• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Security Catastrophe: have you changed your passwords?

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    Security Catastrophe: have you changed your passwords?

    BBC News - Heartbleed Bug: Public urged to reset all passwords

    #2
    The thing is, at the moment you can't be sure all servers have been patched, which means that if you change your password now you could just be giving away the new one, whereas your existing password might never have been compromised.

    It can make more sense to wait a few days for everything to be updated, and only then change your password.

    Though that may be too late, of course

    Security expert Bruce Schneier has a good view on it: "On the scale of 1 to 10, this is an 11." https://www.schneier.com/blog/archiv...eartbleed.html

    Comment


      #3
      Originally posted by NickFitz View Post
      The thing is, at the moment you can't be sure all servers have been patched, which means that if you change your password now you could just be giving away the new one, whereas your existing password might never have been compromised. ...
      There ought to be a standard drill for a vulnerability like this, in that as soon as it is patched the site should direct users to a password replacement page where they are validated by their answers to a decent set of contextual questions (stored on a separate server solely for this purpose) and prompted to enter a new password.
      Work in the public sector? Read the IR35 FAQ here

      Comment


        #4
        To avoid this kind of issue I don't use passwords. Much more secure.
        "He's actually ripped" - Jared Padalecki

        https://youtu.be/l-PUnsCL590?list=PL...dNeCyi9a&t=615

        Comment


          #5
          Originally posted by MyUserName View Post
          To avoid this kind of issue I don't use passwords. Much more secure.
          So how do you log into CUK?

          Comment


            #6
            Originally posted by vwdan View Post
            So how do you log into CUK?
            SASguru

            twat

            Let us not forget EU open doors immigration benefits IT contractors more than anyone

            Comment


              #7
              Just don't use anything that's open source. Problem solved.

              Good write up of the problem:

              http://www.theregister.co.uk/2014/04...eed_explained/

              Not quite as stupid as the recent Apple bug.
              Will work inside IR35. Or for food.

              Comment


                #8
                Originally posted by vwdan View Post
                So how do you log into CUK?
                An arrogant and stubborn refusal to accept the fact I can't
                "He's actually ripped" - Jared Padalecki

                https://youtu.be/l-PUnsCL590?list=PL...dNeCyi9a&t=615

                Comment


                  #9
                  Originally posted by MyUserName View Post
                  An arrogant and stubborn refusal to accept the fact I can't
                  To be honest, I think I totally misinterpreted your first post - I thought you were making some point about alternate authentication methods.

                  Comment


                    #10
                    Originally posted by zeitghost
                    There we are, I've changed all mine from 123456 to ABCDEF.

                    Fixed.
                    AbCdEf - Sh1rLeY?

                    Comment

                    Working...
                    X