# Heartbleed: a serious security bug.  What should I be doing?

**URL:** <https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668>\
**Category:** In My Humble Opinion\
**Created:** [April 8, 2014, 8:23pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668 "2014-04-08T20:23:15Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Leaper](https://avatars.discourse-cdn.com/v4/letter/l/4bbf92/32.png) [@Leaper](https://boards.straightdope.com/u/Leaper)\
**Post date:** [April 8, 2014, 8:23pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/1 "2014-04-08T20:23:15Z")

</div>

Google the name “Heartbleed.” To sum up, it’s a security bug in OpenSSL that allows all kins of shenanigans, including the harvesting of names/passwords and the impersonation of sites.

What exactly can and should I do? I have dozens upon dozens of passwords all across the Internet. How do I know when I should change them, if at all?

---

<div class="post-metadata">

**Author:** ![Ferret\_Herder](https://avatars.discourse-cdn.com/v4/letter/f/e47774/32.png) [@Ferret\_Herder](https://boards.straightdope.com/u/Ferret_Herder)\
**Post date:** [April 8, 2014, 8:59pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/2 "2014-04-08T20:59:10Z")

</div>

Lifehacker has a good article on the subject. I’m on mobile so it’s hard to link right now.

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [April 8, 2014, 9:11pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/3 "2014-04-08T21:11:15Z")

</div>

> [@Ferret\_Herder](#):
>
> Lifehacker has a good article on the subject. I’m on mobile so it’s hard to link right now.

[Here](http://lifehacker.com/what-the-heartbleed-security-bug-means-for-you-1560801201) you go.

---

<div class="post-metadata">

**Author:** ![Claverhouse](https://avatars.discourse-cdn.com/v4/letter/c/13edae/32.png) [@Claverhouse](https://boards.straightdope.com/u/Claverhouse)\
**Post date:** [April 8, 2014, 9:18pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/4 "2014-04-08T21:18:31Z")

</div>

Stack Exchange almost **[addresses](http://security.stackexchange.com/questions/55076/what-should-a-website-operator-do-about-the-heartbleed-openssl-exploit)** this, but not particularly usefully right now.

I don’t think there’s anything anyone not a server admin can, or has to, do. Those can patch etc., and keep their fingers crossed their machines weren’t compromised. But even if I thought there was anything to panic about, it seems to have been open for 2 years without much happening. If CloudFlare hadn’t announced it early the patches would be soon ready and it would be merely of historical interest such as the bugs of yesteryear.

---

<div class="post-metadata">

**Author:** ![Leaper](https://avatars.discourse-cdn.com/v4/letter/l/4bbf92/32.png) [@Leaper](https://boards.straightdope.com/u/Leaper)\
**Post date:** [April 8, 2014, 9:22pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/5 "2014-04-08T21:22:51Z")

</div>

> [@Ferret\_Herder](#):
>
> Lifehacker has a good article on the subject. I’m on mobile so it’s hard to link right now.

I read the article. So what am I supposed to assume — that if a site doesn’t tell me, I don’t necessarily need to change the password (same with “not connecting with vulnerable sites” — I see the link to the tool, but it says it doesn’t say anything about past vulnerability, and trying it just tells me it can’t connect to the site)? Like I said, I have at least 40 passwords all over the Internet (mostly for job sites). Changing them all is an all-night thing.

---

<div class="post-metadata">

**Author:** ![DrCube](https://avatars.discourse-cdn.com/v4/letter/d/a3d4f5/32.png) [@DrCube](https://boards.straightdope.com/u/DrCube)\
**Post date:** [April 8, 2014, 10:17pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/6 "2014-04-08T22:17:40Z")

</div>

Keep your OS up to date and cross your fingers that your bank will too. I imagine Windows and most Linux distros will release OpenSSL updates soon. Servers don’t usually get updated as often for stability reasons, so if you’re really worried, you can pester Amazon and other websites who have your CC info to patch their software. Though if they _really_ don’t update their software that often, they might still be on an older version of OpenSSL that doesn’t have the bug.

---

<div class="post-metadata">

**Author:** ![Pedro](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@Pedro](https://boards.straightdope.com/u/Pedro)\
**Post date:** [April 8, 2014, 10:39pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/7 "2014-04-08T22:39:51Z")

</div>

> [@Leaper](#):
>
> I read the article. So what am I supposed to assume — that if a site doesn’t tell me, I don’t necessarily need to change the password (same with “not connecting with vulnerable sites” — I see the link to the tool, but it says it doesn’t say anything about past vulnerability, and trying it just tells me it can’t connect to the site)? Like I said, I have at least 40 passwords all over the Internet (mostly for job sites). Changing them all is an all-night thing.

