Little users can do to protect themselves from Heartbleed bug: Experts

Advertisement
By Reuters | Updated: 10 April 2014 13:32 IST
Security experts warn there is little Internet users can do to protect themselves from the recently uncovered "Heartbleed" bug that exposes data to hackers, at least not until vulnerable websites upgrade their software.

Researchers have observed sophisticated hacking groups conducting automated scans of the Internet in search of Web servers running a widely used Web encryption program known as OpenSSL that makes them vulnerable to the theft of data, including passwords, confidential communications and credit card numbers.

OpenSSL is used on about two-thirds of all Web servers, but the issue has gone undetected for about two years.

(Also see: OpenSSL 'Heartbleed' vulnerability lets attackers spy on secure Web traffic)

Advertisement

Kurt Baumgartner, a researcher with security software maker Kaspersky Lab, said his firm uncovered evidence on Monday that a few hacking groups believed to be involved in state-sponsored cyber espionage were running such scans shortly after news of the bug first surfaced the same day.

Advertisement

By Tuesday, Kaspersky had identified such scans coming from "tens" of actors, and the number increased on Wednesday after security software company Rapid7 released a free tool for conducting such scans.

"The problem is insidious," Baumgartner said. "Now it is amateur hour. Everybody is doing it."

Advertisement

OpenSSL software is used on servers that host websites but not PCs or mobile devices, so even though the bug exposes passwords and other data entered on those devices to hackers, it must be fixed by website operators.

(Also see: Heartbleed bug causing major security headache)

"There is nothing users can do to fix their computers," said Mikko Hypponen, chief research officer with security software maker F-Secure.

Advertisement

Representatives for Facebook Inc, Google and Yahoo Inc told Reuters they have taken steps to mitigate the impact on users.

Google spokeswoman Dorothy Chou told Reuters: "We fixed this bug early and Google users do not need to change their passwords."

Ty Rogers, a spokesman for Amazon Inc, said "Amazon.com is not affected."

In a blogpost dated Tuesday, the company said some of its Web cloud services, which provide the underlying infrastructure for apps such as online movie-streaming service Netflix and social network Pinterest, had been vulnerable. While it said the problems had been fixed, the company urged users of those services, which are popular in particular among the tech startup community, to take extra steps such as updating software.

Kaspersky Lab's Baumgartner noted that devices besides servers could be at risk because they run software programs with vulnerable OpenSSL code built into them.

They include versions of Cisco Systems Inc's AnyConnect for iOS and Desktop Collaboration, Tor, OpenVPN and Viscosity from Spark Labs. The developers of those programs have either updated their software or published directions for users on how to mitigate potential attacks.

Steve Marquess, president of the OpenSSL Software Foundation, said he could not identify other computer programs that used OpenSSL code that might make devices vulnerable to attack.

Cleaning up mess
Bruce Schneier, a well-known cryptologist and chief technology officer of Co3 Systems, called on Internet companies to issue new certificates and keys for encrypting Internet traffic, which would render stolen keys useless.

That will be time-consuming, said Barrett Lyon, chief technology officer of cyber-security firm Defense.Net Inc. "There's going to be lots of chaotic mess," he said.

Symantec Corp and GoDaddy, two major providers of SSL technology, said they do not charge for reissuing keys.

Mark Maxey, a director with cybersecurity firm Accuvant, said it is no easy task for large organizations to implement the multiple steps to clean up the bug, which means it will take some a long time to do so.

"Due to the complexity and difficulty in upgrading many of the affected systems, this vulnerability will be on the radar for attackers for years to come," he said.

Hypponen of F-Secure said computer users could immediately change passwords on accounts, but they would have to do so again if their operators notify them that they are vulnerable.

"Take care of the passwords that are very important to you," he said. "Maybe change them now, maybe change them in a week. And if you are worried about your credit cards, check your credit card bills very closely."

© Thomson Reuters 2014

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Ray-Ban Meta Gen 2 Glassses Are Now Available in India
  2. Vivo X300 Review: Pro Power, Pocket Size
  3. Samsung Galaxy S26 vs Galaxy S25: Here Are the Anticipated Upgrades
  4. Vivo X300 Launched in India With MediaTek Dimensity 9500 SoC at This Price
  5. Vivo X300 Pro With 200-Megapixel Telephoto Camera Launched in India
  6. OnePlus Pad Go 2 Visits Geekbench With This Midrange Chipset
  7. Oppo A6x 5G With 6,500mAh Battery Launched in India at This Price
  8. Redmi 15C 5G Camera Details Confirmed a Day Ahead of Launch in India
  9. Samsung Galaxy Z TriFold Launched With 10-Inch Display at This Price
  10. Apple Adds iPhone SE (First Generation), More Products to Obsolete List
  1. Sony Bank Plans US Dollar Stablecoin to Support Game, Anime Payments by 2026
  2. Amazon’s Rufus AI Chatbot Helps Drive Black Friday Sales and Engagement, Data Shows
  3. Redmi 15C 5G Camera Details Confirmed a Day Ahead of Launch in India: Expected Specifications, Features
  4. Samsung Galaxy S26, Galaxy S26+ Hardware Upgrades Spotted in Leaked Comparison With Galaxy S25 Counterparts
  5. Redmi Note 15 5G Series Price, Battery Capacity and Other Key Features Leaked Ahead of Anticipated Global Debut
  6. Khujechi Toke Raat Berate OTT Release: When and Where to Watch This Bengali Series Online?
  7. Twinless Now Available for Rent on Amazon Prime Video and Apple TV: What You Need to Know
  8. Who Is Amar Subramanya? Indian-Origin Researcher Taking Reigns of Apple’s AI Division
  9. Samsung Galaxy S26 Could Feature Revamped Lock Screen Customisation, 3D Wallpaper Effects, One UI 8.5 Leak Shows
  10. HMD XploraOne Teased to Launch Soon as Kid-Friendly Phone; Specifications Tipped
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.