Site icon MacDailyNews

What to do about Heartbleed, a gaping security hole affecting 66 percent of the Internet (at least)

“There’s a security flaw in one of the basic encryption tools used by a huge number of websites, and it probably affects you,” Dylan Tweney reports for VentureBeat. “Just to be safe, you should probably change your passwords. All of them.”

“The flaw goes by the appropriately scary name ‘Heartbleed,’ and it affects OpenSSL, a data encryption library used by — potentially — more than two-thirds of the Internet’s websites,” Tweney reports. “In short, the bug means that attackers can ‘listen in’ on communications between those websites and the browsers visiting them.”

“The flaw exists in versions of OpenSSL that have been in use for about two years, and no one knew about it — no one legitimate, anyway — until a few days ago. Since then, the security researchers who discovered the bug have notified some of the major affected websites as well as the organization responsible for OpenSSL, which has already issued a fix,” Tweney reports. “They have also published an informational web site, at Heartbleed.com. That means major web sites should be fixed soon, if they aren’t already — but given how widespread the bug is, it may be weeks, months, or even years before the affected version is completely out of distribution.”

Read more in the full article here.

Exit mobile version