IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New It now has its own website..
http://heartbleed.com/

Salon has a take:
http://www.salon.com...about_heartbleed/


There are many reasons to be concerned about “Heartbleed,” the catastrophic vulnerability in the Internet’s most popular security technology that was disclosed on Tuesday. For one thing, it’s not even clear what we, as individuals, should be doing about it. At the Atlantic, James Fallows is strongly urging that we change our passwords to our most crucial online services right now. But other experts are advising that we should wait a day or two, until potentially compromised sites have upgraded their software. Otherwise, we’ll just be handing a new password over to an already-busted security system.

That’s nerve-wracking, but not quite as anxiety inducing as the speculation floated by Bruce Schneier, a longtime security analyst with impeccable credentials.

At this point, the odds are close to one that every target has had its private keys extracted by multiple intelligence agencies. The real question is whether or not someone deliberately inserted this bug into OpenSSL, and has had two years of unfettered access to everything. My guess is accident, but I have no proof.

By “odds are close to one” Schneier means that the likelihood that the Heartbleed bug has already been exploited by everyone from the NSA to to the People’s Liberation Army is close to 100 percent. But even more distressing is the notion that this might not have been an accident.

[. . .]



As does Guardian:
http://www.theguardi...usands-of-servers

Etc. ie WHAT "MISSING AIRPLANE" ??? when...

We gots a NEW mystery (of similar signal/noise) wrapped in a cynical matrix of OBVIOUS 'interested Parties', Comrade..
KGB/China/NSANSA/and others too-numerous.
Worst Case??? Hell Youse Guys are s'posed to do gedanken What-Ifs -??- in fucking Boolean Space,

Aint'cha?
New Most damning point IMO
If the PCI guys were against it just for the high-level design, an implementation bug is the least of our worries.

But it makes our site faster ...
--

Drew
New Yes... this. ^^^
--
greg@gregfolkert.net
"No snowflake in an avalanche ever feels responsible." --Stanislaw Jerzy Lec
     Heartbleed and OpenSSL - (folkert) - (27)
         Re: Heartbleed and OpenSSL - (pwhysall) - (6)
             #1353 - (Another Scott) - (1)
                 :0) -NT - (mmoffitt)
             Well dammit -NT - (drook)
             It is even more fun than that - (scoenye) - (1)
                 Look for "pacemaker" as related to heartbleed... - (folkert)
             Amazing... - (folkert)
         It now has its own website.. - (Ashton) - (2)
             Most damning point IMO - (drook) - (1)
                 Yes... this. ^^^ -NT - (folkert)
         XKCD is cool today - (drook) - (1)
             wow - (crazy)
         SJMN: White House and NSA deny they knew about it. - (Another Scott) - (10)
             Re: SJMN: White House and NSA deny they knew about it. - (pwhysall) - (9)
                 I find this comment at Wonkette plausible. - (Another Scott) - (4)
                     Note the followup if you use Chrome. - (Another Scott) - (3)
                         So Google doesn't understand the implications of... - (a6l6e6x) - (2)
                             Deliberately turned off as of 2012 - (scoenye) - (1)
                                 I wonder if "Lifelock" is getting a spike in business... :-( -NT - (Another Scott)
                 Hola Peter.. Query: - (Ashton) - (3)
                     Re: Hola Peter.. Query: - (pwhysall) - (2)
                         hehe. -NT - (Another Scott)
                         No they wouldn't ... they've got Policies -NT - (drook)
         And it's exactly as bad as stated. - (pwhysall) - (2)
             Damn! - (a6l6e6x)
             Irony. - (static)
         Possible nasty side effect on Debian if OpenSWAN is used - (scoenye)

Its ZIMA!
64 ms