Time to change those passwords...

Bleeding Heart Jelly
Bleeding Heart Jelly
Bleeding Heart Jelly




A new bug has been discovered on the internet, called the Heartbleed Bug. The basic idea is that it allowed hackers to steal information from servers that you thought were protected behind a secure (https) connection. That information could include usernames, passwords, credit card information, or anything that you've submitted in a form. Over 2/3 of the servers on the internet use OpenSSL which is the library that this bug was found in.



Subeta is safe. We're fortunate to be protected by cloudflare who was alerted to this bug a week before it became public, and has already patched it. It's very unlikely that any of your information has been stolen from Subeta.



Unfortunately there are a lot of sites that hadn't fixed their implemention of openSSL when the information was made public. This includes some google services, yahoo mail, imgur, and other sites that most of us use daily.



It's our suggestion that you change your passwords everywhere, including Subeta. Before you change your password on a website, check it here to ensure that it's no longer a threat. If you change your password and the site is still unsafe, you could be submitting your password to hackers again!



OpenSSL put out a patch as soon as the bug was made public, and most sites have already begun to patch and fix their servers. Most major sites on the internet have already been patched. You can read more about the bug here. Thank you, and stay safe on the internet! :heart:



Here is another great writeup of this bug.
User Avatar: 1

Posted by Keith

MOKONA

*sigh* So many passwords to change. But about time too anyway, haven't edited them in a while...

Thank you for us about it Keith! :D:D
0

Bliss

Thanks for the heads up!
0

Wings_In_Poetry

Thanks so much for this!
0

Rii

I saw that on Facebook...already changing my gmail passwords. I was worried about Subeta but I'm glad to know it's already patched. Just gotta think of a unique password to replace the old one I won't forget...

Thanks for the reminder!
0

DarkVixen28

I don't even know all what sites I belong to anymore...o.O'
New goal! To keep a little account journal squirreled away somewhere so I know what accounts I have when things like this happen.
0

bulleta

Luckily I don't visit a lot of sites
My mom, however, is online shopping queen
fucking shit
0

pumpkins

For Chromeusers, there's also the Chromebleed extension that you can get, which warns you if a site you've visited has been affected :)
0

Sianach

Thanks for letting us know, Keith. I'm really grateful that you take the time to do this for us. (:
0

LOUD

Thank you for the infos.
0

Rowan

Thanks for the reminder bro.
0

Sneaky

I don't really want to change my passwords cause I'll most likely forget...most of the sites I use are apparently safe anyway...
0

The_Rasmus

Thank you so much for letting us know!!
0

Lyric

After reading conflicting posts from users can we get an official update clarifying the changing of passwords or waiting?
0

lull

Thank you Keith. I'd never know bout stuff like this if you didn't bring it to our attention *hugs*
0

wild_jester

O_O thank you for this info
0

Jibrille

Wow o.o thanks for the heads up. It will take... a few weeks at least for me to remember all the sites I have accounts on o_O It must be over 100, and some I haven't logged into in months or years. I guess a lot of those aren't really important so if they get hacked, hopefully there aren't really bad consequences.
0

Takks

Thanks for letting us know!
0

Eiji

Thank you very much for the information, Keith!
0

Iridescent

I hadn't even heard about this. crazy
0

L0stS0ul

I heared on the radio that the leak has been existing for the past two years.
So I dunno, if hackers wanted to steal anything, they had two years to do it
0

Finnie

@Noelle & FCOD

I believe if a website is listed as "no SSL" it means it's using a different protocol other than SSL for its server security.
0

operationivy

Bad, bad news for everyone of course. I changed my password here and I'm changing all my passwords and other information all over the internet.
0

BULLET

I appreciate the warning and update. :)
0

Noelle

Silly question. If a site says it has no SSL does that mean it is vulnerable and that I should still change my password on those particular sites?
0

Chef

Thank you for this. I was going back and forth as to if I wanted to change everything, which is A LOT, and after reading this, I'm working on doing that right now!
0

Kilala

Thank you so much for this information, Keith! I am about to change every single PW I have on all the sites I visit, which thankfully isn't too many XD.
0

TJPanda

Thank you Keith for the update. I'm glad to hear the site is safe.
I wasn't aware of what was going on until I saw this news post ^_^.
0

8=8

Thanks for the headsup :heart:
0

LunaWolf

Thank you for the notice, I was wondering why in the last week i have been having a major issue on my laptop and had to keep running scans and cleaning up daily
0

FCoD

Just a question that I don't understand, using @Jazzy's link to the list of sites what about the ones that say no SSL, are they vulnerable or not?

Sorry if that seems dumb. :)

Also thanks for the heads up.
0

Targaryen

Thanks for telling us and where to check! Glad Yahoo and Google is patched!
0

Alenwen

I heard this on the radio yesterday D;
Thanks for providing all the information!
0

amethyst227

Thank you so much for the info.
0

Shamte

Thanks so much for notifying us! I had no idea this was even happening. ):
0

QueenOfImladris

Well...just changed all the main ones, I'll do the rest as I remember them.
I'm on so many sites (a lot of which I don't even visit monthly, let alone daily) that it'd be impossible to do them all in one evening.
<_<
Thanks for that link to test the sites, it'd suck changing it just to have to change it again days later.
0

Anberlin

It's really good to see so many sites taking this seriously.
0

techn0witch

Virus, check using the link provided. :u
0

Zay

Thanks for letting everyone know, I know there were at least a few users who weren't aware of the situation!
Thank you for keeping everyone in the loop!
0

foxette

This is scary stuff. Bravo Subeta for being on top of it!
0

Damon

Does anyone know if paypal is safe?
0

Pagan

I continue to be impressed and more impressed by Subeta's proactive ethics and communications. Thank you all. Feeling safe, and feeling like someone is keeping an eye on these issues and promptly and clearly addressing them is such a pleasant change for me!
0

honey_bear

@Finnie Ah, ok. Thanks for the clarification. Appreciate it :). And thanks @Keith for posting about this. :)
0

azazel

Thanks for alerting people about this. I'm sure there were/are quite a few who were not aware.
0

