‘Heartbleed’ puts Internet security at risk

  • Los Angeles Times
  • Wednesday, April 9, 2014 3:45pm
  • Business

SAN FRANCISCO — The discovery of a significant flaw in software that was supposed to provide extra protection for thousands of websites has thrown the tech world into chaos as experts scrambled to understand the scope of the vulnerability.

Consumers started to receive a trickle of notices from services they use online alerting them to potential issues and recommended steps, such as changing passwords. But given the scope of the issue, security experts projected that it could take years to sew up all the holes created by the Heartbleed bug.

“This is one of the worst security issues we’ve seen in the last decade and will remain within the top 5 for many years to come,” said Adam Ely, founder and chief operating officer of Bluebox Security.

Added Jeff Forristal, Bluebox chief technical officer: “OpenSSL is extremely pervasive on all manners of devices, systems and servers. It is going to take the ecosystem significant time to get everything updated, and we will be looking at a long tail situation that could easily extend into years.”

Heartbleed is a vulnerability in OpenSSL, a technology used to provide encryption of an estimated 66 percent of all servers on the public Internet. OpenSSL is an open-source code developed and maintained by a community of developers, rather than by a single company.

Although such jargon is unfamiliar to average users, most people online probably have seen the green padlock icon in the address bar of their browser, followed by “https” that indicates that the OpenSSL added security has been enabled.

The vulnerability was found separately last week by Neel Mehta, a security researcher at Google Inc., and a team of engineers at Codenomicon, a security website that has since created a site with information about Heartbleed.

On Tuesday, Tumblr, owned by Yahoo Inc., disclosed that it had been hit by Heartbleed and urged users to change not just the password for its site but for all others as well.

Signaling just how much uncertainty and confusion surrounds the glitch, security experts warned that such a gesture might actually be useless because if a site has not fixed the problem hackers could just as easily steal the new password.

“The scope of this is immense,” said Kevin Bocek, vice president of security strategy and threat intelligence for Venafi, a Salt Lake City cybersecurity company. “And the consequences are still scary. I’ve talked about this like a ‘Mad Max’ moment. It’s a bit of anarchy right now. Because we don’t know right now who has the keys and certificates on the Internet right now.”

It appears the bug was introduced into OpenSSL by a programming mistake that got pushed out as websites around the world updated their version of OpenSSL.

After the discovery last week, news spread quickly around the Web as the implications became clearer. As Tumblr made its announcement, security experts found numerous “exploits” or simple pieces of software widely available online that hackers could use to attack sites left vulnerable by Heartbleed.

By running such exploits, a hacker could in just a few seconds download countless emails, passwords, user IDs and much other personal information.

“Heartbleed is like finding a faulty car part used in nearly every make and model, but you can’t recall the Internet and all the data you put out on it,” said Jonathan Sander, vice president of research and technology for Stealthbits Technologies, a cybersecurity firm in Hawthorne, N.J.

An updated version of OpenSSL has been issued, and sites can use that to fix the bug. In addition to updating OpenSSL, sites will need to update many pieces of their security protocols.

But Internet users now face a dilemma: How do they know they can trust a site?

A website created by Filippo Valsorda, an Italian cyber security expert, promises to vet websites for safety. The tool tests websites by trying to exploit them using the Heartbleed bug, Valsorda said.

Valsorda said that he built the tool in a few hours but that he has kept working on it to improve how it works. He said the website, at http://filippo.io/Heartbleed, was being used about 7,000 times per minute Wednesday.

A check of the website Wednesday listed many popular sites as secure, including Facebook, Twitter, Gmail, Amazon and Yahoo.

Besides checking to make sure websites are secure, Valsorda recommends that users also keep an eye out for statements from their most frequented websites in case they were hacked through the Heartbleed bug.

Experts worry that hackers can use security information gathered via Heartbleed to create fake copies of real sites that will induce users to disclose more information.

“Avoid things like online banking and avoid sensitive sites if you’re not sure,” said Andrew Storms, director of DevOps at CloudPassage. “Some people will see it as overkill. But I think that’s the simplest guidance.”

What’s making the security community so nervous is just how little is known about how widely the vulnerability has been exploited to get personal and commercial information.

“This is an excellent example of vulnerabilities that exist within encryption products just waiting to be discovered,” said Lucas Zaichkowsky, enterprise defense architect for AccessData. “This particular programming error was introduced in December 2011 with OpenSSL version 1.0.1. Criminals could have been using it. Intelligence agencies like the NSA could have been exploiting it. It’s hard to say what those organizations have in their arsenal, being used quietly.”

The bug is also raising questions about the wisdom of relying on such a single standard.

