Heartbleed , the bug discovered in the OpenSSL protocol , is much more serious than it may sound and affects almost all users who use online services .
This is a technical issue that has an impact on our daily lives, since it affects everything from web email services such as those of Google and Yahoo, to financial institutions, and therefore our transactions.
The worst part is that no one can say for sure if and who has been affected by this particular bug – either companies or users. Let's see why.
What is Heartbleed? It is a security flaw in the open-source OpenSSL communications encryption standard – when there is a secure connection between a server and a user. It is named so because it affects the heartbeat , which is the way (resembling a heartbeat) to confirm that there is communication between two ends, e.g. your computer and a server.
What types of applications are affected?
Web surfing , email , instant messaging , as well as VPNs (Virtual Private Networks), in short, almost everything during our online activity.
How many servers are vulnerable?
Experts estimate that approximately two-thirds of servers worldwide were affected.
Who discovered Heartbleed ? Researchers from the cybersecurity company Codenomicon and Google.
How long were the servers
The OpenSSL code that had the vulnerability was released in March 2012.
Should we be worried?
Yes! Our personal information that we think is safe, in fact is not, since there is a possibility that it is in the possession of fraudsters who managed to extract it from the servers where it is stored. However, no one can know if data has been stolen from the servers of company X, even if they had this specific problem.
How can I know if my data has been stolen?
In reality, there is no way, since due to this specific security flaw, the servers could not recognize the difference between real users and an attempt to record/steal data.
If you want to see if a site was affected by the Heartbleed bug, you can check it with this tool. By typing in its address, you can see if it is on the list of those affected. Two more indicative lists can be found here and here and another tool here.
What should I do ? The only thing someone can do is change their login details for the services they use. However, this will only make sense if the site in question has updated its servers with the security update.
If not made the relevant updates, there is a possibility that your new information could end up in the hands of hackers, who probably in the process of extracting user data from the servers that have the problem.
Source: e-pcmag.gr

