1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

This plugin will warn you immediately when you visit a site affected by Heartbleed

Discussion in 'News & Current Events' started by allheart55 (Cindy E), Apr 10, 2014.

  1. allheart55 (Cindy E)

    allheart55 (Cindy E) Administrator Administrator

    Joined:
    Jun 11, 2009
    Messages:
    10,617
    Location:
    Pennsylvania
    Operating System:
    Windows 10
    Computer Brand or Motherboard:
    ASUS M4A77TD AM3 AMD 770 ATX AMD
    CPU:
    AMD Phenom II X6 1090T-Thuban 3.2GHz
    Memory:
    Crucial-DDR3 SDRAM 1333-8GB
    Hard Drive:
    WD Caviar Black SE HDD 640 GB - WD Caviar Black SE HDD 500 GB
    Graphics Card:
    Sapphire Radeon HD-7870 2GB
    Power Supply:
    CORSAIR CMPSU-750W
    Heartbleed is one of the most widespread vulnerabilities we have seen in recent years — it impacted an estimated 66% of the entire Internet at the time of its discovery. The bug affects OpenSSL, which is a popular security protocol used to encrypt sensitive data sent to and from websites. Major sites such as Yahoo, Flickr and Imgur are among the sites that were affected by Heartbleed, potentially exposing users’ passwords and other data to hackers. While many have patched the bug and others continue to do so, it will be months or even years before every site addresses the issue.
    In the meantime, a simple free Chrome browser plugin will alert users when they visit a website that is still vulnerable.
    Developer Jamie Hoyle has created a nice Chrome extension dubbed Chromebleed that serves a single purpose: It displays a warning when you visit a website affected by Heartbleed.

    From the plugin’s description:

    Many HTTPS-secured sites on the internet use OpenSSL. Unfortunately, a major vulnerability in OpenSSL was disclosed – known as the Heartbleed bug – yesterday that put hundreds of thousands of servers at risk of compromise.
    Whilst some servers have been patched already, many remain that have not been patched. Chromebleed uses a web service developed by Filippo Valsorda and checks the URL of the page you have just loaded. If it is affected by Heartbleed, then a Chrome notification will be displayed. It’s as simple as that!
    Head over to this post to learn exactly what you should do when you encounter sites with the Heartbleed vulnerability.

    http://news.yahoo.com/plugin-warn-immediately-visit-affected-heartbleed-143835743.html
     
  2. Plastic Nev

    Plastic Nev SUPER MODERATOR IN MEMORY

    Joined:
    May 2, 2009
    Messages:
    2,801
    Location:
    In front of a monitor in Blackburn Lanc's UK.
    Operating System:
    Windows 7
    Could do with an add on for other browsers too, as many like me will not use Chrome and prefer Firefox, or any of the other browsers.
     
  3. allheart55 (Cindy E)

    allheart55 (Cindy E) Administrator Administrator

    Joined:
    Jun 11, 2009
    Messages:
    10,617
    Location:
    Pennsylvania
    Operating System:
    Windows 10
    Computer Brand or Motherboard:
    ASUS M4A77TD AM3 AMD 770 ATX AMD
    CPU:
    AMD Phenom II X6 1090T-Thuban 3.2GHz
    Memory:
    Crucial-DDR3 SDRAM 1333-8GB
    Hard Drive:
    WD Caviar Black SE HDD 640 GB - WD Caviar Black SE HDD 500 GB
    Graphics Card:
    Sapphire Radeon HD-7870 2GB
    Power Supply:
    CORSAIR CMPSU-750W
    Yeah, me either Nev. I wish there was a plug in for IE but no such luck...
     
