Jump to content

  • Log In with Google      Sign In   
  • Create Account

Photo

--OFFTOPIC-- CHANGE YOUR PASSWORDS, NOW!


  • Please log in to reply
29 replies to this topic

#1 sloosecannon

sloosecannon

    Admin - I code stuff

  • Administrators
  • 2,468 posts
  • Steam:sloosecannon
  • LocationThis dimension (right now...)

Posted 09 April 2014 - 08:09 AM

This is not mod related, but is important enough to warrant a news post.
 
 Two days ago, CVE-2014-0160 was reported to the world. This is a bug in the OpenSSL encryption library, allowing a malicious user to read memory and compromise the entire TLS encryption standard. Any web server using OpenSSL, including servers running on two of the most popular web platforms, Apache and Nginix, may have their private keys and server memory disclosed.

This means your username, password, and any other information passed between you and the server IS VULNERABLE. This bug includes Facebook, Google, and other major providers.
 
Here's what you (non-server users) need to do:

  • Test every site you use with this tool: http://filippo.io/Heartbleed

  • If it's safe, change your password!

  • If not, assume anything you've done and anything you will do on that site is compromised until they fix it. DO NOT CHANGE YOUR PASSWORD ON THESE SITES UNTIL THEY'VE FIXED THE VULNERABILITY!

Another good piece of advice is to STAY AWAY from any public wifi hotspots for a while, until this bug is fixed in a majority of sites.

 
A bit of background information:
 
This bug abuses the "TLS heartbeat" function, allowing for a malicious packet to force the server to read random memory off the stack. This renders anything stored in memory, including passwords, private keys, user sessions, etc, completely vulnerable.
 
More info: 
http://www.cnn.com/2...tbleed-openssl/
http://heartbleed.com/
  • Unikraken likes this
#define true false
//happy debugging suckers!!!!!

Notable SOTP forum/Steam chat quotes:

Spoiler

Donate to the forum! https://kd8rho.net/donate

#2 Unikraken

Unikraken

    친애하는 지도자

  • Administrators
  • 2,910 posts
  • Steam:Unikraken
  • LocationNew Mexico

Posted 09 April 2014 - 08:23 AM


  • HTRK74JR likes this

[10:46:02 PM] VDNKh: Piercing Lance
[10:46:11 PM] VDNKh: fitting name for the ship that just fucked me

 

"Unikraken can soothe any nasties."


#3 SPECTRE

SPECTRE

    Banned user who criticised terrorists

  • Members
  • 3,455 posts
  • LocationANGLIA BRUV, HOME TO THE PRODIGY, NON CRIMINAL GANGSTAS AND FARMERS

Posted 09 April 2014 - 09:02 AM

I have no idea what the hell you're on about. Non server users? My password?

I'm back (temp)

Spoiler

#4 Moustachio86

Moustachio86

    UniMinion

  • Contributor
  • 1,360 posts

Posted 09 April 2014 - 09:06 AM

I'm with SPECTRE. It feels like there's a missing paragraph here. I don't understand what's wrong.

#5 Unikraken

Unikraken

    친애하는 지도자

  • Administrators
  • 2,910 posts
  • Steam:Unikraken
  • LocationNew Mexico

Posted 09 April 2014 - 09:09 AM

I'm with SPECTRE. It feels like there's a missing paragraph here. I don't understand what's wrong.

A load of websites you probably use have a vulnerability in them that allows hackers to see stuff like usernames and passwords. Change your passwords on sites that you share passwords with sites that have this vulnerability, but don't change them on the sites with those vulnerabilities, because then you're just giving hackers your new passwords. This isn't about SotP, this is sloose being a bro warning you, his friends.


  • wafflecommander likes this

[10:46:02 PM] VDNKh: Piercing Lance
[10:46:11 PM] VDNKh: fitting name for the ship that just fucked me

 

"Unikraken can soothe any nasties."


#6 Moustachio86

Moustachio86

    UniMinion

  • Contributor
  • 1,360 posts

Posted 09 April 2014 - 09:10 AM

Right, got you! Now, just to remember all the sites I have passwords on. Doesn't Chrome have a function for this?

#7 SPECTRE

SPECTRE

    Banned user who criticised terrorists

  • Members
  • 3,455 posts
  • LocationANGLIA BRUV, HOME TO THE PRODIGY, NON CRIMINAL GANGSTAS AND FARMERS

Posted 09 April 2014 - 09:25 AM

Meh fuckit, I have a ghost thing anyway. (How that for a coincident)

I'm back (temp)

Spoiler

#8 D4RKST0RM99

D4RKST0RM99

    There's a DarkStorm coming Mr. Canadaman...

  • Authorized Playtester
  • 961 posts
  • LocationScotland

Posted 09 April 2014 - 10:28 AM

Meh fuckit, I have a ghost thing anyway. (How that for a coincident)

Covenant or supernatural type, also if covenant- how many miles to the galon on one of those things?



#9 SPECTRE

SPECTRE

    Banned user who criticised terrorists

  • Members
  • 3,455 posts
  • LocationANGLIA BRUV, HOME TO THE PRODIGY, NON CRIMINAL GANGSTAS AND FARMERS

Posted 09 April 2014 - 10:36 AM

Covenant or supernatural type, also if covenant- how many miles to the galon on one of those things?


