{"id":2145,"date":"2014-04-17T01:03:29","date_gmt":"2014-04-17T05:03:29","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=2145"},"modified":"2019-03-08T19:52:28","modified_gmt":"2019-03-09T00:52:28","slug":"blog-heartbleed-security-hack-need-to-change-your-password","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2014\/04\/17\/blog-heartbleed-security-hack-need-to-change-your-password\/","title":{"rendered":"Blog: Heartbleed Security Hack &#8211; Need to Change Your Password?"},"content":{"rendered":"<p>by Danielle Bringard, Associate Survey &amp; Symposium Editor<\/p>\n<p>&nbsp;<\/p>\n<p>I don\u2019t know about you, but my heart skipped several beats after reading the first wave of news detailing the Heartbleed Security Hack.\u00a0 I changed all of my passwords on various sites only to find if I had changed them before that particular web operation had updated its software I would have to change my passwords again.\u00a0 Now, I find, by checking the security of a website I may be violating the law?<\/p>\n<p>Heartbleed is not a virus, but a software defect.<a title=\"\" href=\"#_ftn1\">[1]<\/a>\u00a0 It affects OpenSSL software which is used for encryption.<a title=\"\" href=\"#_ftn2\">[2]<\/a>\u00a0 OpenSSL is an open source software, meaning anyone can access the code, review it, and make changes to it.<a title=\"\" href=\"#_ftn3\">[3]<\/a>\u00a0 So what happens when Heartbleed is exploited?\u00a0 Essentially it allows a hacker to retrieve memory which may contain usernames, passwords, keys, credit card numbers, social security numbers or other useful information.<a title=\"\" href=\"#_ftn4\">[4]<\/a>\u00a0 Each time the hacker access the system it he or she can gain access to more information.<a title=\"\" href=\"#_ftn5\">[5]<\/a>\u00a0 This is a serious problem as many people now do much of their banking and shopping on the internet.<\/p>\n<p>\u00a0So before you change your passwords it might be a good idea to check to see if the website is still vulnerable.\u00a0 If the website hasn\u2019t patched its software then changing your password will do you no good.\u00a0 McAfee released a free tool to help consumers determine if the website they visit is safe or not.<a title=\"\" href=\"#_ftn6\">[6]<\/a>\u00a0 That tool can be accessed at <a href=\"http:\/\/tif.mcafee.com\/heartbleedtest\">http:\/\/tif.mcafee.com\/heartbleedtest<\/a>.\u00a0<\/p>\n<p>\u00a0STOP!\u00a0 Before you click that link and test a website you have in mind, you should know that some technology experts are worried that doing so could break the law.<a title=\"\" href=\"#_ftn7\">[7]<\/a>\u00a0 These naysayers cite the United States Computer Fraud and Abuse Act.<a title=\"\" href=\"#_ftn8\">[8]<\/a>\u00a0 Software that checks a website to see if it has patched the Heartbleed actually accesses that sites security certificate, which may or may not fall under the purview of 18 U.S.C. \u00a71030.\u00a0 Since everyone across the globe is experiencing the effects of Heartbleed, and it may take some time before all websites have patched their software<a title=\"\" href=\"#_ftn9\">[9]<\/a>, I doubt the U.S. government would prosecute a citizen simply seeking to ensure their person information remained protected or taking any proactive steps to do so.<\/p>\n<p>As always, safety first.\u00a0<\/p>\n<div>\n<hr align=\"left\" size=\"1\" width=\"33%\" \/>\n<div>\n<p><a title=\"\" href=\"#_ftnref1\">[1]<\/a> James Lyne, <i>How Heartbleed Happened the NSA and Proof Heartbleed Can Do Real Damage, <\/i>Forbes (Mar. 14, 2014, 9:27 AM), <i>available at<\/i> http:\/\/www.forbes.com\/sites\/jameslyne\/2014\/04\/14\/how-heartbleed-happened-the-nsa-and-proof-heartbleed-can-do-real-damage\/.<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref2\">[2]<\/a> <i>Id.<\/i><\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref3\">[3]<\/a> <i>Id.<\/i>\u00a0<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref4\">[4]<\/a> James Lyne, <i>Heartbeat Heartbleed Bug Breaks Worldwide Internet Security Again (And Yahoo)<\/i>, Forbes (Mar. 8, 2014, 11:39 PM), <i>available at<\/i> http:\/\/www.forbes.com\/sites\/jameslyne\/2014\/04\/08\/heartbeat-heartbleed-bug-breaks-worldwide-internet-security-again-and-yahoo\/; Craig Timberg, <i>Heartbleed Bug Puts the Chaotic Nature of the Internet Under the Magnifying Glass<\/i>, Wash. Post (April 9, 2014), <i>available at <\/i>http:\/\/www.washingtonpost.com\/business\/technology\/heartbleed-bug-puts-the-chaotic-nature-of-the-internet-under-the-magnifying-glass\/2014\/04\/09\/00f7064c-c00b-11e3-bcec-b71ee10e9bc3_story.html.<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref5\">[5]<\/a> Lyne, <i>Heartbeat Heartbleed<\/i> <i>supra<\/i> note 4.\u00a0<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref6\">[6]<\/a> Robert Siciliano, <i>Heartbleed: Free Tool to Check If That Site is Safe<\/i>, Huffington Post (Mar. 12, 2014, 10:35 AM), <i>available at<\/i> http:\/\/www.huffingtonpost.com\/robert-siciliano\/heartbleed-free-tool-to-c_b_5137993.html.<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref7\">[7]<\/a> Anthony M. Freed, <i>Running Heartbleed Health Checks May Be Illegal<\/i>, TripWire (April 11, 2014), <i>available at<\/i> http:\/\/www.tripwire.com\/state-of-security\/top-security-stories\/running-heartbleed-health-checks-may-be-illegal\/; Michael Santarcangelo, <i>How You Need To Respond To Heartbleed, and How You Can Explain It To Others<\/i>, CSOnline (April 11, 2014, 12:27 PM), <i>available at<\/i> http:\/\/www.tripwire.com\/state-of-security\/top-security-stories\/running-heartbleed-health-checks-may-be-illegal\/.<\/p>\n<p>\u00a0<a title=\"\" href=\"#_ftnref8\">[8]<\/a> John Leyden, <i>It May Be Illegal to Run Heartbleed Checks<\/i>, The Register (April 11, 2014), <i>available at<\/i> http:\/\/www.theregister.co.uk\/2014\/04\/11\/heartbleed_health_checking_services_may_be_illegal\/; <i>supra<\/i> note 7.<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref9\">[9]<\/a> Brian Fung, <i>Heartbleed is About to Get Worse, and Will Slow the Internet to a Crawl<\/i>, Wash. Post (April 14, 2014, 2:54 PM), <i>available at<\/i> http:\/\/www.washingtonpost.com\/blogs\/the-switch\/wp\/2014\/04\/14\/heartbleed-is-about-to-get-worse-and-it-will-slow-the-internet-to-a-crawl\/.\u00a0<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>by Danielle Bringard, Associate Survey &amp; Symposium Editor &nbsp; I don\u2019t know about you, but my heart skipped several beats after reading the first wave of news detailing the Heartbleed Security Hack.\u00a0 I changed all of my passwords on various sites only to find if I had changed them before that particular web operation had [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[51366],"tags":[],"class_list":["post-2145","post","type-post","status-publish","format-standard","hentry","category-blog-post"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-yB","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/2145","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=2145"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/2145\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=2145"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=2145"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=2145"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}