The bug can give a would be attacker access to pieces of RAM content from any machine using a buggy OpenSSL version (and there are many). So for the truly paranoid anything that touched random memory is compromised. For the more reasonably cautious, it would be enough to change only some high value passwords. There are no known exploits in the wild.

What you should do is update OpenSSL to a non buggy version, and anything that links statically with it. And hope the servers you use do the same.

---

<div class="post-metadata">

**Author:** ![Baron\_Greenback](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/baron_greenback/32/48_2.png) [@Baron\_Greenback](https://boards.straightdope.com/u/Baron_Greenback)\
**Post date:** [April 8, 2014, 10:42pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/8 "2014-04-08T22:42:49Z")

</div>

> [@Leaper](#):
>
> I read the article. So what am I supposed to assume — that if a site doesn’t tell me, I don’t necessarily need to change the password (same with “not connecting with vulnerable sites” — I see the link to the tool, but it says it doesn’t say anything about past vulnerability, and trying it just tells me it can’t connect to the site)? Like I said, I have at least 40 passwords all over the Internet (mostly for job sites). Changing them all is an all-night thing.

The LastPass Heartbleed tool [https://lastpass.com/heartbleed/](https://lastpass.com/heartbleed/) detects when the SSL certificate on any given site was reissued. Anyone who has done it very recently was probably vulnerable, and you can safely change the password. There’s no point changing it on any site that still shows are vulnerable.

[Yahoo.com](http://Yahoo.com) was still showing as vulnerable 5 hours ago, and I note that [boards.straightdope.com](http://boards.straightdope.com) reissued at Apr 8 18:22:02 2014 GMT

---

<div class="post-metadata">

**Author:** ![Claverhouse](https://avatars.discourse-cdn.com/v4/letter/c/13edae/32.png) [@Claverhouse](https://boards.straightdope.com/u/Claverhouse)\
**Post date:** [April 9, 2014, 6:13am UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/9 "2014-04-09T06:13:34Z")

</div>

> [@DrCube](#):
>
> Keep your OS up to date and cross your fingers that your bank will too. I imagine Windows and most Linux distros will release OpenSSL updates soon.

Indeed. Eight hours later, and no doubt earlier if I hadn’t just woken up, OpenSuse Yast has _OpenSSL_ update, and a related _gnutls_ update.

---

<div class="post-metadata">

**Author:** ![Little\_Pig](https://avatars.discourse-cdn.com/v4/letter/l/c57346/32.png) [@Little\_Pig](https://boards.straightdope.com/u/Little_Pig)\
**Post date:** [April 9, 2014, 7:47am UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/10 "2014-04-09T07:47:30Z")

</div>

If it of value to you then change the password.

---

<div class="post-metadata">

**Author:** ![DrCube](https://avatars.discourse-cdn.com/v4/letter/d/a3d4f5/32.png) [@DrCube](https://boards.straightdope.com/u/DrCube)\
**Post date:** [April 9, 2014, 2:17pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/11 "2014-04-09T14:17:24Z")

</div>

What about phone OSes? I have a Nexus phone that I keep up to date with CyanogenMod, so I’m not too worried. But I imagine most people have older phones with carrier installed OSes that they either can’t or won’t update.

Is there a list of OS versions affected? And do all those people need to avoid HTTPS sites entirely until they get a new phone?

---

<div class="post-metadata">

**Author:** ![Bricker](https://avatars.discourse-cdn.com/v4/letter/b/977dab/32.png) [@Bricker](https://boards.straightdope.com/u/Bricker)\
**Post date:** [April 9, 2014, 2:36pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/12 "2014-04-09T14:36:31Z")

</div>

1. Update any server you run that has openssl to a non-vulnerable version.
2. If no update is available, recompile openssl with the -DOPENSSL\_NO\_HEARTBEATS flag.
3. Revoke any certificates you had on those servers, regenerate the private keys, re-create the CSRs, and get new certificates.

---

<div class="post-metadata">

**Author:** ![Bricker](https://avatars.discourse-cdn.com/v4/letter/b/977dab/32.png) [@Bricker](https://boards.straightdope.com/u/Bricker)\
**Post date:** [April 9, 2014, 2:41pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/13 "2014-04-09T14:41:00Z")

</div>

> [@Claverhouse](#):
>
> Indeed. Eight hours later, and no doubt earlier if I hadn’t just woken up, OpenSuse Yast has _OpenSSL_ update, and a related _gnutls_ update.

No Fedora yum update yet. My Fedora box has 1.0.1e.

