COLD WATER FOR WARM & FUZZIES. As web sites and software - TopicsExpress



          

COLD WATER FOR WARM & FUZZIES. As web sites and software developers continue their rush to the front of the line with announcements that theyve patched their services to prevent the evil #Heartbleed exploit, others have been making warm and fuzzy public announcements of their own, stating that their services were never at risk because even though they rely on #OpenSSL, they werent using the affected versions. Heres what youre being told - without being told - when many of these developers tell you that their systems werent at risk because the Heartbleed exploit only applies to OpenSSL v1.01 -> v1.01f and they use versions like v0.9.8 or even v0.9.6 ... Theyre not staying current with their security toolkits, many of which havent been updated for years, and although theyre not vulnerable to Heartbleed, they ARE potentially vulnerable to many other exploits and attacks with the possibilities being dependent upon the specific versions and revisions. Sorry, Charlie, but you dont get brownie points for not being open to Heartbleed attacks if havent updated your compiled security protocols in 2-10+ years.
Posted on: Thu, 10 Apr 2014 22:09:21 +0000

Trending Topics



Recently Viewed Topics




© 2015