{"id":64196,"date":"2014-04-08T19:31:12","date_gmt":"2014-04-08T17:31:12","guid":{"rendered":"http:\/\/onsoftware.en.softonic.com\/?p=64196"},"modified":"2025-07-02T00:46:05","modified_gmt":"2025-07-02T07:46:05","slug":"heartbleed-openssl-security-bug","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/heartbleed-openssl-security-bug\/","title":{"rendered":"&#8220;Heartbleed&#8221; security bug leaves majority of the web vulnerable"},"content":{"rendered":"<p>A major <a title=\"Security tag\" href=\"http:\/\/news.en.softonic.com\/t\/security\" target=\"_self\" rel=\"noopener noreferrer\">security<\/a> flaw called Heartbleed was discovered today by security researchers. OpenSSL, the open-source encryption software library, has a massive bug that affects a majority of the web. The bug allows hackers to uncover personal information without being detected.<\/p>\n<p>It&#8217;s a complex security issue but I&#8217;ll try to keep it as simple as possible. Heartbleed is going to be an ongoing issue and you should take precautions to protect yourself.<\/p>\n<h3>What is OpenSSL?<\/h3>\n<p>OpenSSL is an open-source cryptographic library that <strong>helps secure web traffic<\/strong>. It protects information like usernames, passwords, and other information from being eavesdropped by hackers.<\/p>\n<p>By using OpenSSL, users can be certain that they are contacting the site they intend to and that information exchanged with the site is secure.<\/p>\n<h3>What is the Heartbleed bug?<\/h3>\n<p>Heartbleed is the code name for the bug that was discovered in OpenSSL. The bug has <strong>been around for over two years<\/strong> but wasn&#8217;t discovered until now.<\/p>\n<p>The vulnerability compromises the secret keys OpenSSL exchanges with users to encrypt traffic. If a hacker is eavesdropping on a compromised connection, usernames and passwords will allow them to <strong>impersonate you<\/strong>.<\/p>\n<p>The scariest part is that Heartbleed doesn&#8217;t let sites and services know if they are compromised or have been compromised in the past. This means your information could have been stolen but you would never know.<\/p>\n<h3>Which websites and services are affected?<\/h3>\n<p>Over <strong>66% of the web uses OpenSSL<\/strong> so tons of sites are affected. <strong>Yahoo!, Imgur, and OkCupid<\/strong> are just a few major sites that are affected. There&#8217;s a master list of affected sites at <a title=\"GitHub Heartbleed master list\" href=\"https:\/\/github.com\/musalbas\/heartbleed-masstest\/blob\/master\/top1000.txt\" target=\"_blank\" rel=\"noopener noreferrer\">GitHub<\/a> if you want to check which sites you visit are vulnerable.<\/p>\n<p>Many sites have begun patching their the bug but it may be too late. The bug has been around for two years and <strong>your information may already be exposed<\/strong>.<\/p>\n<h3>What can I do to protect myself?<\/h3>\n<p>Not much, unfortunately. Since OpenSSL is implemented by websites and services, it&#8217;s up to them to patch the bug.<\/p>\n<p>If you can, avoid going to the sites that are listed on Github&#8217;s master list. <strong>Changing your passwords on those sites won&#8217;t help until they&#8217;ve fixed the bug<\/strong>. Wait until the site has patched Heartbleed before changing your password.<\/p>\n<p>If a site isn&#8217;t listed, you can change your password anyway just to be safe.<\/p>\n<p>All you can do now is wait for sites to patch the bug. It&#8217;s a good time to check any suspicious activity on your accounts as well.<\/p>\n<p>Always enable <a title=\"Guide to using two-step verification\" href=\"http:\/\/features.en.softonic.com\/guide-to-using-two-step-verification\" target=\"_self\" rel=\"noopener noreferrer\">two-factor authentication<\/a> when possible and <strong>use unique passwords<\/strong> for each site and service you sign up for. Password lockers like <a title=\"1Password for Windows\" href=\"http:\/\/1password.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">1Password<\/a> and <a title=\"LastPass for Windows\" href=\"http:\/\/en.softonic.com\/s\/lastpass\" target=\"_self\" rel=\"noopener noreferrer\">LastPass<\/a> are great options to generate and keep track of all your passwords.<\/p>\n<p><em>Source: <a title=\"Heartbleed.com\" href=\"http:\/\/heartbleed.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Heartbleed.com<\/a> | <a title=\"GitHub\" href=\"https:\/\/github.com\/musalbas\/heartbleed-masstest\" target=\"_blank\" rel=\"noopener noreferrer\">GitHub<\/a> | <a title=\"OpenSSL FAQ\" href=\"https:\/\/www.openssl.org\/support\/faq.html\" target=\"_blank\" rel=\"noopener noreferrer\">OpenSSL<\/a><\/em><\/p>\n<p><em>Via: <a title=\"Lifehacker\" href=\"http:\/\/lifehacker.com\/what-the-heartbleed-security-bug-means-for-you-1560801201\" target=\"_blank\" rel=\"noopener noreferrer\">Lifehacker<\/a><\/em><\/p>\n<h4>RELATED STORIES<\/p>\n<ul>\n<li><a href=\"http:\/\/news.en.softonic.com\/virus-shield-scam-app-rose-to-1-in-google-play-before-discovery\" target=\"_self\" rel=\"noopener noreferrer\">Virus Shield scam app rose to #1 in Google Play before discovery<\/a><\/li>\n<li><a href=\"http:\/\/features.en.softonic.com\/keep-using-xp-after-support-ends\" target=\"_self\" rel=\"noopener noreferrer\">How to keep using XP after support ends<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/firechat-for-android\" target=\"_self\" rel=\"noopener noreferrer\">Anonymous off-the-grid messaging app FireChat comes to Android<\/a><\/li>\n<\/ul>\n<\/h4>\n","protected":false},"excerpt":{"rendered":"<p>A major security flaw called Heartbleed was discovered today by security researchers. OpenSSL, the open-source encryption software library, has a massive bug that affects a majority of the web. The bug allows hackers to uncover personal information without being detected. It&#8217;s a complex security issue but I&#8217;ll try to keep it as simple as possible. &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/heartbleed-openssl-security-bug\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;&#8220;Heartbleed&#8221; security bug leaves majority of the web vulnerable&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2033,"featured_media":64200,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":3},"categories":[2441],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-64196","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-how-to"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/64196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/2033"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=64196"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/64196\/revisions"}],"predecessor-version":[{"id":330980,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/64196\/revisions\/330980"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/64200"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=64196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=64196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=64196"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=64196"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=64196"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=64196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}