Heartbleed

Please remember the terms of your membership agreement.

Moderators: valis, garyb

Post Reply
Neil B

Heartbleed

Post by Neil B »

Anyone know if this forum & its password system is affected by the so called heartbleed bug that's currently in the news?
User avatar
garyb
Moderator
Posts: 23380
Joined: Sun Apr 15, 2001 4:00 pm
Location: ghetto by the sea

Re: Heartbleed

Post by garyb »

as i understand it, even if it was, there's very little that a bad guy could actually do with the info, other than post in your name.
jksuperstar
Posts: 1638
Joined: Mon Nov 15, 2010 12:57 pm

Re: Heartbleed

Post by jksuperstar »

I don't think typical communications are https on boards like this. So you're always vulnerable :)
hubird

Re: Heartbleed

Post by hubird »

your login password could be stolen tho...and if you (against all recommendations) use it also elsewhere...and they know where that is...

hmm, I remember an angry forum member knew to find my full name and physical adres and posted it here.
Personal tracks on the internet are everywhere, combinations are always possible.

As you can automaticly login on Planetz it doesn't hurt to change password, but you would have to repeat it in the next future as it takes some times befor the leaks on all infected servers will be bunged.

I feel it's time to use a keypass manager anyway.
User avatar
John Cooper
Moderator
Posts: 1182
Joined: Thu Mar 22, 2001 4:00 pm
Location: Planet Z
Contact:

Re: Heartbleed

Post by John Cooper »

jksuperstar wrote:I don't think typical communications are https on boards like this. So you're always vulnerable :)
That's essentially correct. phpbb doesn't use https, so passwords, etc are sent in the clear instead of encrypted.
Of course the password is stored encrypted in the phpbb database.
But anyone snooping on network traffic could grab your password when you log in.

-John
User avatar
braincell
Posts: 5943
Joined: Thu Sep 13, 2001 4:00 pm
Location: Washington DC

Re: Heartbleed

Post by braincell »

They can only capture random bits of data which are being processed during the attack anyway.
Post Reply