• 🏆 Texturing Contest #33 is OPEN! Contestants must re-texture a SD unit model found in-game (Warcraft 3 Classic), recreating the unit into a peaceful NPC version. 🔗Click here to enter!
  • It's time for the first HD Modeling Contest of 2024. Join the theme discussion for Hive's HD Modeling Contest #6! Click here to post your idea!

Heartbleed

Status
Not open for further replies.
So apparently this Heartbleed is a big deal and something we should worry about.

After a quick check using this site:
http://filippo.io/Heartbleed/ (I don't know if it gives a trustworthy answer)

It appears that Hive is in the compromised category.
Google.com and Facebook.com are apparently safe.

I am not capable of giving detailed info about Heartbleed since I don't know how it works.
But here is a heads up to you who cares.

Here is a link with more info:
http://krebsonsecurity.com/2014/04/heartbleed-bug-exposes-passwords-web-site-encryption-keys/
 

Dr Super Good

Spell Reviewer
Level 64
Joined
Jan 18, 2005
Messages
27,198
Only people who were using openSSL were affected. It also only affects server owners in the form of a personal information leak so there is no updating needed for clients (unless they host a private SSL connection for some reason in which case they need to update).

Blizzard was also not affected because they use their own security systems (not openSSL).

The problem comes about with the heartbeat message that is part of SSL. By using an invalid offest field (larger than the buffer) you gain access to nearby addresses in the process memory space (64 KB of memory to be exact). This is not a direct data leak (they cannot query specific personal information) but it does allow them to snoop at what traffic is going through the SSL process since it mostly uses memory around that 64 KB area to handle all connections. This lets hackers get recently transmitted personal information and store it for use later in a crime.

Basically a bounds check fault. Someone forgot to check if value < size. Yes that is how dumb most of these security faults are.
 
Status
Not open for further replies.
Top