public marks

PUBLIC MARKS with tag heartbleed

14 April 2014

Passwords are Obsolete — Cyber Security — Medium

by innipukinn & 1 other
I have 268 passwords on 268 different websites. At least that’s what my password manager says. I actually stopped saving new passwords a while back, so the real number of passwords I should change now that Heartbleed has been revealed is even higher than that. How many of those passwords do you think I’m going to change? It took me 10 minutes just to find the change password form for my bank! What about the average computer user who uses the same password for every website and doesn’t understand the details of the exploit? How many passwords will they change?

10 April 2014

Be Still My Breaking Heart | Dan Kaminsky's Blog

by night.kame

It shouldn’t take absolute heroism, one of the smartest guys in our community, and three years for somebody to notice a flaw when there’s a straight up length field in the patch. And that, I think, is a major and unspoken component of the panic around Heartbleed. The OpenSSL dev shouldn’t have written this (on New Years Eve, at 1AM apparently). His coauthors and release engineers shouldn’t have let it through. The distros should have noticed. Somebody should have been watching the till, at least this one particular till, and it seems nobody was.

Nobody publicly, anyway.

If we’re going to fix the Internet, if we’re going to really change things, we’re going to need the freedom to do a lot more dramatic changes than just Ping over TLS. We have to be able to manage more; we’re failing at less.

Heartbleed, le monumental échec du bazard cher à ESR et aux agileux de tout poil.

PUBLIC TAGS related to tag heartbleed

esr +   openssl +   security +  

Active users

innipukinn
last mark : 14/04/2014 12:26

night.kame
last mark : 10/04/2014 22:30