Calgarypuck Forums - The Unofficial Calgary Flames Fan Community

Go Back   Calgarypuck Forums - The Unofficial Calgary Flames Fan Community > Main Forums > The Off Topic Forum > Tech Talk
Register Forum Rules FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Search this Thread
Old 04-11-2014, 10:31 AM   #21
Bobblehead
Franchise Player
 
Bobblehead's Avatar
 
Join Date: Jul 2005
Location: in your blind spot.
Exp:
Default

Cloudflare has now come out saying that after extensive testing they haven't been able to uncover a servers keys, so it is either super difficult or impossible. That is because, like the comic above showed, the key would need to be included in the 64K of data returned, and that 64K comes from memory buffers, so it would only happen if the key happened to be in the buffer when the fraudulent request was made. So it may not be as bad as initially feared (but tests are ongoing).
http://www.theverge.com/2014/4/11/56...keys-after-all

As for how was the news of the bug initially released, that is a pretty big story on its own.
http://www.theverge.com/2014/4/10/56...-web-in-secret
__________________
"The problem with any ideology is that it gives the answer before you look at the evidence."
—Bill Clinton
"The greatest obstacle to discovery is not ignorance--it is the illusion of knowledge."
—Daniel J. Boorstin, historian, former Librarian of Congress
"But the Senator, while insisting he was not intoxicated, could not explain his nudity"
—WKRP in Cincinatti
Bobblehead is offline   Reply With Quote
The Following User Says Thank You to Bobblehead For This Useful Post:
Old 04-12-2014, 10:17 PM   #22
Bobblehead
Franchise Player
 
Bobblehead's Avatar
 
Join Date: Jul 2005
Location: in your blind spot.
Exp:
Default

Cloudflare has said 4 people have successfully extracted the private key, so sites absolutely need to update their keys after patching.

http://arstechnica.com/security/2014...ew-data-shows/
__________________
"The problem with any ideology is that it gives the answer before you look at the evidence."
—Bill Clinton
"The greatest obstacle to discovery is not ignorance--it is the illusion of knowledge."
—Daniel J. Boorstin, historian, former Librarian of Congress
"But the Senator, while insisting he was not intoxicated, could not explain his nudity"
—WKRP in Cincinatti
Bobblehead is offline   Reply With Quote
Old 04-14-2014, 01:10 PM   #23
Inglewood Jack
#1 Goaltender
 
Inglewood Jack's Avatar
 
Join Date: Jan 2012
Exp:
Default

well here we are, first confirmed Heartbleed theft that I've seen. I'm actually surprised they caught it.

http://www.theglobeandmail.com/techn...ticle17956353/

Quote:
About 900 social insurance numbers were stolen from the computers of the Canada Revenue Agency, the revenue department has confirmed, following a shutdown of its public online services caused by the Heartbleed Internet bug.

“Based on our analysis to date, Social Insurance Numbers (SIN) of approximately 900 taxpayers were removed from CRA systems by someone exploiting the Heartbleed vulnerability,” the CRA communiqué said. “We are currently going through the painstaking process of analyzing other fragments of data, some that may relate to businesses, that were also removed.”
tax filings have some of the most confidential information on you that is available, so if this happened to me I'd be pretty freaked. credit cards are one thing, but stuff like SIN and income are a whole new ballgame.
Inglewood Jack is online now   Reply With Quote
Old 04-14-2014, 01:51 PM   #24
GoinAllTheWay
Franchise Player
 
GoinAllTheWay's Avatar
 
Join Date: Apr 2003
Location: Not sure
Exp:
Default

/\/\

Yep, that's pretty freaky stuff right there. I heard they would be sending registered mail to the people they think are affected. No phone calls or email, 100% registered mail.

