox...
 

orange

Veteran and General Yakker
Joined
Jul 6, 2010
Messages
17,704
Tagline
Broken beyond repair but highly affable
#13
If adobe.com is not in the URL, it's fake, and Yahoo is where they tend to come from if you stay too long.
 
Last edited:
Top