  4. Plastic Nev

    Plastic Nev SUPER MODERATOR IN MEMORY

    Joined:
    May 2, 2009
    Messages:
    2,801
    Location:
    In front of a monitor in Blackburn Lanc's UK.
    Operating System:
    Windows 7
    Just looked through the list of tested websites, a huge number are already not vulnerable, with a small number that still are, fortunately they are not sites I use anyway, however that is not really enough to be sure.
    There must be billions of websites and associated servers, so some are bound to be as yet vulnerable but not as yet tested.
    What did surprise me, which I suppose it shouldn't, was the huge amount of obviously shall we say, adult content types out there, and would you believe none that I saw were vulnerable. :biggrin:
     
  5. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
  6. allheart55 (Cindy E)

    allheart55 (Cindy E) Administrator Administrator

    Joined:
    Jun 11, 2009
    Messages:
    10,617
    Location:
    Pennsylvania
    Operating System:
    Windows 10
    Computer Brand or Motherboard:
    ASUS M4A77TD AM3 AMD 770 ATX AMD
    CPU:
    AMD Phenom II X6 1090T-Thuban 3.2GHz
    Memory:
    Crucial-DDR3 SDRAM 1333-8GB
    Hard Drive:
    WD Caviar Black SE HDD 640 GB - WD Caviar Black SE HDD 500 GB
    Graphics Card:
    Sapphire Radeon HD-7870 2GB
    Power Supply:
    CORSAIR CMPSU-750W
  7. Pesi

    Pesi Registered Members

    Joined:
    Apr 3, 2014
    Messages:
    86
    Operating System:
    Windows 10
    Wow, great! Hotmail is infected according to this plugin, and I logged in to two of my primary accounts within the last 48 time frame. I sincerely hope Microsoft patches this quick.

    I am going to start creating email accounts for every site I use; each on different platforms. That way when an email is compromised, it won't have all sensitive contents in one place which makes all other accounts at risk of having its password reset by an unauthorised user.
     
    Last edited by a moderator: Apr 10, 2014
  8. Rich M

    Rich M Guest

    Joined:
    Dec 24, 2013
    Messages:
    4,580
    Location:
    NE Pa USA
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MSI Z97 PC Mate LGA 1150 Intel Z97
    CPU:
    Intel i7 4790K 4.0Ghz
    Memory:
    Corsair Vengeance 16GB (2x8GB) DDR3 2133
    Hard Drive:
    Crucial 256 Gb SSD+ WD Raptor 300 Gb Sata III
    Graphics Card:
    Radeon R9 280 2GB HDMI
    Power Supply:
    Seasonic 750 watt
    In spite of all the recent problems with the widespread free email accounts, it amazes me that anyone still uses them. All I know is I have used pc based email for almost 15 years and
    I have never had an issue with it and never lost anything. Everyone makes fun of me with Outlook and my website based email but it just goes on and on....
     
  9. DSTM (Dougie)

    DSTM (Dougie) Registered Members

    Joined:
    May 3, 2009
    Messages:
    8,270
    Location:
    SYDNEY AUSTRALIA
    Operating System:
    Windows 7
    Don't be amazed, Rich. We all use the Email accounts that suits us best.
    Free Email accounts offer a lot more than Outlook.
    If you only send bland emails then Outlook is fine.
    If an email account is hacked there is always an easy fix.
    If you only want to send funny emails which include funny emoticons and animations to Family and friends then we use the free email account which suits us best.
    We all use Emails for different reasons.
    I do have an Email notifier which lets me read an email without ever actually opening the email.
     
  10. Rich M

    Rich M Guest

    Joined:
    Dec 24, 2013
    Messages:
    4,580
    Location:
    NE Pa USA
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MSI Z97 PC Mate LGA 1150 Intel Z97
    CPU:
    Intel i7 4790K 4.0Ghz
    Memory:
    Corsair Vengeance 16GB (2x8GB) DDR3 2133
    Hard Drive:
    Crucial 256 Gb SSD+ WD Raptor 300 Gb Sata III
    Graphics Card:
    Radeon R9 280 2GB HDMI
    Power Supply:
    Seasonic 750 watt
    Really Dougie.
    I can read email without opening them. There are eons of different stationery I can use for email as well as a full working word processor in Outlook capable of doing anything Ms Word can do to a project.
    I can use one of 1200 fonts, 36 different font sizes as well as 48 colors for the fonts. I can have 6 email accounts empty into one inbox and send email from any of those accounts with different signatures
    for every account and I can access the storage from 10 computers for the one program and 6 email addresses. at home or away. I have a calendar with reminders, contacts separate for all 6 accounts and a task list as well and gmail , Hotmail and Yahoo Mail can't do any of what I listed but the one thing they can do is get hacked on a daily basis!
     
