The Heartbleed Aftermath

May 12, 2014

by: Doug Zbikowski

heartbleed[1] It’s been over a month since the Heartbleed bug brought Internet security to the forefront of the news, and according to Errata Security’s Robert Graham , more than 300,000 servers across the globe are still vulnerable. This is a big drop from the 600,000 initially detected when the vulnerability first became public, but it’s still a large number.

After its discovery earlier this year, Heartbleed is still a serious threat because it can potentially release usernames, credit card information, passwords, and other personal data to attackers. It was determined a flaw in OpenSSL, a common tool used to encrypt and secure communication between a user to a server, is the source of this security breach.

Graham’s numbers are concerning, and they might just be the tip of the iceberg.

His testing was done by scanning port 443 (a port is a “channel” used in Internet communication that is reserved for a specific function. Port 443 is typically used for SSL traffic). There may be thousands…even millions…more servers out there using undetected alternate ports that are still unpatched.

What Exactly IS Heartbleed?

The easiest way to describe how Heartbleed works is to imagine a computer and a server talking to each other. They don’t want anyone else listening in, so they speak to each other in a unique language only they can understand. Any other computers trying to join in the conversation would just hear gibberish.

Once in a while, there may be a lull in the conversation, so the computer will want to make sure the server is still listening. The computer will send a “heartbeat”, or a nudge saying “Hey! Prove you’re still there!”

Your computer might say “Prove you’re there: respond with “Pineapple (spelled with 9 characters)”.
The server replies “Pineapple”.

“Prove you’re there: respond with “Car (spelled with 3 characters)”.
The server replies “Car”.

Some clever person discovered that if you form a heartbeat request to say something equivalent to “Prove you’re there: respond with “Phone (spelled with 1000 characters)”, the server would respond with “Phone” and then the next 995 characters of data in the server’s memory. This data would include data from anyone else’s SSL transactions, so payment information, personal data…everything that was supposed to be secure could be exposed. (Of course, this is a very simplistic explanation, but it gets the point across.)

World Status

 

It’s clear that a lot of servers on the Internet have not been patched to fix the Heartbleed bug, and that’s not likely to change anytime soon. Ars Technica , another well known security firm, found that a month after Heartbleed was announced vulnerable servers decreased only .44%. This indicates that server patching has essentially stopped.

 

If you’re wondering what you can do to protect yourself, you’re in the same boat as everyone else. Nobody knows exactly which services and servers still have the flaw. Many companies have done their best to let their users know if they were or were not affected, but there is no comprehensive list saying “We fixed the problem, so change your password.” You can bet that financial institutions, ISP’s, and large companies patched their OpenSSL servers quickly, so most of the remaining servers are probably going to be run by small businesses that either do not know they have the bug or do not have the expertise to repair it. You best bet is to check with any services that require a username/password to log into an account to see if they were affected.

 

On a positive note, Heartbleed has made security a top priority again. Many companies are reviewing their security practices, making sure they have the basics like antivirus software and are getting their software updates in a timely fashion. You’ll probably want to join in with them.

 

 

By Mike Pawlecki 31 Mar, 2021
TOAST.net is excited to offer 4 new Business Broadband plans
By Mike Pawlecki 11 Mar, 2021
TOAST.net is excited to announce 3 new Business Fiber Plans
By Mike Pawlecki 12 Jan, 2021
TOAST.net has added two new residential Fiber Internet plans!
By Mike Pawlecki 14 Aug, 2020
This coming Monday, Aug. 17th, we will be switching to universal pricing -- one price for all DSL speeds (around $65) and one price for Fiber (around $90). So if anyone is thinking they could use one of our basic service plans, now's the time to order. For example:  DSL - 12 Mbps for $43.95/month - Great for seniors on a fixed income. Plenty of speed for surfing the web, checking email, and streaming for 1 or 2 TVs. Fiber - 60 Mbps for $45.00/month - Awesome solution for just about any household. Note that fiber is a new technology and only about 20% of the country can get it.  Check your address to see what service you qualify for and order by Sunday, 8/16/20! This is your last chance to lock in the speed and price of a great DSL or Fiber plan before they are grandfathered! 
Google Meet for your home or office.
By Mike Pawlecki 20 May, 2020
Google Meet is now free for everyone. Check out TOAST.net's blog that tells you more about Google Meet usage at your home or office.
By Mike Pawlecki 01 May, 2020
Google - Meet Meet is video conference software, similar to Zoom. To help businesses, schools, and people around the world navigate remote life, Google is making Meet free for everyone with availability rolling out over the coming weeks. See Google's blog post for details. SolarWinds - Take Control You may need to run applications off your PC or server at the office. In that case, SolarWinds makes makes an easy-to-use application that allows home users to remote desktop to their PC in the office. It's secure and doesn't require special hardware, a static IP, or VPN. We're offering this software free of charge for 90 days. Please contact us if interested.
By Mike Pawlecki 20 Mar, 2020
This week we've taken quite a few calls from companies asking how their employees and staff can work from home (WFH). We're happy to offer several WFH solutions to help organizations mitigate health risks to employees and customers. TOAST.net understands how important it is to keep your employees connected, productive, and safe during this unprecedented pandemic. Here are the services we have to help your business through this difficult time : Business Portal is a 'home page' for your browser that improves communication and efficiencies within your organization. It's a private Intranet that features company news, announcements, links to vendors and cloud apps, an employee schedule, and more! We offer this at no charge to our customers. Visit https://start.toast.net Google's G Suite - TOAST.net is an authorized reseller of G Suite, a cloud-based collaboration tool featuring Email, Calendar, Chat, Hangouts (video conferencing), and Drive. You can create files, documents, spreadsheets, and presentations with just your browser (no software to install) and share these with fellow workers, customers, and vendors. More info Remote Desktop - an easy-to-use application that allows home users to connect to PCs in the office. It's secure and doesn't require special hardware or a static IP. We're offering this free of charge for 90 days. High-speed Internet for Home - We provide residential Cable, DSL, and Fiber Internet service . So you can pay for your employee's Internet connection on your business invoice. Please contact us if you're interested in any of these services. B est wishes to everyone to stay healthy, safe, and upbeat as we socially distance ourselves for a quick end to this situation. Note: Our customer support team continues to work their regular hours. We operate support teams in multiple locations and, while there may be some disruption at certain locations for a limited time, overall we do not expect any significant change in access to support.
By TOAST.net Internet 28 Jan, 2019
In the month after Christmas, we’ve seen a high demand for our Internet service with unlimited data. Much of it is from people wanting to use their new streaming device (Fire Stick, Roku, Chromecast, Apple TV, etc.) to cancel their expensive cable TV service. This is commonly referred to as “cutting the cord.”
By TOAST.net Internet 17 Dec, 2018
TOAST.net is pleased to announce fiber Internet service in 12 new metro areas:
By TOAST.net Internet 12 Dec, 2018
Moved Facebook link from top bar to the Popular Sites section. Added Yahoo Finance to the Personal Finance section. Yahoo Finance is one of the largest business news web sites in the United States by monthly traffic.
More Posts
Share by: