Top Banner
Heartbleed Bug
14

Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

Dec 16, 2015

Download

Documents

Bryce Johns
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

HeartbleedBug

Page 2: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.
Page 3: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

When all the net security people are freaking out, it’s probably an okay time to worry

Page 4: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

A serious bug in OpenSSL — a library that is used to secure a very, very large percentage of the Internet’s traffic — was yesterday discovered and publicly disclosed

Page 5: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

The apps you use, the sites you visit; if they encrypt the data they send back and forth, there’s a good chance they use OpenSSL

Page 6: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

This means an attacker could get a server to spit out its secret keys, allowing them to read any communication that they intercept, like it wasn’t encrypted it all …

Page 7: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

including the keys it uses to encrypt and decrypt communication (e.g. usernames, passwords, credit cards, etc.)

Page 8: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

2+ yearsAffects 2/3 of webMillions of servers

Page 9: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

Discovered and reported to the OpenSSL team by Neel Mehta of Google’s security team

Page 10: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

•Yahoo was affected•Say they patched most of their sites yesterday

Page 11: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

•Apple, Google, Microsoft not affected•Most e-banking sites OK

Page 12: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

•Flair for drama?•Tor says “You might want to stay away from the Internet entirely for the next few days while things settle.”

Page 13: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

•Do you Yahoo?•Use the same password on multiple sites? Might want to change it.

Page 14: Heartbleed Bug. When all the net security people are freaking out, it’s probably an okay time to worry.

•This is breaking news. We’ll await further advice which hopefully will be coming soon