“Having common technology is typically viewed as a good thing. But it can also lead to assumptions,” Sander of Stealthbits said. “People assume the parts they use are safe if everyone uses them. If deep testing isn’t being done by the good guys to make sure those parts stay safe over time, then you can be sure the bad guys will find the faults first.”

Added Mark Bower, vice president of product management and solution architecture for Voltage Security:

“Security vulnerabilities will always exist, and provide the ideal beachhead for attackers to establish the data-stealing malware infantry front line. In this case, Heartbleed’s significant data theft risk also emphasizes the need to take a different approach to data protection above and beyond SSL.”

It’s also led to a debate about the reliability of open-sourced security tools.

“This is really serious and a big blow to the credibility of open source,” said Phil Lieberman, president of Lieberman Software in Los Angeles. “This is very bad, and the consequences are very scary now that it has been disclosed. The fact that this code is on home- and commercial Internet-connected devices on a global scale means that the Internet is a different place today.”

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

(Image from Pexels.com)
The real estate pros you need to know: Top 3 realtors in Snohomish County

Buying or selling? These experts make the process a breeze!

Relax Mind & Body Massage (Photo provided by Sharon Ingrum)
Celebrating the best businesses of the year in Snohomish County.

Which local businesses made the biggest impact this year? Let’s find out.

Construction contractors add exhaust pipes for Century’s liquid metal walls at Zap Energy on Monday, Feb. 3, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Snohomish County becomes haven for green energy

Its proximity to Boeing makes the county an ideal hub for green companies.

A closing sign hangs above the entrance of the Big Lots at Evergreen and Madison on Monday, July 22, 2024, in Everett, Washington. (Ryan Berry / The Herald)
Big Lots announces it will shutter Everett and Lynnwood stores

The Marysville store will remain open for now. The retailer reported declining sales in the first quarter of the year.

George Montemor poses for a photo in front of his office in Lynnwood, Washington on Tuesday, July 30, 2024.  (Annie Barker / The Herald)
Despite high mortgage rates, Snohomish County home market still competitive

Snohomish County homes priced from $550K to $850K are pulling in multiple offers and selling quickly.

Henry M. Jackson High School’s robotic team, Jack in the Bot, shake hands at the 2024 Indiana Robotics Invitational.(Henry M. Jackson High School)
Mill Creek robotics team — Jack in the Bot — wins big

Henry M. Jackson High School students took first place at the Indiana Robotic Invitational for the second year in a row.

The computer science and robotics and artificial intelligence department faculty includes (left to right) faculty department head Allison Obourn; Dean Carey Schroyer; Ishaani Priyadarshini; ROBAI department head Sirine Maalej and Charlene Lugli. PHOTO: Arutyun Sargsyan / Edmonds College.
Edmonds College to offer 2 new four-year degree programs

The college is accepting applications for bachelor programs in computer science as well as robotics and artificial intelligence.

Rick Steves speaks at an event for his new book, On the Hippie Trail, on Thursday, Feb. 27 at Third Place Books in Lake Forest, Washington. (Will Geschke / The Herald)
Travel guru won’t slow down

Rick Steves is back to globetrotting and promoting a new book after his cancer fight.

FILE — Boeing 737 MAX8 airplanes on the assembly line at the Boeing plant in Renton, Wash., on March 27, 2019. Boeing said on Wednesday, Feb. 21, 2024, that it was shaking up the leadership in its commercial airplanes unit after a harrowing incident last month during which a piece fell off a 737 Max 9 jet in flight. (Ruth Fremson/The New York Times)
Federal judge rejects Boeing’s guilty plea related to 737 Max crashes

The plea agreement included a fine of up to $487 million and three years of probation.

Neetha Hsu practices a command with Marley, left, and Andie Holsten practices with Oshie, right, during a puppy training class at The Everett Zoom Room in Everett, Washington on Wednesday, July 3, 2024. (Annie Barker / The Herald)
Tricks of the trade: New Everett dog training gym is a people-pleaser

Everett Zoom Room offers training for puppies, dogs and their owners: “We don’t train dogs, we train the people who love them.”

Andy Bronson/ The Herald 

Everett mayor Ray Stephenson looks over the city on Tuesday, Jan. 5, 2015 in Everett, Wa. Stephanson sees  Utah’s “housing first” model – dealing with homelessness first before tackling related issues – is one Everett and Snohomish County should adopt.

Local:issuesStephanson

Shot on: 1/5/16
Economic Alliance taps former Everett mayor as CEO

Ray Stephanson will serve as the interim leader of the Snohomish County group.

Molbak's Garden + Home in Woodinville, Washington will close on Jan. 28. (Photo courtesy of Molbak's)
After tumultuous year, Molbak’s is being demolished in Woodinville

The beloved garden store closed in January. And a fundraising initiative to revitalize the space fell short.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.