---

<div class="post-metadata">

**Author:** ![Baron\_Greenback](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/baron_greenback/32/48_2.png) [@Baron\_Greenback](https://boards.straightdope.com/u/Baron_Greenback)\
**Post date:** [April 9, 2014, 2:43pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/14 "2014-04-09T14:43:01Z")

</div>

Hmm, perhaps not

---

<div class="post-metadata">

**Author:** ![filmore](https://avatars.discourse-cdn.com/v4/letter/f/7993a0/32.png) [@filmore](https://boards.straightdope.com/u/filmore)\
**Post date:** [April 9, 2014, 2:54pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/15 "2014-04-09T14:54:52Z")

</div>

> [@Pedro](#):
>
> The bug can give a would be attacker access to pieces of RAM content from any machine using a buggy OpenSSL version (and there are many).

I’m having trouble understanding how this could be part of the bug. Does anyone know the details? Does a client say ‘give me data between addresses X and Y’?

---

<div class="post-metadata">

**Author:** ![Baron\_Greenback](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/baron_greenback/32/48_2.png) [@Baron\_Greenback](https://boards.straightdope.com/u/Baron_Greenback)\
**Post date:** [April 9, 2014, 3:08pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/16 "2014-04-09T15:08:21Z")

</div>

> [@filmore](#):
>
> I’m having trouble understanding how this could be part of the bug. Does anyone know the details? Does a client say ‘give me data between addresses X and Y’?

The exploit uses the heartbeat function - basically checking that the server is still there to keep the connection. Normally the client just gets back a few bytes “Hi, I’m here!”, but a malicious client can exploit a vulnerability (due to a missed check) where effectively an additional (almost) 64kB of whatever is nearby in memory is returned.  
The gory details are here: [http://blog.existentialize.com/diagnosis-of-the-openssl-heartbleed-bug.html](http://blog.existentialize.com/diagnosis-of-the-openssl-heartbleed-bug.html)

---

<div class="post-metadata">

**Author:** ![Rysto](https://avatars.discourse-cdn.com/v4/letter/r/ecccb3/32.png) [@Rysto](https://boards.straightdope.com/u/Rysto)\
**Post date:** [April 9, 2014, 3:16pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/17 "2014-04-09T15:16:45Z")

</div>

> [@filmore](#):
>
> I’m having trouble understanding how this could be part of the bug. Does anyone know the details? Does a client say ‘give me data between addresses X and Y’?

As I understand it, the bug is that you can ask the server (or client) to send you X bytes of data in a message, but trick it into allocating a message that is much smaller than that. This means that you get whatever happens to be in memory right after your message.

The really nasty thing is that you can repeat this indefinitely and get a different piece of memory each time, so statistically your chances of getting something really important are extremely high given enough attempts.

---

<div class="post-metadata">

**Author:** ![Bricker](https://avatars.discourse-cdn.com/v4/letter/b/977dab/32.png) [@Bricker](https://boards.straightdope.com/u/Bricker)\
**Post date:** [April 9, 2014, 3:22pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/18 "2014-04-09T15:22:03Z")

</div>

> [@Rysto](#):
>
> The really nasty thing is that you can repeat this indefinitely and get a different piece of memory each time, so statistically your chances of getting something really important are extremely high given enough attempts.

This.

It’s very very unlikely you’ll capture a private key.

In one random attempt.

But throw enough darts at the dartboard, and eventually one will stick in the bullseye.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [April 9, 2014, 3:22pm UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/19 "2014-04-09T15:22:15Z")

</div>

I’d like to hear more about this “effectively random” block of memory. If an attacker exploited this twice in a row on the same server, would they get back the same block of memory both times? If so, then it’s a very minor problem, since you’d only get something like a millionth of the total memory content, and any given piece of sensitive information would be very unlikely to be in that block. On the other hand, if it’s a different “random” block each time, or worse, systematically proceeds through all of the memory in the target machine, then an attacker can get a much larger amount of information.

EDIT: Never mind, **Rysto** ninjaed me.

---

<div class="post-metadata">

**Author:** ![Hari\_Seldon](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/hari_seldon/32/5173_2.png) [@Hari\_Seldon](https://boards.straightdope.com/u/Hari_Seldon)\
**Post date:** [April 10, 2014, 12:25am UTC](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668/20 "2014-04-10T00:25:31Z")

</div>

Our computer centre just sent around a notice that they would be repairing the bug and let us know when it is done and then we should change our passwords, but there was no point in changing it until the fix was finished.

[Next page](https://boards.straightdope.com/t/heartbleed-a-serious-security-bug-what-should-i-be-doing/685668.md?page=2)
