Diberdayakan oleh Blogger.
Tampilkan postingan dengan label Heartbleed. Tampilkan semua postingan
Tampilkan postingan dengan label Heartbleed. Tampilkan semua postingan

Jumat, 25 April 2014

How to protect your Android from the Heartbleed bug

Loie Favre

Loie Favre

Loie Favre is a Canadian-German, food-loving, live-music-craving globe-trotter. Coming from a humble background in the Canadian Prairies centred around nature and the Arts, she studied Translation and Languages in Edmonton. She left his home on the Pacific Coast of Canada, to seek her fortune in Berlin. She is now an Editor and Manager for AndroidPIT.com and is enjoying discovering about everything and anything under the sun about Android.

Heartbleed is one of the biggest security breaches the internet has ever known. Here’s how to protect your Android smartphone against this OpenSSL bug which leaves your phone vulnerable to virus attacks.

android heartbleed© AndroidPIT

What is Heartbleed

Hearbleed is a flaw in the OpenSLL software ‘’Heartbeat’’ function which is what’s behind secure internet connections. It is this function that is buggy, allowing attackers to manipulate it and cause some serious damage to the affected systems. The Heartbleed vulnerability impacts any infrastructure that has the affected version of OpenSSL.

So who is affected?

According to Symantec, the majority of main browsers do not use this OpenSLL software. But on Android, it’s the complete opposite. Your Android is at risk, which means that private info stored on it is as well. You can use the Symantec SSL Tool check to see if a website is vulnerable to the Heartbleed bug.

Heartbleed on Android

Generally speaking, if you are on a vulnerable website and a new identical tab opens when you have entered your identifiers, stop right there and close out right away. Another method that hackers often use is to inject a code into a vulnerable Android navigator, which allows the instigator to fish out sensitive information that is stored in the phone’s memory.

How to protect your Android against Heartbleed

Lookout, a developing group that you might already know thanks to their antivirus app, have developed a new app called Heartbleed Security Scanner that will help you see whether your phone is vulnerable or not: the application however does NOT protect you, which means you will have to wait until Google or your manufacturer releases an update.

heartbleed© AndroidPIT

Tips to protect your data

  • Change your password regularly
  • Avoid using the same passwords on various websites
  • If you detect a vulnerable site using the Symantec SSL toolbox, wait before changing your password.
  • If your Android is vulnerable, be cautious and make sure you update your phone.

The real problem with Heartbleed is that the bug has already existed for over two years, and that your passwords are potentially exposed, yet another reason why you should change them regularly.

Source: Ars Technica



View the Original article

Selasa, 22 April 2014

Chromebleed Notifies You if a Visited Site was Hit by Heartbleed Bug

Chromebleed Notifies You if a Visited Site was Hit by Heartbleed Bug

Chrome: The Heartbleed bug is among the major security vulnerabilities we have seen in recent times. It's one of those cases where precaution is the order of the day. You could manually check sites or use Chromebleed, an extension that tells you if the site you're on was affected by the bug.

Chromebleed uses Filippo Valsorda's little tool to test if the page was hit by Heartbleed and hasn't issued a patch yet. You're going to be safe on the bigger websites like Yahoo, but there's a chance that some of the smaller sites haven't yet patched their servers, so this little protection will help. If you do visit some such site, Chromebleed will throw a notification warning you, in which case it's best to exit and notify the site's developers to fix their issue.

Chromebleed | Chrome Web Store via BGR



View the Original article

Senin, 21 April 2014

Report: NSA Exploited Heartbleed For Years. NSA: No

Update: An account associated with the NSA tweeted out a quick denial: “Statement: NSA was not aware of the recently identified Heartbleed vulnerability until it was made public.” So, either Bloomberg was misled, misunderstood their information, or the NSA is lying. [A caveat: The Twitter account in question is being treated by the larger world as legitimate, but remains unverified by Twitter itself.]

Update 2: See bottom of post for full NSA statement. Source one, two. 

This afternoon Bloomberg reported that the National Security Agency (NSA) knew about the now infamous Heartbleed flaw in OpenSSL, and that it used the weakness to collect intelligence.

It is not clear if the NSA used Heartbleed to collect information regarding citizens in the United States, so this issue may not concern privacy like so many other revelations regarding the agency have. Instead, the idea is that the NSA was reportedly aware of the issue, and chose to exploit the exploit rather than helping the larger technology community quickly.

In short, The NSA essentially decided that its own intelligence efforts were more important than the security of your information.

In the ensuing few days since the Heartbleed weakness has been exposed, companies and services large and small have rushed to patch their systems, change their cryptographic protections, and alert their users to change their passwords. This situation could have been ameliorated, if not avoided altogether.

