ADD Forums - Attention Deficit Hyperactivity Disorder Support and Information Resources Community

ADD Forums - Attention Deficit Hyperactivity Disorder Support and Information Resources Community (http://www.addforums.com/forums/index.php)
-   Site News, Information & Events (http://www.addforums.com/forums/forumdisplay.php?f=15)
-   -   Does Heartbleed affect the add forums? (http://www.addforums.com/forums/showthread.php?t=160678)

Greengrasshoppe 04-12-14 10:33 PM

Does Heartbleed affect the add forums?
 
http://www.cnet.com/news/heartbleed-...d-to-know-faq/

namazu 04-12-14 10:45 PM

Re: Does Heartbleed affect the add forums?
 
No. The forum does not use OpenSSL and thus isn't affected.

(You can tell because the address starts with "http" rather than "https".)

On the other hand, this means that server traffic didn't have that extra encryption (SSL = secure sockets layer) to begin with.

But in any case, ADDF isn't vulnerable to the Heartbleed issue.

tryn-optmsm 04-12-14 11:47 PM

Re: Does Heartbleed affect the add forums?
 
Pinterst isn't https; they emailed me to change my password due to heartbleed + so did other sites that are faaaar from https ssl encrypted

namazu 04-13-14 12:15 AM

Re: Does Heartbleed affect the add forums?
 
As far as I understand things (which isn't all that far), Heartbleed only affects sites using OpenSSL -- and not all versions of OpenSSL, just 1.0.1 and 1.0.2-beta.

Sites that did not use these versions of OpenSSL were not vulnerable. (See "Heartbleed: Serious OpenSSL zero day vulnerability revealed".)

It's possible -- and I'm speculating here -- that
a) some sites may use OpenSSL behind the scenes in some way that leads to password vulnerability, and/or
b) because many people reuse passwords across multiple websites, they figured compromised passwords could be a problem, and recommended changing passwords to cover this possibility.

Pinterest does have HTTPS enabled; at least, https : // pinterest.com takes you to the site. There is no https : // addforums.com.

Finally, it's possible I could be wrong on this -- in which case I hope someone more knowledgeable will come along and set the record straight. But it's my understanding that only OpenSSL-encrypted sites are at risk.

Fortune 04-13-14 12:47 AM

Re: Does Heartbleed affect the add forums?
 
If you use the same password here that you use anywhere else, it's still a good idea to change your password. The heartbleed bug/exploit was so wide ranging that it may be safest just to change all passwords just to be sure.

ginniebean 04-13-14 01:23 AM

Re: Does Heartbleed affect the add forums?
 
Change my passwords well crap.

Fortune 04-13-14 01:30 AM

Re: Does Heartbleed affect the add forums?
 
Quote:

Originally Posted by ginniebean (Post 1637050)
Change my passwords well crap.

Despite what I posted, this is exactly how I feel.

mctavish23 05-12-14 11:06 PM

Re: Does Heartbleed affect the add forums?
 
Dammitt!!!! I thought this was going to be about sappy emotions :doh: :mad:

But Noooooo :eyebrow:

u r welcome :cool:


All times are GMT -4. The time now is 05:45 PM.

Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2018, Jelsoft Enterprises Ltd.
(c) 2003 - 2015 ADD Forums