Lisa

Okay, changed everything. Except my Apple/iTunes password...should I change that one too? I don't know if that would be included...
0

Durandal

That's hella scary.
Thank you so much for warning the people who weren't aware of this, I really appreciate it.
0

Sirensong

I've been following this story too and was very pleased too see that when I checked Subeta was listed as safe. The site my hubby spends all his time on isn't.
0

Hyena

Oh blergh. Thanks for the warning!
0

sikkykins

this suuuucks. the news says it's found hundreds of yahoo usernames and passwords. (i am a frequent yahoo user too.) what a pain. :| thanks for the heads up. luckily i never put out card/address info online i suppose...
0

Finnie

@Lisa

You should honestly be changing your passwords every few months anyway, it's just good practice.
0

Tardis

Thank you for the heads up Keith. I heard about this not too long ago via the Current Events thread. Huge sigh of relief that subeta and facebook are safe. I guess that's one good reason to be poor. I can't afford to buy anything.
0

Nostalgia_507

Wow, @Keith, thanks for warning us! I hadn't heard about this latest bug exploit. *busily changing all her passwords*
0

Frankenchokies

@Keith

The grammar suggests it is not. So my bad or your bad? OR IS IT SATAN'S BAD?

Wait, what.
0

Keith

@Frankenchokies Obviously hypothetical.
0

Lisa

Should I change my passwords on everything? Really? My bank, iTunes, Comcast, tumblr, deviantart...all of those? That's such a pain in the butt. I just now got them memorized and now I'm going to have to do it all again. I hate hackers. So, so much. -_-
0

Finnie

@honey_bear

As Keith stated in announcement, once the websites you use have cleared the heartbleed test (once the site has been confirmed as patched), it is safe to change your passwords :)
0

honey_bear

@Finnie , I'm just a little confused by your comment post. Are you suggesting we change our passwords before or after the patch you mentioned. Sorry, just a little confused. Thanks :)
0

DreamsInPink

So, if Subeta is safe, why do we need to change our PWs??
0

Victim

Thanks for the heads up! I haven't heard anything about this, so I really appreciate the info!
0

Jazmine

Information about the sites affected:
Master list of sites affected by Heartbleed.
A more in depth article about the situation

Orgasmic that should answer your questions :)
0

Taters

My mom is in web security and said that the issue was that only one of the many versions of ssl had the problem. But unless you own the site you cant really know which use it unless you know where to look. That website is the one they used in her office, and most things relating to banking are safe as they do check those things daily.
Plus, it was an update to the ssl that had the biggest problem, and most places dont get those that quick.

So just be safe and use different pws on sites relating to your money, and even change your pin here if your worried :)

But its awesome subeta cares so much about us and wanted to warn those whose parents dont work with these things on a daily basis lol
0

Ambition

thank you so much for looking out for us and being on top of security issues! :D
0

Yelan

Thank you so much for telling us this.
0

orgasmic

Yeah I'm not understanding how to look at the websites I use to see if they're under threat or not.
0

deadly

do you recommend we change ALL our passwords? email, banking, social networking, ect?
0

red5luke

The company I work for got right on this for our website (which is good, because I've been answering a lot of emails about it today). I was wondering if Subeta was on top of it as well, and I'm glad to hear you guys are!
0

Gem_840

Thank you for letting us know how Subeta is handling this situation! I have been following it, and was wondering about the situation here.
0

poppet

I'm so amused that CloudFlare was good for something!
0

Keith

@Virus Yup :)
0

Frankenchokies

@Keith

Did you seriously just expose InSaNe's password or are you being hypothetical?
0

Damon

So Subeta is safe right, if we need to change anything it's alright to do so?
0

pax

Thank you for the announcement. This is something that has to be disseminated to people as quickly as possible.
We've rolled out Fixed OpenSSL in a server I assist in running, the other day.
(And before someone lurches at me for my grammar, English is my third language. :P)
0

Keith

@Finnie Thank you! I was looking for that link, going to add it to the news post.
0

Keith

@InSaNe Someone who noticed that your Subeta password is the same as your paypal password.
0

Grey_503

is paypal safe?
0

Finnie

Until this afternoon subeta was coming up as being vulnerable on the heartbleed tester --- http://filippo.io/Heartbleed/

Most techs are recommending not to change your passwords at this point because the more recently your password (or other information) has been logged in the server the more vulnerable it is to hackers.

However I believe once the patches have been made you no longer have to worry about that, and yes, you should change your passwords.
0

InSaNe

who would want to hack my subeta account anyway
0

Aspirati

thanks for the heads up :)
0

Rue

Thanks for the heads up!
This is scary ;0;
0

what

really appreciate the information.
0

saranghae

Thank you for letting us know! Very scary for those of is (like me) who use the web a LOT and to do a LOT of things.
0

SexyFart

Thank you for the heads up! Glad to know subeta is safe. :D
0

_blackwolf_2009_

Thanks for the update. I been seeing this around but glad that this website still gives out info like this.
0

Owl

Thanks for letting us know about this.
0

Frankenchokies

Your grammar is shocking.
0

Lyllytas

Thanks for the heads up!
0

Damon

Scared the crap out of me for a moment.... but so glad Subeta is safe. Thank you for the heads up. Had been hearing around this all day. Hope it gets fixed and fast.
0

Leave Comment

Comments are currently on a short cache, meaning your comment may take a few minutes to show up after you post it.


-or-