The NSA’s reputation inside of the technology world has been long-suffering, especially in the wake of efforts to weaken encryption by inserting back doors, and its efforts to tap the cables between data centers of large, popular technology firms. This will not help.

Making the average person understand the extent of the NSA’s actions has been difficult — some don’t get, or simply don’t care, about their digital privacy — but to deliberately ignore a known flaw that could put every member of your family at risk? That’s easier to grasp.

Update 2, continued: 

Screen Shot 2014-04-11 at 2.04.47 PM

CrunchWeek: Heartbleed Terrifies The Internet, And Dropbox Hires Condoleezza Rice

Happy Friday everyone, and welcome to another episode of CrunchWeek, our weekly round up of the biggest stories in technology.

This week Leena Rao, Kim-Mai Cutler, and your humble servant took to the round table to dig into Heartbleed, and the NSA-thereof, along with Dropbox’s new controversial board pick, and its new products.

(If can add a small production note, the show was taped in between Bloomberg’s bombshell post that the NSA knew about Heartbleed and had exploited it, and the NSA’s later vigorous denial. Naturally, this short explanation itself will become dated as well once more truth shakes loose. For now, enjoy the show!)

Minggu, 20 April 2014

Your phone has Heartbleed? Lookout’s Detector app can tell

how-to-check-for-heartbleed-lookout-detector-app-0212

Following this week’s discovery of the serious Heartbleed bug in OpenSSL, mobile security company Lookout released an Android tool that will help users detect the presence of the security vulnerability on their Android devices.

The Heartbleed bug allows malicious intruders to exploit a vulnerability in the OpenSSL library, thereby exposing confidential and encrypted data that were normally protected by SSL/TLS encryption.

Vulnerability detection

Lookout’s detector app can be downloaded for free from the Google Play Store and does nothing else but identify the OpenSSL version being used on the Android device, check for the existence of Heartbleed, and, if it is present, determine whether Heartbleed is enabled.

The app, however, won’t tell the user if sites visited or other apps used are affected. The app doesn’t provide a fix either.

If the device is in the clear, the app will display “Everything is OK”. In the worst case, the user will see a red warning sign along with the confirmation “And the vulnerable behavior is enabled,” indicating that Heartbleed is present and is active or enabled.

Most others will likely get a yellow warning, indicating the presence of Heartbleed but assuring that, although it’s there, it’s not enabled.

User concern

Although the security flaw is primarily a server-side vulnerability, Android users worry about it because Android uses a version of OpenSSL. Devices running Android 4.1.1 Jelly Bean are vulnerable, but Google is working on a patch for that specific version.

Google assured Android users, though, that “all versions of Android are immune to CVE-2014-0160 (with the limited exception of Android 4.1.1; patching information for Android 4.1.1 is being distributed to Android partners).”

On the bright side, Lookout reports that it has not yet found cases of mobile devices exploited using the Heartbleed vulnerability. However, this is not good reason for anyone to be completely complacent.

Vigilance and looking out

One positive step that an average user may take is to check for software updates from the Android device’s manufacturer and to install them immediately, especially updates that patch the security hole. Another is to be vigilant and be on the lookout for notices and alerts from sites that the user has online accounts with. Affected sites may implement measures to remove the vulnerability and inform their users accordingly. Apart from these, there’s very little else that a user can do.

Have you scanned your Android device for Heartbleed today? What result did you get? Does it scare you? Share your thoughts in the comments section.

Jumat, 18 April 2014

Heartbleed: What Is It And What Should You do About It?

If you see a red, hollow, dripping heart symbol in your news feed, then yes, you’ve probably heard of the latest security breach to hit the Internet: Heartbleed. The security bug that’s compromised the security of accounts on sites like Yahoo, Facebook and even the Canadian Revenue agency has the whole Internet is up in arms. You’ve probably been asked to change your passwords for your emails, online accounts etc, but hold up.

Heartbleed

In the midst of all this information, though, it’s can be hard to make heads or tails of what’s going on exactly. What is Heartbleed, exactly? Is it really as dangerous as everyone’s saying? How can you find out if you’re affected? Here’s a quick look at some of the main issues surrounding Heartbleed and what you can do about it.

What Is Heartbleed?

Heartbleed is a bug that affects the OpenSSL service, which is a cryptographic library that’s used to encrypt data on more than two-thirds of all the websites on the Internet. If you’ve ever seen that locked padlock logo in your browser, or visited a site using the https: protocol, then you’re familiar with OpenSSL.

What Heartbleed Can Do

The Heartbleed bug exposes data held in a server’s RAM, meaning just about anyone has access to, and can snoop on Internet traffic, even when it’s supposedly encrypted.

Interlopers, if any, could take advantage of Heartbleed to obtain the keys and data that they’d need to decipher and read all the encrypted data that recently passed through a server.

Is It A Problem?

Given the fact that more than two-thirds of websites and services on the internet use OpenSSL, yes, Heartbleed is quite a major problem. However, it’s important to bear in mind that Heartbleed is not malware or a virus, and thus, a site affected by Heartbleed may not necessarily have had any data stolen. And it’s been around, undetected, since 2012.

Pretty much all forms of personal, encrypted information are vulnerable to Heartbleed. As long as it passes through the OpenSSL protocol, someone could have accessed it illegitimately. Passwords, emails, user names, communications — you name it, it’s probably accessible in some form or another due to Heartbleed.

So, yes, it is a problem.

How To Tell If You’re Affected

While it’s true that not every service has been affected by Heartbleed, it’s still better to be safe than sorry. While you can’t know for sure whether your own data has been compromised, there are a couple of services out there that can help you check whether you’re affected by Heartbleed.

Filippo Heartbleed Test

This Heartbleed test sends out malformed heartbeats to the website of your choice, extracting around 80 bytes of memory as proof. In other words, the test attacks the site much like a hacker would, to test whether the site is vulnerable to Heartbleed.

Filippo Heartbleed Test

LastPass Heartbleed Checker

The LastPass team has also put up a tool for you to check for affected sites. All you have to do is to type in the domain of the website you want to check and then click on See if the site is vulnerable to Heartbleed.

LastPass Heartbleed Checker

What To Do If You’re affected

If from the checks, you’ve found that you have an account on a site that could be compromised by Heartbleed, you have to decide on a course of action. The common wisdom is to immediately change your password, but this advice ignores one crucial fact: there’s no point changing passwords if the site hasn’t been fixed.

Heartbleed, as discussed earlier, isn’t a simple database leak, so simply changing your passwords won’t help if the problem hasn’t been fixed by the site. Some websites and services, such as Google, will have made this clear, but there will definitely be websites that don’t explicitly state whether they’ve rectified the issue on their end.

GitHub List

What you can do now is to use either of the two tools listed above, or check the site to at the GitHub or Mashable lists to see if the service is still vulnerable.

Note that the two tools and the GitHub list don’t differentiate between services that were never vulnerable and services that have been fixed. It’s probably safer that you change your passwords if the site reports as not vulnerable.

Simply taking a break from affected services might help too, since Heartbleed only exposes data that’s in a server’s RAM.

Password Security

While Heartbleed goes beyond just an issue with password security, it’s still a good time to remind ourselves of some of the best ways to ensure the security of online accounts. Yes, there’s more to password security than just changing your password every few months.

While two-factor authentication may not necessarily protect you from Heartbleed, it’s still a great security measure that you should definitely take advantage of on any services that support it.

Two-Factor Authentification

If you’re unfamiliar, two-factor authentification is a way of verifying the identity of a user based on two steps instead of one. In other words, instead of just asking for a username and password, two-factor authentification also requires you to key in a verification code or use a smartphone app to further verify your identity.

Another security measure you should probably take is to use tools to generate and manage passwords for you. The major benefit of these tools is the fact that they will create randomized passwords and manage them for you; no more having to memorize a ton of different passwords or, even worse, use the same password on multiple websites.

Password Generator

Conclusion

Heartbleed is a serious security issue that affects almost everyone on the Internet, and there isn’t much that any of us can do about it. Beyond checking the services we use and changing our passwords if they’ve fixed the flaw, or taking a break and remaining vigilant if they haven’t, it’s really all in the hands of the server administrators. If anything, Heartbleed serves as a reminder that we can never take the security of our personal data for granted.



View the Original article

Selasa, 15 April 2014

What Bitcoin Users Need To Know About Heartbleed

If you’re using a bitcoin wallet or an online wallet or exchange, Heartbleed could be a very real problem for you and your BTC. Luckily, things have finally settled down after a few days of panic and there are a few very easy ways to ensure you’re protected.

First, understand that the core bitcoin protocol, which transfers bitcoin through the system, is unaffected. “Whilst the Bitcoin Core client will be updated to 0.9.1 to address the OpenSSL vulnerability, the core developers stress that the Bitcoin protocol itself is not affected by the Heartbleed bug,” wrote Venzen Khaosan on CryptocoinsNews.

That didn’t stop many exchanges from taking down some of their services just to be safe. Yesterday Bitstamp shut down “accregistration, login & all virtual currency withdrawal functions,” as it investigated the effect of Heartbleed on its servers. Anti-DDOS service Incapsula also had to update its servers to remain secure. Bitstamp has since restarted all functionality. The OpenSSL exploit essentially allows a dedicated hacker to methodically collect email addresses, keys, and log-ins from affected servers.

Other services, including Bitcurex and Blockchain.info are reported that they’ve patched and updated their services.

