OpenSSL Heartbleed Exploit: This is just the tip of the iceberg.
Most of you are probably already aware that there has been a major internet security breach that has the potential to affect millions and millions of people. This security exploit, which has been coined “Heartbleed” by a Finnish Security group called Codenomicon and was first publicly revealed on April 7th, 2014, affects websites that use an SSL certificate to secure customer information. In a nutshell this SSL certificate is what helps encrypt and make secure your connection to various websites like financial institutions or when you are logging into your Facebook or Gmail account. When you see an “https://” at the start of the URL in your web browser you are browsing over an SSL connection. This exploit doesn’t affect ALL SSL connections but it does affect a significant number. Despite the underwhelming lack of guidance coming from major financial websites, going forward most companies will be able to fix this problem very quickly. Less reassuring is the fact that this exploit has existed for 2 years and the real unknown is in how much customer information has already been leaked and/or compromised. You can find more details about the vulnerability all across the internet today. Here’s an article in The New York Times about it and a lot of information is being aggregated on the Heartbleed website which is being run by Codenomicon.
David Chartier, chief executive at Codenomicon was quoted in the New York Times article as saying, “It’s a serious bug in that it doesn’t leave any trace. Bad guys can access the memory on a machine and take encryption keys, usernames, passwords, valuable intellectual property, and there’s no trace they’ve been there.”
So what should you do right now? That is a hard question to answer because things continue to evolve and move rapidly and more and more is being understood about the long term implications. Even now information and/or speculation is coming out that home routers, wireless printers and major parts of the internet backbone may also be exploitable. This exploit is unique in that just because a company has fixed the problem in the past 48 hrs doesn’t necessarily ensure that your private information, credit cards, passwords, social security numbers have been safe. It is possible that some of that could have been stolen already sometime in the past two years. And just quickly changing your passwords on your various secure accounts doesn’t necessarily protect you. In some cases this may make things potentially worse for you. Now that this exploit is fully public there are hackers from all over the world rushing to capitalize on the exposed window that is slowly closing. If you change your password during this period you actually make it easier for some very clever hackers to get your information. Really the best course of action is to verify with your various providers whether their servers were affected or not affected by the “Heartbleed” exploit. If they were affected they need to confirm to you that their own SSL certificates were reissued and that future connections to your account are now secure. Once that happens it is safe to change your account logins and passwords. When in doubt, call your provider first. Remember this only affects online accounts that would use a secure SSL connection.
A number of different factors have to fall in line for this bug to lead to a successful exploitation.
1) The website in question has to implement SSL in the first place – no SSL means no Heartbleed bug.
2) The site has to be running the software packaged OpenSSL. That rules out a significant portion of the internet, including most IIS websites. A word of caution here, having an IIS server does not completely mitigate all risk for you because it may be connected to something like a load balancing server which is compromised.
3) The OpenSSL version has to be somewhere between 1.0.1 and 1.0.1f; anything older or newer and the bug isn’t present. So for you late adopters like us you might actually be okay.
An attacker needs to have had access to an at-risk environment somewhere between learning of the bug and it being patched by the provider. If all these things line up, then there must be something useful and retrievable from memory at the time of the attack. That is very likely in all but the most dormant sites.
So these three options below are good place to start in figuring out what you should do next. If one of your providers contacts you with specific information then you should follow those steps. Keep in mind however that in the coming weeks hackers will try to spoof various major websites and try to trick you into compromising your information or accounts. I know, just what we need to layer in on top of this growing iceberg. We have all heard the saying, Trust but Verify and this applies to any email sent to you telling you to click on this link to update your password. So below provides a general guideline.
a) If my bank (or any website) was running IIS server software, then I’m fairly safe, and there is no need to change my password. Unless of course you have a terrible password that is something like all lowercase, no numerals, caps or special characters. Then you might want to change your password anyway.
b) If my bank was running Apache or Nginx, realized the extent of the vulnerability, installed the fix, AND had a new certificate issued this week, then I SHOULD change my password and watch for unusual transactions to any credit cards associated with this account.
c) If my bank was running Apache or Nginx, and did not have a new certificate issued this week, then just by signing on I might be exposing my password (because the bad guys may have the private key to the site), even if the site now passes the Hearbleed test. You should call your provider and ask when they will have both the software patch in place and updated SSL certificates.
Lastly, this article on mashable seems to be a pretty good compilation of the major websites that were affected and which accounts should have passwords reset. Note this list is changing rapidly and just changing your password on any online bank account or secure website where you have used a credit card is not necessarily a prudent thing to do. As discussed above the reason is that you are not necessarily protected if you change your password on a website that hasn’t yet patched their software AND been issued a new security certificate. Changing your password on those sites might actually make it easier for someone to get your information and compromise your account. When in doubt the safest thing will always be to directly contact someone at your provider company and ask them about “Heartbleed” and whether they were exposed and what steps you should take next.
When more pertinent information becomes available we will be sure to pass that along to everyone.
Eric Ellason, Founder and CTO of SlickRockWeb Inc.




