recommended reading

What You Need to Know About Heartbleed, the New Security Bug Scaring the Internet

Pavel Ignatov/

What should you know about Heartbleed, a recently uncovered security bug? The shortest version: You'll have to change all of your passwords, and temporarily avoid any site that is known to be vulnerable. That sounds a bit alarmist, we know, but now that internet and security experts know a little more about the security vulnerability, it's becoming more and more clear that Heartbleed is nothing to mess with.

Tumblr users recently heard about Heartbleed thanks to a note sent out by the blogging service encouraging all of its users to change their passwords, immediately. So here's the rundown on what you need to know, and what you can do to protect yourself as much as possible from the fall-out. 

So what is it? 

Heartbleed is a security vulnerability in OpenSSL, a popular, open-source protocol used to encrypt vast portions of the web. It's used to protect your usernames, passwords, and sensitive information set on secure websites. Lifehacker, who published a great, plain-language guide to the flaw earlier today, notes that about 66 percent of the web probably uses OpenSSL to encrypt data. Security company Codenomicon  set up an entire website to handle questions about the vulnerability, although their explanation might be too in the weeds for some readers. 

At this point, some sites will be running new, fixed versions of OpenSSL and are already secure, while some may have never upgraded to the years-old version of the protocol that contains the vulnerability in the first place. There are a few tools out there you can use to test whether a site is vulnerable to this flaw. And here's an incomplete list of sites that are indicating they are vulnerable, including Yahoo. A sample: 


How does it work? 

The Verge has a very good explanation, so we'll quote them: 

The bug allows an attacker to pull 64k at random from a given server's working memory. It's a bit like fishing — attackers don't know what usable data will be in the haul — but since it can be performed over and over again, there's the potential for a lot of sensitive data to be exposed. The server's private encryption keys are a particular target, since they're necessarily kept in working memory and are easily identifiable among the data. That would allow attackers to eavesdrop on traffic to and from the service, and potentially decrypt any past traffic that had been stored in encrypted form.

In other words, someone could simply pull small bits of data from a server, over and over, until gaining the private keys needed to read all of the information that's there. That's potentially disastrous for both the companies and their users, for reasons that should not need any explaining. 

What do I do? What do I do? 

Do you Yahoo? Do you use your Yahoo password on other sites? That password was possibly compromised by the security bug, and you'll have to change it once the bug is fixed. But because each system administrator has to manually fix the problem, which takes time, there's really nothing you can do until the compromised sites are up and running with an updated version of OpenSSL, and a new security certificate in place — a "reset" of the encryption used to protect current and archived information on the server going forward. Yahoo is working on a fix, but isn't there yet with all of its properties. Each site affected will have to do the same. Until then, stay away from those sites. It could take days, or longer, for vulnerable sites to recover from the bug.

Flair for drama? Take Tor's advice on Heartbleed: "If you need strong anonymity or privacy on the Internet, you might want to stay away from the Internet entirely for the next few days while things settle." 

In any case, its worth noting that even the best fixes to Heartbleed won't completely secure all past web traffic from vulnerability. And, because individual servers have to be fixed manually, some sites might not get around to repairing the bug for quite awhile. In other words, take Heartbleed on a site-by-site basis. Very few sites have offered comprehensive information on what to do about Heartbleed to its users. One would hope that advice will be coming soon.

Who would want to exploit Heartbleed? 

You know, anyone with basic programming skills who might want some sensitive user data at their finger tips. Or, as many have suggested, there are some government agencies known to have a fondness for collecting user information and web traffic in bulk. If they knew about it before its exposure, Heartbleed could have been a big Christmas present to those efforts. 

(Image via Pavel Ignatov/

Threatwatch Alert

Stolen credentials

14M University Email Accounts for Sale on Dark Web

See threatwatch report


Close [ x ] More from Nextgov

Thank you for subscribing to newsletters from
We think these reports might interest you:

  • It’s Time for the Federal Government to Embrace Wireless and Mobility

    The United States has turned a corner on the adoption of mobile phones, tablets and other smart devices, outpacing traditional desktop and laptop sales by a wide margin. This issue brief discusses the state of wireless and mobility in federal government and outlines why now is the time to embrace these technologies in government.

  • Featured Content from RSA Conference: Dissed by NIST

    Learn more about the latest draft of the U.S. National Institute of Standards and Technology guidance document on authentication and lifecycle management.

  • A New Security Architecture for Federal Networks

    Federal government networks are under constant attack, and the number of those attacks is increasing. This issue brief discusses today's threats and a new model for the future.

  • Going Agile:Revolutionizing Federal Digital Services Delivery

    Here’s one indication that times have changed: Harriet Tubman is going to be the next face of the twenty dollar bill. Another sign of change? The way in which the federal government arrived at that decision.

  • Software-Defined Networking

    So many demands are being placed on federal information technology networks, which must handle vast amounts of data, accommodate voice and video, and cope with a multitude of highly connected devices while keeping government information secure from cyber threats. This issue brief discusses the state of SDN in the federal government and the path forward.

  • The New IP: Moving Government Agencies Toward the Network of The Future

    Federal IT managers are looking to modernize legacy network infrastructures that are taxed by growing demands from mobile devices, video, vast amounts of data, and more. This issue brief discusses the federal government network landscape, as well as market, financial force drivers for network modernization.


When you download a report, your information may be shared with the underwriters of that document.