What about folks with wallets on their own machines? A bit of updating is in order. A new version of the Bitcoin Core, 0.9.1, just dropped, and it features improved security for wallets. Users should have openssl 1.0.1g or later. You can see your openssl version in the Help->Debug window in Bitcoin-Qt. Other wallets like Multibit have not updated (although they may not need to) but care should be taken to encrypt and password-protect your coins.

Screen Shot 2014-04-09 at 10.35.19 AM

In short, update everything that touches your bitcoin and don’t trust exchanges that haven’t explicitly explained their position on the exploit. Want more bad news? You should assume that all your usernames and passwords used over the past two years are compromised. This means you should change everything, not just your bitcoin data. A clever hacker could socially engineer her way into your wallet simply by knowing a few things about your online habits.

“I’m hoping the impact will be limited. Major sites will have to rotate their SSL keys after upgrading [...] Most sites should have the private keys for their wallets in a different server process where the data cannot be extracted this way. However it will not surprise me if a few sites are not working this way for whatever reason and might suffer thefts,” wrote Mike Hearn of the Bitcoin Foundation. All is not lost, but all is not great, either.

Heartbleed, The First Security Bug With A Cool Logo

Next Story

Booktrack Raises $3M To Add Soundtracks To E-Books, Launches Classroom Version

It’s been fascinating to watch news of heartbleed, the massive OpenSSL exploit, spread on the web. After years of quietly putting us at risk, the general web user became aware of the exploit only a few days ago, and probably via heartbleed.com.

Screen Shot 2014-04-09 at 9.59.25 AM

The site, which appeared almost overnight, was full of interesting info on the exploit, had a handsome minimalist design and included a nice logo. Someone had taken a bit of time to build an attractive and usable site.

But I was curious: how did heartbleed.com happen? When major exploits appear they are usually proliferated through wonky pages on security researcher sites. These “old-fashioned” exploit pages included a brief description, some references, and mention of the researchers involved. No images, just text.

But this exploit now had its own logo, its own website, and had taken on a life of its own. In short, Heartbleed was one of the first “branded” exploits, a computer bug that has been professionally packaged for easy mass consumption.

Not everyone was happy about this. One Twitter user writes:

While it’s fun to think that someone is profiting from exposing this exploit, the facts are much more mundane. With a bit of not particularly difficult sleuthing, I found the registrar listing for the site. It belonged to a company in Finland, Codenomicon who registered it a mere four days ago, a day or so after the exploit became “popular.”

Screen Shot 2014-04-08 at 2.35.22 PM

The company was happy to answer questions about the site and stated emphatically that they were just trying to help the community.

“The content started as an internal Q&A which we wrote when trying to understand this bug and its impact,” said Miia Vuontisjärvi of Codenomicon. “Within hours of discovery we contacted NCSC-FI to handle the vulnerability coordination. When we tried the attack against ourselves and saw the disclosure of secret keys we understood that the Internet community has a new kind of vulnerability remediation challenge to solve.”

“Experiencing the pain of the bug first hand we got a nagging feeling that this calls for a ‘Bugs 2.0′ approach in getting the message out in an emergency. Ossi, one of our experts came up with Heartbleed as an internal codeame and from there on thing lead to the other. The domain was available and our artist Leena Snidate did a an excellent job in putting our pain into the logo. It all went much faster than expected.

“When the vulnerability became public we realized that this is going to be a crisis communication. We said what we had to say in the Q&A with as little litter as possible. We put it available on a low latency and high bandwidth content delivery network so that it is very accessible for anyone in the need. Based on initial reactions we did some minor edits but we quickly saw the Internet community picked the issue up in an astonishing way.”

The idea of a branded exploit – one that is carefully curated for easy consumption – is a new one. Historically obfuscation, either real or inadvertent, has been the watchword in computer security mostly because not everyone cared about major exploits. Heartbleed, in a way, was different. It was worldwide, very dangerous, and oddly photogenic. Whereas a Java exploit or Adobe Reader problem is “invisible” to the average user, the idea of a hacker watching your passwords scroll, Matrix-like without security systems setting off alarm bells is compelling and frightening. By creating a “bugs 2.0″ page for the exploit, Codenomicon inadvertently allowed the average user to understand and potentially react to the problem.

Screen Shot 2014-04-08 at 11.20.19 AM

It worked.

“It is amazing to see such a community reaction to address this: internet wide scans, detection tools, pressure on passive service providers, top-notch reactions from progressive service providers (including re-keying and password changes), users advising each other and useful analysis by the media worldwide,” said Vuontisjärvi. “All this is making security more democratic, this issue was too big for the security community to handle alone. Seeing almost one tweet per second at its peak on normal users reacting to this has been reassuring and is restoring our trust into the Internet.”