Select Page

What You Need to Know About the Heartbleed Bug

Making waves in the Internet security community is the discovery of the Heartbleed bug, a serious vulnerability that allows hackers to steal personal information that is normally protected by OpenSSL encryption. OpenSSL provides security for Web applications, email, instant messaging and some virtual private networks. According to Internet security services provider Netcraft, about half a million trusted websites are vulnerable to the bug.

Heartbleed Basics

heartbleed bugThe bug allows anyone on the Internet to read the memory of any applications or websites that use vulnerable versions of OpenSSL. Hackers can exploit the vulnerability to steal proprietary data, including:

  1. Encryption keys, which can be used to decrypt protected information
  2. User credentials (username and password, etc.)
  3. Personal information, such as financial details, private emails or anything else worth encrypting

Are You Affected?

Chances are this affects you and your business in one way or another. OpenSSL is the most popular cryptographic library in use on the Internet, so it is likely that you use several websites that may have this vulnerability. Unfortunately, websites using the most current versions of OpenSSL (versions 1.0.1 through 1.0.1f) are the ones most likely to be at risk. Earlier versions are not vulnerable.

How Can You Fix the Problem?

OpenSSL has issued a fix for the Heartbleed bug. System administrators, or others who handle the infrastructure and web server on which your site runs, should update OpenSSL to version 1.0.1g immediately. The update can be found at www.openssl.org. It is also a good practice to notify your customers that you have reacted quickly to fix the vulnerability.

What Should Employees, Friends and Family Do?

Do not advise non-technical employees, family and friends to stay off the Internet entirely. Changing every password they have may be pointless if the website in question is still vulnerable. Websites that are vulnerable will likely contact users letting them know exactly what to do, up to and including changing passwords.

Use this as an opportunity to share the importance of picking strong passwords and using two-factor authentication wherever possible. These methods won’t necessarily protect them from a Heartbleed vulnerability, but they increase the overall security of their information now and in the future.

The content of this News Brief is of general interest and is not intended to apply to specific circumstances. It does not purport to be a comprehensive analysis of all matters relevant to its subject matter. The content should not, therefore, be regarded as constituting legal advice and not be relied upon as such. In relation to any particular problem which they may have, readers are advised to seek specific advice. © 2014 Zywave, Inc. All rights reserved.

Get a fast & convenient insurance quote from our local insurance agency.

Insurance Quote Online Request Form:

After getting you the best pricing for your coverage needs, our job doesn’t end.

Enjoy the convenience of 24/7 online account management, an Eaton & Berube mobile app, and more.

Learn about the client services your policy comes with:

Why Choose Us?

Get the best of both worlds. Eaton & Berube offers affordable coverage options with transparent, local service.  Learn about the advantage of working with a local broker.