The issue has apparently been fixed but there was a period of vulnerability, which Yahoo has not specifically identified.
http://www.cnet.com …n-reveals-user-passwords/
joeblack2022 Goldmember 3,005 posts Likes: 5 Joined Sep 2011 Location: The Great White North More info | Apr 09, 2014 09:55 | #1 The issue has apparently been fixed but there was a period of vulnerability, which Yahoo has not specifically identified. Joel
LOG IN TO REPLY |
morph2_7 Goldmember 1,112 posts Joined Sep 2012 Location: Los Angeles More info | Apr 09, 2014 12:24 | #2 Thanks for the heads up. The question is has Yahoo fixed all of their servers? If we change our passwords now and they happen to hit Yahoo servers that have not had the fix, bad guys will have our new passwords.
LOG IN TO REPLY |
joeblack2022 THREAD STARTER Goldmember 3,005 posts Likes: 5 Joined Sep 2011 Location: The Great White North More info | Apr 09, 2014 12:28 | #3 morph2_7 wrote in post #16821544 ![]() The question is has Yahoo fixed all of their servers? From the article: Yahoo said just after noon PT that it fixed the primary vulnerability on its main sites: "As soon as we became aware of the issue, we began working to fix it. Our team has successfully made the appropriate corrections across the main Yahoo properties (Yahoo Homepage, Yahoo Search, Yahoo Mail, Yahoo Finance, Yahoo Sports, Yahoo Food, Yahoo Tech, Flickr, and Tumblr) and we are working to implement the fix across the rest of our sites right now. We're focused on providing the most secure experience possible for our users worldwide and are continuously working to protect our users' data." I looked on Yahoo's website but couldn't find any official statement. Joel
LOG IN TO REPLY |
morph2_7 Goldmember 1,112 posts Joined Sep 2012 Location: Los Angeles More info | Apr 09, 2014 12:32 | #4 I used this site: http://filippo.io/Heartbleed
LOG IN TO REPLY |
DGStinner Goldmember ![]() More info | Apr 09, 2014 12:50 | #5 It probably wouldn't be as much of an issue if Yahoo! implemented two factor authentication. Dave Stinner
LOG IN TO REPLY |
Michael60d Member ![]() 39 posts Joined Feb 2012 More info | Apr 09, 2014 13:23 | #6 Even if "fixed" the damage still done, existing passwords are vulnerable. Think about changing all of your passwords for each of your important "secure" internet etc. Banking or anything "sensitive" in nature. - Photographer newbie who loves his 60D and learning more about photography
LOG IN TO REPLY |
Apr 09, 2014 13:28 | #7 Michael60d wrote in post #16821700 ![]() Even if "fixed" the damage still done, existing passwords are vulnerable. Think about changing all of your passwords for each of your important "secure" internet etc. Banking or anything "sensitive" in nature. If, a site/server has still not patched, then changing your password now would still mean it's vulnerable, so probably a good idea to keep changing them for a while, or until you get the warm fuzzies again Will it still be on my computer waiting for my new passwords?
LOG IN TO REPLY |
RWJP Member ![]() 120 posts Joined Sep 2013 Location: Dorset, UK More info | Apr 10, 2014 05:31 | #8 DigitalDon wrote in post #16821710 ![]() Will it still be on my computer waiting for my new passwords? No, because it is not something that exists on your computer. This is a vulnerability in an encryption/communication method used by servers. Gear:
LOG IN TO REPLY |
Apr 10, 2014 09:04 | #9 RWJP wrote in post #16823177 ![]() No, because it is not something that exists on your computer. This is a vulnerability in an encryption/communication method used by servers. Thanks
LOG IN TO REPLY |
morph2_7 Goldmember 1,112 posts Joined Sep 2012 Location: Los Angeles More info | Apr 10, 2014 10:33 | #10 DigitalDon wrote in post #16823477 ![]() Thanks This you whos that is yahoo is about as behind times as aol (my aol has alread been hacked once,don't use it anymore) would love to drop Yahoo but my service provider bellsouth/att uses them for my main email account. I wonder if Yahoo/bellsouth/ATT is going to let me know that they have their end fixed and let me know to change my password. Yahoo is not the only one affected by this bug. There are many other websites affected by this problem. I won't worry about my Yahoo account as much as I do about my accounts at financial websites.
LOG IN TO REPLY |
Going to a website that I want to check the certificate of, I click on the lock icon next to the address bar, then clicking on View Certificates, I can see the info under the Details tab but how do I know if it has been patched?
LOG IN TO REPLY |
morph2_7 Goldmember 1,112 posts Joined Sep 2012 Location: Los Angeles More info | Apr 10, 2014 11:18 | #12 You can use the link in post #4 to check the site or ask the website support.
LOG IN TO REPLY |
Apr 10, 2014 11:27 | #13 morph2_7 wrote in post #16823792 ![]() You can use the link in post #4 to check the site or ask the website support. I tried entering in the site I wanted to check, a blue line goes across the top of the screen but does nothing else, how long should it take for it to check a site.
LOG IN TO REPLY |
morph2_7 Goldmember 1,112 posts Joined Sep 2012 Location: Los Angeles More info | Apr 10, 2014 11:33 | #14 It should be instantaneous, about 3-5 seconds. However, I've seen the problem you're experiencing (blue line goes all the way to the right and does nothing else). I guess their site isn't that reliable or too busy. It would be better if you contact the website support.
LOG IN TO REPLY |
Apr 10, 2014 11:44 | #15 morph2_7 wrote in post #16823824 ![]() It should be instantaneous, about 3-5 seconds. However, I've seen the problem you're experiencing (blue line goes all the way to the right and does nothing else). I guess their site isn't that reliable or too busy. It would be better if you contact the website support. Use to at the bottom of every website there was a link to the Web Master but I guess that is gone forever. Looked at Quicken website and my banking website and can't find anything related to asking them about a certificate update, And you know how it would be trying to talk to somebody on the phone that wouldn't have a clue as to what I was talking about.
LOG IN TO REPLY |
![]() | x 1600 |
y 1600 |
Log in Not a member yet?
Register to forums
Registered members may log in to forums and access all the features: full search, image upload, follow forums, own gear list and ratings, likes, more forums, private messaging, thread follow, notifications, own gallery, all settings, view hosted photos, own reviews, see more and do more... and all is free. Don't be a stranger - register now and start posting! |
| ||
Latest registered member is nader23 852 guests, 209 members online Simultaneous users record so far is 15144, that happened on Nov 22, 2018 |