  11. allheart55 (Cindy E)

    allheart55 (Cindy E) Administrator Administrator

    Joined:
    Jun 11, 2009
    Messages:
    10,617
    Location:
    Pennsylvania
    Operating System:
    Windows 10
    Computer Brand or Motherboard:
    ASUS M4A77TD AM3 AMD 770 ATX AMD
    CPU:
    AMD Phenom II X6 1090T-Thuban 3.2GHz
    Memory:
    Crucial-DDR3 SDRAM 1333-8GB
    Hard Drive:
    WD Caviar Black SE HDD 640 GB - WD Caviar Black SE HDD 500 GB
    Graphics Card:
    Sapphire Radeon HD-7870 2GB
    Power Supply:
    CORSAIR CMPSU-750W
    I had to jump through hoops after my Yahoo account was hacked. I lost all my contacts, folders and messages. (Luckily
    I was able to have them restored because I discovered it immediately.) Unfortunately because the hacker also sent a
    begging email to all of my contacts, I was forced by my bank to open all new accounts. This included our online banking site,
    debit cards, savings and checking accounts. The bank wanted to err on the side of caution.

    Needless to say, I purchased the Yahoo paid email and began popping my email immediately.
     
  12. Rich M

    Rich M Guest

    Joined:
    Dec 24, 2013
    Messages:
    4,580
    Location:
    NE Pa USA
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MSI Z97 PC Mate LGA 1150 Intel Z97
    CPU:
    Intel i7 4790K 4.0Ghz
    Memory:
    Corsair Vengeance 16GB (2x8GB) DDR3 2133
    Hard Drive:
    Crucial 256 Gb SSD+ WD Raptor 300 Gb Sata III
    Graphics Card:
    Radeon R9 280 2GB HDMI
    Power Supply:
    Seasonic 750 watt
    I remember that. I called Cindy that morning because I got an email purportedly from her that she and her husband were on vacation in Puerto Rico and they had their wallets stolen and could I send her
    $500 so she could gbet a plane ticket to come home...something like that!
     
  13. DSTM (Dougie)

    DSTM (Dougie) Registered Members

    Joined:
    May 3, 2009
    Messages:
    8,270
    Location:
    SYDNEY AUSTRALIA
    Operating System:
    Windows 7
    Post Edited.

    Bland is not the correct description of Outlook.
    Some people who want to send emoticons, animated images and speech bubbles prob use something like Incredimail.
    Yahoo seems a prime target for hackers.
    I have GMAIL and luckily I haven't been hacked yet. (touch wood)
    I will not use the Net for Banking as I think too risky however that's my choice.
     
  14. Match

    Match Registered Members

    Joined:
    Apr 23, 2009
    Messages:
    4,175
    Location:
    Wolverhampton, UK.
    Computer Brand or Motherboard:
    Abit AN52
    CPU:
    AMD Athlon dual core 5000+
    Memory:
    4 Gig Corsair
    Hard Drive:
    160 Gb Hitachi 500 Gb Western Digital
    Graphics Card:
    Radion XFX 4650
    Power Supply:
    550W EZcool
    I think the thing were missing is most people arn't that computer literate, I have 6 main accounts and others that are set to forward mail to one of the main accounts, I use the filters provided and rarly get spam, bulk mail I don't want into my inbox, yet most people I know constantly complain about junk mail.

    I think the main concern here is that hackers are realising that by targeting cloud based servers the gains are greater than targeting individual devices.
     
  15. Rich M

    Rich M Guest

    Joined:
    Dec 24, 2013
    Messages:
    4,580
    Location:
    NE Pa USA
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MSI Z97 PC Mate LGA 1150 Intel Z97
    CPU:
    Intel i7 4790K 4.0Ghz
    Memory:
    Corsair Vengeance 16GB (2x8GB) DDR3 2133
    Hard Drive:
    Crucial 256 Gb SSD+ WD Raptor 300 Gb Sata III
    Graphics Card:
    Radeon R9 280 2GB HDMI
    Power Supply:
    Seasonic 750 watt
    Sorry Dougie if I overreacted...Match hit the nail on the head with my summary of "more bang for the buck hitting a cloud based server" and that is still another reason I love Outlook.
    Don't get me wrong it is a cumbersome program, difficult to move from an old computer to a new one but to those who get used to that we learn to love it.
     