Bound to be a number of phishing scams pop up over this.
GoinAllTheWay is offline   Reply With Quote
Old 04-14-2014, 02:24 PM   #25
Rathji
Franchise Player
 
Rathji's Avatar
 
Join Date: Nov 2006
Location: Supporting Urban Sprawl
Exp:
Default

Quote:
Originally Posted by Inglewood Jack View Post
well here we are, first confirmed Heartbleed theft that I've seen. I'm actually surprised they caught it.

http://www.theglobeandmail.com/techn...ticle17956353/



tax filings have some of the most confidential information on you that is available, so if this happened to me I'd be pretty freaked. credit cards are one thing, but stuff like SIN and income are a whole new ballgame.
So the question is, if you can't figure out if you have been impacted by Heartbleed, how do they know that these SIN were compromised because of Heartbleed?

Sounds a little fishy to me.
__________________
"Wake up, Luigi! The only time plumbers sleep on the job is when we're working by the hour."
Rathji is offline   Reply With Quote
Old 04-14-2014, 02:35 PM   #26
Bobblehead
Franchise Player
 
Bobblehead's Avatar
 
Join Date: Jul 2005
Location: in your blind spot.
Exp:
Default

Quote:
Originally Posted by Rathji View Post
So the question is, if you can't figure out if you have been impacted by Heartbleed, how do they know that these SIN were compromised because of Heartbleed?

Sounds a little fishy to me.
Actually, there have been methods to retroactively determine if there was an exploit attempted. Not perfect but not impossible either.

http://www.riverbed.com/blogs/Retroa...xpression.html
__________________
"The problem with any ideology is that it gives the answer before you look at the evidence."
—Bill Clinton
"The greatest obstacle to discovery is not ignorance--it is the illusion of knowledge."
—Daniel J. Boorstin, historian, former Librarian of Congress
"But the Senator, while insisting he was not intoxicated, could not explain his nudity"
—WKRP in Cincinatti
Bobblehead is offline   Reply With Quote
Old 04-14-2014, 02:36 PM   #27
ZedMan
Scoring Winger
 
Join Date: Apr 2008
Exp:
Default

You can't figure it out just from, say, web server logs, but if you were capturing every packet entering/leaving your network, you would be able to identify it. Most IPS/IDS vendors had signatures that could detect heartbleed out within days.
ZedMan is online now   Reply With Quote
The Following User Says Thank You to ZedMan For This Useful Post:
Old 04-14-2014, 02:43 PM   #28
DownhillGoat
Franchise Player
 
DownhillGoat's Avatar
 
Join Date: Jan 2010
Exp:
Default

Quote:
Originally Posted by Inglewood Jack View Post
tax filings have some of the most confidential information on you that is available, so if this happened to me I'd be pretty freaked.
Meh, student loans already gave away my info.
DownhillGoat is offline   Reply With Quote
Old 04-14-2014, 03:28 PM   #29
dissentowner
Franchise Player
 
dissentowner's Avatar
 
Join Date: Jul 2005
Location: SW Ontario
Exp:
Default

Quote:
Originally Posted by photon View Post
It's pretty significant for sure, everyone I know is more in get it patched mode rather than trying to assess if anything was actually compromised.

Not that we use SSL, but CP's software is too old and doesn't have the vulnerability to begin with
Didn't CP get hacked bad way back in the day? I thought I remember something like that...
dissentowner is offline   Reply With Quote
Old 04-14-2014, 05:39 PM   #30
photon
The new goggles also do nothing.
 
photon's Avatar
 
Join Date: Oct 2001
Location: Calgary
Exp:
Default

Quote:
Originally Posted by dissentowner View Post
Didn't CP get hacked bad way back in the day? I thought I remember something like that...
Yeah it got hacked one time, someone managed to do some kind of exploit to reset the Admin password. Fortunately they didn't do a huge amount of damage.
__________________
Uncertainty is an uncomfortable position.
But certainty is an absurd one.
photon is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -6. The time now is 06:35 PM.

Calgary Flames
2023-24




Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright Calgarypuck 2021