# "Heartbleed" Password Hack

**URL:** <https://boards.straightdope.com/t/heartbleed-password-hack/685762>\
**Category:** About This Message Board\
**Created:** [April 9, 2014, 10:50pm UTC](https://boards.straightdope.com/t/heartbleed-password-hack/685762 "2014-04-09T22:50:17Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cartooniverse](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cartooniverse/32/3084_2.png) [@Cartooniverse](https://boards.straightdope.com/u/Cartooniverse)\
**Post date:** [April 9, 2014, 10:50pm UTC](https://boards.straightdope.com/t/heartbleed-password-hack/685762/1 "2014-04-09T22:50:17Z")

</div>

Please let us know by Stickies at the top of every Forum when it is time for us all to change our Password here on the Dope.

I’m wondering how the powers that be at the Dope will know if the [Heartbleed hack](http://www.latimes.com/business/technology/la-fi-tn-tumblr-change-passwords-heartbleed-https-20140408,0,4912342.story?track=rss&utm_source=dlvr.it&utm_medium=twitter&dlvrit=515009#axzz2yKOoK6WM) is a problem.

---

<div class="post-metadata">

**Author:** ![Canadjun](https://avatars.discourse-cdn.com/v4/letter/c/76d3ee/32.png) [@Canadjun](https://boards.straightdope.com/u/Canadjun)\
**Post date:** [April 9, 2014, 11:53pm UTC](https://boards.straightdope.com/t/heartbleed-password-hack/685762/2 "2014-04-09T23:53:40Z")

</div>

> [@Cartooniverse](#):
>
> Please let us know by Stickies at the top of every Forum when it is time for us all to change our Password here on the Dope.
> 
> I’m wondering how the powers that be at the Dope will know if the [Heartbleed hack](http://www.latimes.com/business/technology/la-fi-tn-tumblr-change-passwords-heartbleed-https-20140408,0,4912342.story?track=rss&utm_source=dlvr.it&utm_medium=twitter&dlvrit=515009#axzz2yKOoK6WM) is a problem.

Doesn’t look like SDMB uses SSL (no password icon, no HTTPS: in the address), so my guess is that there is nothing to fix.

---

<div class="post-metadata">

**Author:** ![Canadjun](https://avatars.discourse-cdn.com/v4/letter/c/76d3ee/32.png) [@Canadjun](https://boards.straightdope.com/u/Canadjun)\
**Post date:** [April 10, 2014, 12:00am UTC](https://boards.straightdope.com/t/heartbleed-password-hack/685762/3 "2014-04-10T00:00:36Z")

</div>

ETA a late: No [del]password[/del] lock icon

---

<div class="post-metadata">

**Author:** ![Cartooniverse](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cartooniverse/32/3084_2.png) [@Cartooniverse](https://boards.straightdope.com/u/Cartooniverse)\
**Post date:** [April 10, 2014, 12:31am UTC](https://boards.straightdope.com/t/heartbleed-password-hack/685762/4 "2014-04-10T00:31:25Z")

</div>

Ignorance fought.

Thank you very much.

---

<div class="post-metadata">

**Author:** ![Bricker](https://avatars.discourse-cdn.com/v4/letter/b/977dab/32.png) [@Bricker](https://boards.straightdope.com/u/Bricker)\
**Post date:** [April 10, 2014, 1:51am UTC](https://boards.straightdope.com/t/heartbleed-password-hack/685762/5 "2014-04-10T01:51:15Z")

</div>

Of course, the failure to use SSL when credentials are passed means that your SDMB username and password is theoretically vulnerable to a man-in-the-middle interception.

But that has nothing to do with Heartbleed.

---

<div class="post-metadata">

**Author:** ![Canadjun](https://avatars.discourse-cdn.com/v4/letter/c/76d3ee/32.png) [@Canadjun](https://boards.straightdope.com/u/Canadjun)\
**Post date:** [April 10, 2014, 2:21pm UTC](https://boards.straightdope.com/t/heartbleed-password-hack/685762/6 "2014-04-10T14:21:56Z")

</div>

> [@Bricker](#):
>
> Of course, the failure to use SSL when credentials are passed means that your SDMB username and password is theoretically vulnerable to a man-in-the-middle interception.
> 
> But that has nothing to do with Heartbleed.

Or, to put it slightly differently, do not **ever** make your SDMB password the same as the password to any system you care about (e.g. banking, on-line ordering, e-mail, etc.) The same applies to any other non-HTTPS system. You really shouldn’t duplicate passwords on any important systems, but it becomes even more critically important in this case.

---

<div class="post-metadata">

**Author:** ![Measure\_for\_Measure](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/measure_for_measure/32/557_2.png) [@Measure\_for\_Measure](https://boards.straightdope.com/u/Measure_for_Measure)\
**Post date:** [April 10, 2014, 7:47pm UTC](https://boards.straightdope.com/t/heartbleed-password-hack/685762/7 "2014-04-10T19:47:33Z")

</div>

1. For those more interested in heartbleed than in the SDMB, this is the most concise article on the subject I’ve come across so far. It’s 3 paragraphs at engadget. [How to avoid heartburn, er, Heartbleed](http://www.engadget.com/2014/04/09/how-to-avoid-heartbleed/).
2. With all the password attacks and necessity for strong and periodically changed passwords, a password manager is the only way to go, eggs in baskets notwithstanding. IMHO. I use KeePass.
3. There are lots of longer and interesting articles on heartbleed. Here is one.  
[http://www.newyorker.com/online/blogs/elements/2014/04/the-internets-telltale-heartbleed.html](http://www.newyorker.com/online/blogs/elements/2014/04/the-internets-telltale-heartbleed.html)

Krebs is a daily blogger covering security and cybercrime. James Fallows is a trustworthy journalist who also covers intermediate computing.

> **[Krebs on Security – In-depth security news and investigation](https://krebsonsecurity.com/)**
>
> In-depth security news and investigation

> **[James Fallows](https://www.theatlantic.com/author/james-fallows/)**
>
> The Atlantic covers news, politics, culture, technology, health, and more, through its articles, podcasts, videos, and flagship magazine.

Longer primer:

> **[Heartbleed Bug: What Can You Do? – Krebs on Security](https://krebsonsecurity.com/2014/04/heartbleed-bug-what-can-you-do/#more-25638)**
>
> In the wake of widespread media coverage of the Internet security debacle known as the Heartbleed bug, many readers are understandably anxious to know what they can do to protect themselves. Here's a short primer.

1. Relative to heartbleed the security problems at the SDMB are miniscule. Brrrrrr.

---

<div class="post-metadata">

**Author:** ![Kyrie\_Eleison](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/kyrie_eleison/32/7682_2.png) [@Kyrie\_Eleison](https://boards.straightdope.com/u/Kyrie_Eleison)\
**Post date:** [April 12, 2014, 4:33am UTC](https://boards.straightdope.com/t/heartbleed-password-hack/685762/8 "2014-04-12T04:33:07Z")

</div>

> [@Measure\_for\_Measure](#):
>
> 1. Relative to heartbleed the security problems at the SDMB are miniscule. Brrrrrr.

I wouldn’t go that far; that’s kind of true, but also kind of misleading. The security claims at the SDMB basically boil down to, “We’re not that secure, but no one really gives a damn. Possibly contrary to your expectations, the hackers of the world are not all that interested in cracking your SDMB login. We’re safe enough for any informed and reasonable person.” And that’s all true. Just don’t use the same password and username here and somewhere else.

I should point out that I’m talking about the regular message board operations, and have nothing to say about the credit card payment operations. (Sorry SDMB operators,) I’ve never looked at the payment part of the boards.

The heartbleed problem is different. These sites said, “We’re secure. We’re very secure. Trust us, no one can see your private information.” They were wrong, albeit somewhat indirectly so, in that no one could target you specifically, but they could still gather supposedly private information from the sites affected.

Basically, security on the SDMB doesn’t rise _high_ enough to be compromised by heartbleed until this link works: [https://boards.straightdope.com](https://boards.straightdope.com)