  16. Match

    Match Registered Members

    Joined:
    Apr 23, 2009
    Messages:
    4,175
    Location:
    Wolverhampton, UK.
    Computer Brand or Motherboard:
    Abit AN52
    CPU:
    AMD Athlon dual core 5000+
    Memory:
    4 Gig Corsair
    Hard Drive:
    160 Gb Hitachi 500 Gb Western Digital
    Graphics Card:
    Radion XFX 4650
    Power Supply:
    550W EZcool
    I've never liked outlook or Yahoo, but I think that was Dougies point people are different and like different things.

    but hackers and malware are all quite similar, they want data to make, steel money, for as little work as possible. and it now looks like attention has turned to sites rather than devices,

    Is this the first of many? or just a one off that exploits a hole in security? is this the start of the end for SSL?
     
  17. DSTM (Dougie)

    DSTM (Dougie) Registered Members

    Joined:
    May 3, 2009
    Messages:
    8,270
    Location:
    SYDNEY AUSTRALIA
    Operating System:
    Windows 7
    That is what I was trying to get across, Match.
    We all want different things from the net to suit our own likes.
    We don't all drive the same car so what suits you may not suit me.:)
     
  18. Plastic Nev

    Plastic Nev SUPER MODERATOR IN MEMORY

    Joined:
    May 2, 2009
    Messages:
    2,801
    Location:
    In front of a monitor in Blackburn Lanc's UK.
    Operating System:
    Windows 7
    Just to keep the risk low and manageable should something go wrong, I only use two E mail addresses, one is hotmail, the other is my ISP based, both have very strong passwords, both different and certainly not used on any other websites. Being a Windows 7 main desktop, that is the only computer with E mail configured and for simplicity used the Windows Live Mail, configured to access both E Mail providers.
    As for the SSL vulnerability, most major servers have already addressed the problem anyway, add to that there is very little if any, evidence that the vulnerability was actually used.
    However, time will tell with that as there is no way to record hacking activity as and when it happened, so directly speaking it isn't known if anything has been gained by hackers before the problem was seen and the loophole closed.

    Give it a couple of weeks, if information was acquired by hackers through that vulnerability, it will start to show up by then. Otherwise I think there has been a bit of an over reaction to this threat, given that if it had been used heavily it could have cost a few millions, as yet though no proof of that. So perhaps a bit too much panic when it was first discovered.
    KEEP
    CALM
    AND
    CARRY ON.

    Nev.
     
    Pesi likes this.
  19. Rich M

    Rich M Guest

    Joined:
    Dec 24, 2013
    Messages:
    4,580
    Location:
    NE Pa USA
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MSI Z97 PC Mate LGA 1150 Intel Z97
    CPU:
    Intel i7 4790K 4.0Ghz
    Memory:
    Corsair Vengeance 16GB (2x8GB) DDR3 2133
    Hard Drive:
    Crucial 256 Gb SSD+ WD Raptor 300 Gb Sata III
    Graphics Card:
    Radeon R9 280 2GB HDMI
    Power Supply:
    Seasonic 750 watt
    A number of years ago I tried using Gmail online to access all my email addies but it was so clumsy to use and so lacking in features I was used to like a full array of fonts and font sizes and there just weren't enough settings really to personalize it the way I like email. Then my web host started with Zimbra mail platform which was online and had a lot more options but I still just wasn't happy with enough features. I so wish I could find an online application that was as configurable as Live Mail or Outlook because it would make accessing from different locations so much easier but time will tell. The other thing I like is with onboard mail when you go to send a photo Live Mail and Outlook or Windows Mail always automatically send to the mail recipient and allow you to shrink the size to accommodate folks with slower email accounts as well. I gues it all biol;s down to ones needs and what they are used to.
     

Share This Page