Skip to main content

Heartbleed bug affects ‘almost everyone,’ expert warns

two apple airport base stations were vulnerable to heartbleed but have been patched bug
Image used with permission by copyright holder

Experts say the Heartbleed OpenSSL bug — a flaw in the network software meant to protect your data — may have actually allowed hackers to steal the very data it’s meant to guard. Think you’re safe from this obscure bug in OpenSSL, whatever that is? Think again. One expert noted that “almost everyone” uses it. 

“Given that over half of the world’s webservers use Apache, and Apache uses OpenSSL, the majority of people are using applications built on top of OpenSSL on a regular basis,” explained Steve Pate, the Chief Architect at cloud services company HyTrust.

The Heartbleed bug is a security hole discovered in OpenSSL, widely used network software that encrypts the sensitive data you input into many popular websites. The flaw allows hackers to steal data directly from the memory chips of servers all over the world, and has been in existence for roughly two years. Jean Taggart, a Senior Security Researcher at Malwarebytes, which makes popular anti-malware software, described it as an easy way for crooks to invisibly sweep up your data.

MORE: What is the Heartbleed Bug?

“This vulnerability gives cyber criminals a method for collecting very sensitive information, like private encryption keys. If an adversary has extracted the private key through the Heartbleed vulnerability, they can impersonate the victim, and set up an undetectable man-in-the-middle attack,” Taggart said.

OpenSSL has a history of being vulnerable to attacks, Pate says, with the first flaw spotted by HyTrust back in May of 2009. However, Pate also notes that though OpenSSL 1.0.1 and 1.0.2-beta already have Heartbleed bug fixes available, if the affected versions are being used, the exploit may have already been used by hackers to swipe sensitive data.

 Taggart also explained that exterminating the security flaw will be no easy task.

“Fixing this bug will not be trivial, because even though security professionals can roll out an upgrade, many will not reset their certificates as this is a difficult and lengthy task. So if they were compromised prior to the announcement of the bug, their private keys might already be in the hands of adversaries, and their encrypted communications could be intercepted by third parties.”

MORE: Which websites are affected by the Heartbleed Bug?

Nathaniel Couper-Noles, a Principal Security Consultant at security firm Neohapsis, said that though there are workarounds and fixes available to combat Heartbleed, “the horse may already be out of the barn.”

“Many organizations aren’t instrumented to identify whether and where they’re vulnerable, the attack may leave no footprint discernable from legitimate traffic, and the consequences can potentially be long term,” Couper-Noles said. On top of that, Couper-Noles noted that there could be “hundreds or thousands of affected systems” across the world’s businesses.

At this point, changing your passwords is the best course of action you can take to protect yourself from the Heartbleed bug. On top of that, avoiding the webpages on this list of sites that are allegedly affected by the OpenSSL flaw is also highly recommended.

Image credit: http://www.wallpaperzzz.com

Editors' Recommendations

Konrad Krawczyk
Former Digital Trends Contributor
Konrad covers desktops, laptops, tablets, sports tech and subjects in between for Digital Trends. Prior to joining DT, he…
Samsung Cyber Monday deals: TVs, tablets, smartphones, and more
Stack of Samsung Galaxy S22 phones.

Samsung is behind a lot of different electronic devices in the market, like TVs, monitors, smartphones, tablets, and refrigerators. It's among the most trusted names in the consumer electronics industry, with offerings that range from budget to premium, and you can secure discounts across the board through the Cyber Monday deals that have launched. You're going to have to act quickly though, because there's always high demand for Samsung Cyber Monday deals. We've gathered some of our favorite bargains below to help you decide fast, but it's also worth checking Samsung has on sale by clicking on the button below.

Samsung TV Cyber Monday deals

Read more
Best Chromebook Cyber Monday deals on HP, Lenovo, and more
Digital Trends Best Cyber Monday Chromebook Deals

Cyber Monday deals are online, making this the perfect time to grab a new laptop, especially if you're thinking about getting a Chromebook. They're easy to set up, simple to use, and affordable, making the Chrome OS-powered devices perfect for students and casual users.

If you do want a more premium laptop, but with up to $1,000 off of a high-powered laptop, we highly recommend you check out these Best Buy Cyber Monday laptop deals, or Cyber Monday laptop deals and Cyber Monday MacBook deals, for PC and MacOS respectively.
Best HP Chromebook Cyber Monday Deals

Read more
Best Cyber Monday laptop deals: Dell, HP, Lenovo, and more
Digital Trends Best Black Friday Laptop Deals

Since Cyber Monday deals are going strong, it's the perfect time to buy new tech like laptops. We've seen some fantastic deals over the past week, and there are no signs that the bargains are slowing down. There are some amazing laptop deals right now from a wide variety of retailers, and we've collected our favorites below. You'll see the best of Amazon Cyber Monday laptop deals and Best Buy Cyber Monday laptop deals. We've pulled from a ton of different brands, all from the PC side, but if you want Cyber Monday MacBook deals, check out that list too.
Top 3 Cyber Monday laptop deals
HP 17-inch laptop -- $250, was $500

Currently heavily discounted as part of HP laptop Cyber Monday deals, the HP 17-inch laptop is ideal for anyone on a slim budget. It looks more expensive than it is thanks to having a 17-inch HD+ screen with 1600 x 900 and 250 nits of brightness. That extra room also means the keyboard is roomier with a numeric pad to the right of it that's ideal for entering a lot of data. The laptop has an AMD Athlon Gold 7220U processor along with 8GB of memory and 128GB of SSD storage. It also has a lift-hinge to ensure you can type at a more natural position.

Read more