Heartbleed Security Vulnerability

Heartbleed Security Vulnerability: What It Is And How To Protect Yourself

The Heartbleed Security Vulnerability means that people all across the web are at risk of having their sensitive data stolen. Heartbleed is an extremely serious issue affecting some 500,000 servers, according to Netcraft, an Internet research firm. Here’s what consumers can do to protect themselves.

The Heartbleed Security Vulnerability

On Monday, April 7, security researchers announced a security flaw in OpenSSL, a popular data encryption standard. The flaw gives hackers who know about it the ability to extract massive amounts of data from services we use every day and assume are secure.

In fact, this isn’t simply a bug in some app you can quickly update. The weakness is in the machines that power services that transmit secure information, such as Gmail and Facebook.

Heartbleed is a flaw in OpenSSL, the open-source encryption standard most websites use to transmit the data users want to keep secure. It basically gives you a secure line when you’re sending an email or chatting on IM.

What You Should Do to Protect Yourself

First, update your packages and restart your services on your server. Here’s how to do it on CentOS and Ubuntu:

CentOS:
su to root
# su –
update the package and restart the service
# yum update openssl
# service httpd restart or service nginx restart
Ubuntu:
Use sudo to upgrade
# sudo apt-get update
update the package and restart the service
# sudo apt-get upgrade openssl
# sudo service apache2 restart or sudo service nginx restart

Change passwords of sensitive accounts like banks and email first. Make sure your password is long enough, randomized, and not reused across multiple accounts. Avoid passwords like “abc1234,” “password,” or “admin,” etc.

Attackers can access a server’s memory for credit card information, therefore keep a close eye on your financial statements for the next few days. It wouldn’t hurt to be on the lookout for unfamiliar charges on your bank statements.

Even if you’ve implemented two-factor authentication (which, in addition to a password, asks for another piece of identifying information, like a code texted to you), we recommend changing that password.

Finally, do not log into accounts from affected sites until you’re sure the company has solved the problem.

Share this blog

About cookies on Volico.com

Volico Data Centers use cookies to collect and analyse information on site performance and usage. This site uses essential cookies which are required for functionality.  More detail is available in our privacy policy. Learn more