{"id":64563,"date":"2014-04-11T22:34:06","date_gmt":"2014-04-11T20:34:06","guid":{"rendered":"http:\/\/onsoftware.en.softonic.com\/?p=64563"},"modified":"2025-07-02T00:45:35","modified_gmt":"2025-07-02T07:45:35","slug":"heartbeat-bug-exaggeration","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/heartbeat-bug-exaggeration\/","title":{"rendered":"Are the dangers of the Heartbleed vulnerability exaggerated?"},"content":{"rendered":"<p>News of the <a title=\"&quot;Heartbleed&quot; security bug leaves majority of the web vulnerable\" href=\"http:\/\/news.en.softonic.com\/heartbleed-openssl-security-bug\" target=\"_self\" rel=\"noopener noreferrer\">Heartbleed<\/a> security vulnerability have spread like wildfire. According to Netcraft, an internet service company, 66% of the web is vulnerable because of Heartbleed. But are these figures overblown?<\/p>\n<p>Today, content delivery network CloudFlare <a title=\"Answering the Critical Question: Can You Get Private SSL Keys Using Heartbleed?\" href=\"http:\/\/blog.cloudflare.com\/answering-the-critical-question-can-you-get-private-ssl-keys-using-heartbleed\" target=\"_blank\" rel=\"noopener noreferrer\">released a report<\/a> that shows the difficulty of exploiting web servers using Heartbleed. The company found that there have been <strong>no verified reports of the theft of private keys<\/strong>.<\/p>\n<p>CloudFlare received early notice of the Heartbleed vulnerability and patched its own servers twelve days ago. It then began testing to see if it was possible to use Heartbleed to exploit its own services. &#8220;After extensive testing on our software stack, we have been unable to successfully use Heartbleed on a vulnerable server to retrieve any private key data,&#8221; wrote CloudFlare software engineer Nicholas Sullivan.<\/p>\n<p>While the company says it could not exploit a vulnerable server, it <strong>does not rule out the possibility of an attack<\/strong>. CloudFlare does not &#8220;feel comfortable&#8221; saying the exploit won&#8217;t work but instead says it would be &#8220;very hard&#8221; to achieve. The company has set up a <a title=\"CloudFlare challenge page\" href=\"https:\/\/www.cloudflarechallenge.com\/heartbleed\" target=\"_blank\" rel=\"noopener noreferrer\">challenge<\/a> for security researchers and hackers to exploit a vulnerable page using the Heartbleed bug.<\/p>\n<p>Netcraft also followed up its initial report about 66% of the web being vulnerable. Of the 66% of the web using OpenSSL, <strong>only 17.5% of those sites actually use the Heartbleed extension<\/strong>. &#8220;Not all of these servers are running an HTTPS service, nor are they all running vulnerable versions of OpenSSL with heartbeats enabled,&#8221; writes web security tester <a title=\"Paul Mutton Twitter\" href=\"https:\/\/twitter.com\/paulmutton\" target=\"_blank\" rel=\"noopener noreferrer\">Paul Mutton<\/a>.<\/p>\n<p>Web administrators are not taking any chances and are reissuing security certificates and updating to patched versions of OpenSSL. Companies like Soundcloud are <a title=\"Soundcloud signs out users in wake of Heartbleed bug\" href=\"http:\/\/news.en.softonic.com\/soundcloud-heartbleed-bug-fix\" target=\"_self\" rel=\"noopener noreferrer\">signing users out<\/a> to make sure the fixes get implemented. If you find yourself logged out of some sites and services, it&#8217;s probably because of these updates.<\/p>\n<p>It&#8217;s too soon to say whether Heartbleed is as big of an issue as the media is portraying it to be. If anything, it serves as a <strong>wake-up call<\/strong> for companies and consumers to stay on top of security. Companies need to invest in better security and consumers need to start educating themselves.<\/p>\n<p>Always use <strong>unique passwords<\/strong> for every website and service you sign up for. If your user name and password are exposed on one site, unique passwords prevent hackers from gaining access to your other accounts. Password lockers like <a title=\"LastPass for Windows\" href=\"http:\/\/lastpass.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">LastPass<\/a>, <a title=\"1Password for Windows\" href=\"http:\/\/1password.