INTERNET: SECURITY:
'Heartbleed' Bug Undoes Web Encryption, Reveals Yahoo Passwords
by Stephen Shankland
April 8, 2014 2:55 AM PDT
CNET
http://www.cnet.com/news/
heartbleed-bug-undoes-web-encryption-reveals-user-passwords/
OR
http://tinyurl.com/oponnfm
.
.
A major new vulnerability called Heartbleed could let attackers gain access to
users' passwords and fool people into using bogus versions of Web sites. Some
already say they've found Yahoo passwords as a result.
.
The problem, disclosed Monday night, is in open-source software called OpenSSL
that's widely used to encrypt Web communications. Heartbleed can reveal the
contents of a server's memory, where the most sensitive of data is stored. That
includes private data such as usernames, passwords, and credit card numbers. It
also means an attacker can get copies of a server's digital keys then use that
to impersonate servers or to decrypt communications from the past or
potentially the future, too.
.
Security vulnerabilities come and go, but this one is extremely serious. Not
only does it require significant change at Web sites, it could require anybody
who's used them to change passwords too, because they could have been
intercepted. That's a big problem as more and more of people's lives move
online, with passwords recycled from one site to the next and people not always
going through the hassles of changing them.
.
snip
.
Yahoo said just after noon PT that it fixed the primary vulnerability on its
main sites: "As soon as we became aware of the issue, we began working to fix
it. Our team has successfully made the appropriate corrections across the main
Yahoo properties (Yahoo Homepage, Yahoo Search, Yahoo Mail, Yahoo Finance,
Yahoo Sports, Yahoo Food, Yahoo Tech, Flickr, and Tumblr) and we are working to
implement the fix across the rest of our sites right now. We're focused on
providing the most secure experience possible for our users worldwide and are
continuously working to protect our users' data."
.
However, Yahoo didn't offer advice to users about what they should do or what
the effect on them is.
.
.
The complete article may be read at the URL above.
.
.
Sincerely,
David Dillard
Temple University
(215) 204 - 4584
[log in to unmask]
http://workface.com/e/daviddillard
Net-Gold
http://groups.yahoo.com/group/net-gold
http://listserv.temple.edu/archives/net-gold.html
Index: http://tinyurl.com/myxb4w
General Internet & Print Resources
http://guides.temple.edu/general-internet
COUNTRIES
http://guides.temple.edu/general-country-info
EMPLOYMENT
http://guides.temple.edu/EMPLOYMENT
TOURISM
http://guides.temple.edu/tourism
DISABILITIES
http://guides.temple.edu/DISABILITIES
INDOOR GARDENING
http://tech.groups.yahoo.com/group/IndoorGardeningUrban/
Educator-Gold
http://groups.yahoo.com/group/Educator-Gold/
K12ADMINLIFE
http://groups.yahoo.com/group/K12AdminLIFE/
The Russell Conwell Learning Center Research Guide:
THE COLLEGE LEARNING CENTER
http://tinyurl.com/yae7w79
Information Literacy
http://guides.temple.edu/infolit
Nina Dillard's Photographs on Net-Gold
http://tinyurl.com/36qd2o
and also at
http://www.flickr.com/photos/neemers/
Twitter: davidpdillard
Temple University Site Map
https://sites.google.com/site/templeunivsitemap/home
Bushell, R. & Sheldon, P. (eds),
Wellness and Tourism: Mind, Body, Spirit,
Place, New York: Cognizant Communication Books.
Wellness Tourism: Bibliographic and Webliographic Essay
David P. Dillard
http://tinyurl.com/p63whl
INDOOR GARDENING
Improve Your Chances for Indoor Gardening Success
http://tech.groups.yahoo.com/group/IndoorGardeningUrban/
SPORT-MED
https://www.jiscmail.ac.uk/lists/sport-med.html
http://groups.yahoo.com/group/sports-med/
http://listserv.temple.edu/archives/sport-med.html
HEALTH DIET FITNESS RECREATION SPORTS TOURISM
http://health.groups.yahoo.com/group/healthrecsport/
http://listserv.temple.edu/archives/health-recreation-sports-tourism.html
.
.
Please Ignore All Links to JIGLU
in search results for Net-Gold and related lists.
The Net-Gold relationship with JIGLU has
been terminated by JIGLU and these are dead links.
http://groups.yahoo.com/group/Net-Gold/message/30664
http://health.groups.yahoo.com/group/healthrecsport/message/145
Temple University Listserv Alert :
Years 2009 and 2010 Eliminated from Archives
https://sites.google.com/site/templeuniversitylistservalert/
.
.
|