No like a software thing, I'm patched (permanently) into the internet via the MOD.

I'm back (temp)

Spoiler

#10 Crisiss

Crisiss

    Trap Lord

  • Authorized Playtester
  • 2,340 posts
  • LocationTrap House

Posted 09 April 2014 - 11:42 AM

So what exactly do they have access to? My account on this? Frankly I don't have any personal information on this account, maybe my email at the most. I normally surf on my phone anyways, does that change anything? Thanks for the notification guys.

Nothing happens to anybody which he is not fitted by nature to bear - Marcus Aurelius

Spoiler

Spoiler

#11 sloosecannon

sloosecannon

    Admin - I code stuff

  • Administrators
  • 2,468 posts
  • Steam:sloosecannon
  • LocationThis dimension (right now...)

Posted 09 April 2014 - 11:55 AM

So what exactly do they have access to? My account on this? Frankly I don't have any personal information on this account, maybe my email at the most. I normally surf on my phone anyways, does that change anything? Thanks for the notification guys.


Nah this is an across-the-board warning. Our site isn't actually affected - this is only for secure (https) sites.
#define true false
//happy debugging suckers!!!!!

Notable SOTP forum/Steam chat quotes:

Spoiler

Donate to the forum! https://kd8rho.net/donate

#12 SternuS

SternuS

    Playtester of the poor

  • Authorized Playtester
  • 2,806 posts
  • Steam:SternuS
  • LocationItaly

Posted 09 April 2014 - 01:28 PM

How do I know which sites should I test? What in the name of the Almighty is happening?


c048b5cb018d634cb3a0d9bd3617eb50-d547q01

Peter Jackson, 27/07/2013: 1.08 am. A 20 hour day ... 15 years of Tolkien ... 771 days of shooting ...

"We would be fools to pursue the impossible simply because you believe the achievable is flawed" - Ugin

 


#13 Zero

Zero

    HHF Lead Dev

  • Contributor
  • 1,808 posts
  • LocationKent, Washington, USA

Posted 09 April 2014 - 01:29 PM

BECU is fine, glad my bank account hasn't been compromised with all that dough... (3Gs)


qqpudUa.gif

Spoiler

Spoiler


#14 Mrbump

Mrbump

    Crewman

  • Members
  • 167 posts
  • LocationUnited kingdom

Posted 09 April 2014 - 01:47 PM

Does somebody mind putting that technobabble into leymans terms please? Thanks :)



#15 sloosecannon

sloosecannon

    Admin - I code stuff

  • Administrators
  • 2,468 posts
  • Steam:sloosecannon
  • LocationThis dimension (right now...)

Posted 09 April 2014 - 02:51 PM

Basically, assume any https site you connect to is compromised. Even if the problem is fixed now, your passwords are possibly vulnerable.
That's the problem with this - we don't know what sites have been hit, only what sites might have been hit.
#define true false
//happy debugging suckers!!!!!

Notable SOTP forum/Steam chat quotes:

Spoiler

Donate to the forum! https://kd8rho.net/donate

#16 Zero

Zero

    HHF Lead Dev

  • Contributor
  • 1,808 posts
  • LocationKent, Washington, USA

Posted 09 April 2014 - 03:16 PM

If someone steals my money, the bank owes me. :(


qqpudUa.gif

Spoiler

Spoiler


#17 psdt

psdt

    Crewman

  • Members
  • 107 posts
  • LocationNM

Posted 09 April 2014 - 05:56 PM

So this problem has been fixed, correct? It seems to me that any password changing would be quite futile unless this has been fixed.



#18 Unikraken

Unikraken

    친애하는 지도자

  • Administrators
  • 2,910 posts
  • Steam:Unikraken
  • LocationNew Mexico

Posted 09 April 2014 - 06:02 PM

Reread mystatement.


[10:46:02 PM] VDNKh: Piercing Lance
[10:46:11 PM] VDNKh: fitting name for the ship that just fucked me

 

"Unikraken can soothe any nasties."


#19 Eliteempire

Eliteempire

    The Mouth Breather

  • Members
  • 198 posts

Posted 09 April 2014 - 08:27 PM

This is just another thing made like the Sixton [sp] Virus unleashed in the middle against Iran's nuclear program.


Sins of the Prophet's Let's Player - UNSC play through

 

 

http://www.youtube.c...h?v=z31qnK9A6Ns Part 1

http://www.youtube.c...h?v=36Fxu7LQ-gE Part 2

http://www.youtube.c...h?v=GvGB87lwebg Part 3

http://www.youtube.c...h?v=QWpYkrVkiuI Part 4

 

Sins of the Prophet's Let's Player - Covenant play through coming soon


#20 Zero

Zero

    HHF Lead Dev

  • Contributor
  • 1,808 posts
  • LocationKent, Washington, USA

Posted 10 April 2014 - 12:28 AM

If everyone gives me their passwords right now I'll keep them more secret than a 12 year old school girl losing her virginity to the elementary school gym teacher.


  • Unikraken likes this

qqpudUa.gif

Spoiler

Spoiler





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users