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">1Password<\/a>, and <a title=\"KeePass for Windows\" href=\"http:\/\/keepass.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">KeePass<\/a> are great ways to store your passwords securely.<\/p>\n<p>Enable <a title=\"Guide to two-factor authentication\" href=\"http:\/\/features.en.softonic.com\/guide-to-using-two-step-verification\" target=\"_self\" rel=\"noopener noreferrer\">two-factor authentication<\/a> on every site and service that offers it. Google, Facebook, and Twitter all support two-factor authentication. If a site or service doesn&#8217;t support it, write to the company to request the feature.<\/p>\n<p>For more about the Heartbleed bug, check out our coverage below.<\/p>\n<p><em>Source: <a title=\"CloudFlare\" href=\"http:\/\/blog.cloudflare.com\/answering-the-critical-question-can-you-get-private-ssl-keys-using-heartbleed\" target=\"_blank\" rel=\"noopener noreferrer\">CloudFlare<\/a> | <a title=\"Netcraft\" href=\"http:\/\/news.netcraft.com\/archives\/2014\/04\/08\/half-a-million-widely-trusted-websites-vulnerable-to-heartbleed-bug.html\" target=\"_blank\" rel=\"noopener noreferrer\">Netcraft<\/a> | <a title=\"Heartbleed\" href=\"http:\/\/heartbleed.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Heartbleed<\/a><\/em><\/p>\n<p><em>Via: <a title=\"The Verge\" href=\"http:\/\/www.theverge.com\/2014\/4\/11\/5604300\/heartbleed-may-not-leak-private-ssl-keys-after-all\" target=\"_blank\" rel=\"noopener noreferrer\">The Verge<\/a><\/em><\/p>\n<h4>MORE ON THE HEARTBLEED VULNERABILITY<\/p>\n<ul>\n<li><a href=\"http:\/\/features.en.softonic.com\/heartbleed-five-steps-to-protect-your-account\" target=\"_self\" rel=\"noopener noreferrer\">Heartbleed: five steps to protect your accounts<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/the-softonic-minute-heartbleed-twitter-facebook-and-windows-xp\" target=\"_self\" rel=\"noopener noreferrer\">The Softonic Minute: Heartbleed, Twitter, Facebook and Windows XP<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/apple-not-affected-by-heartbleed-bug\" target=\"_self\" rel=\"noopener noreferrer\">Apple claims it was not affected by Heartbleed security bug<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/soundcloud-heartbleed-bug-fix\" target=\"_self\" rel=\"noopener noreferrer\">Soundcloud signs out users in wake of Heartbleed bug<\/a><\/li>\n<li>&#8220;<a href=\"http:\/\/news.en.softonic.com\/heartbleed-openssl-security-bug\" target=\"_self\" rel=\"noopener noreferrer\">Heartbleed&#8221; security bug leaves majority of the web vulnerable<\/a><\/li>\n<\/ul>\n<\/h4>\n","protected":false},"excerpt":{"rendered":"<p>News of the Heartbleed security vulnerability have spread like wildfire. According to Netcraft, an internet service company, 66% of the web is vulnerable because of Heartbleed. But are these figures overblown? Today, content delivery network CloudFlare released a report that shows the difficulty of exploiting web servers using Heartbleed. The company found that there have &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/heartbeat-bug-exaggeration\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Are the dangers of the Heartbleed vulnerability exaggerated?&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2033,"featured_media":64571,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-64563","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/64563","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/2033"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=64563"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/64563\/revisions"}],"predecessor-version":[{"id":330953,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/64563\/revisions\/330953"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/64571"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=64563"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=64563"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=64563"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=64563"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=64563"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=64563"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}