There has been a big problem with the internet lately – the “Heartbleed” bug.
You can also check it out on on BBC and from the US government;
http://www.bbc.com/news/technology-26985818
What is this computer bug about?
Basically this bug gives hackers a way past the security on roughly two thirds of the websites out there. (Don’t worry; our site was not affected.)
Hackers can grab usernames, passwords, credit card information, encryption keys and other sensitive information they shouldn’t have.
The worst part is that this bug existed for two years before any security company or researcher noticed.
It sounds bad, and it is bad. But it isn’t the end of the world, or even the Internet. Read on to take a look at what exactly is going on and how you can stay safe.
How does it work?
Basically the Heartbleed problem is with the “SSL” part of websites, hackers can’t get info from your computer directly, just what is saved on websites you use. It also doesn’t mean you should avoid encryption. Encryption is essential for online security.
The long-term fix is in the hands of the affected website owners not you… but there is something you can do now…
You can change your passwords to stay secure.. I know its a hassle, but if you want to take matters into your own hands with top security its the best thing you can do.
Fraud alert: If you receive an email from a website asking you to change your password, always open your browser and log in to your account manually. Don’t click on any links in the email. Scammers will be taking advantage of this situation and sending fake emails to trick you into clicking dodgey links.
Luckily, the major websites are responding and fixing Heartbleed quickly. Sites like Yahoo, DropBox, Twitter, Tumblr and many more are already updated. There are still many sites that arent however.
Note: There is some debate about when you should change your passwords, but if you are worried about it you could change all of your passwords to a temporary one for a month and then change them back to something similar to the original ones. I would suggest not using the original passwords as they were.
Why you don’t need to panic…
In Summary just because there was a potential vulnerability it doesn’t mean that it was exploited – just that there was some possibility of it being exploited if the hacker was at the right place at the right time. At the moment it looks like alot of the major sites didn’t experience any big hack attacks, but either way if you have some account that really needs to be secure, its a great time to change your password.

Leave a Reply