Experts: Do not panic over internet security bug

Security experts have urged internet users not to panic and instantly change their passwords in wake of the Heartbleed bug security flaw, despite suggestions to do so from prominent sites like Tumblr.

Experts: Do not panic over internet security bug

Security experts have urged internet users not to panic and instantly change their passwords in wake of the Heartbleed bug security flaw, despite suggestions to do so from prominent sites like Tumblr.

Hugh Boyes, cyber security lead at the UK-based Institution of Engineering and Technology said: “Change your passwords – but only after the affected website operators and internet service providers have implemented the patch to fix the bug.

“Changing your password before the bug is fixed could compromise your new password.”

The popular blogging website Tumblr, which is owned by Yahoo!, had previously urged its users to change all their passwords, especially those protecting sensitive data like email and bank accounts, immediately.

Independent security expert Bruce Schneier has also called for calm, but emphasised the seriousness of the web security breach.

“The bug has been patched. After you patch your systems, you have to get a new public or private key pair, update your SSL certificate and then change every password that could potentially be affected. ’Catastrophic’ is the right word. On the scale of 1 to 10, this is an 11. Half a million sites are vulnerable, including my own.”

Users can test their own vulnerability to the Heartbleed bug by visiting a site created by developer Filippo Valsorda, where you can enter web addresses and find out if the bug has been fixed. Once it is confirmed the site has been patched, it’s safe to change your password.

“Regularly change your passwords. Depending on how sensitive the application/website is, passwords typically ought to be changed monthly or quarterly. Don’t reuse the same passwords on different websites. Try to use a separate password for each website,” said Mr Boyes.

The Heartbleed bug was discovered on Monday by a team of security experts, including one from Google, having gone undetected for more than two years.

The bug bypasses the encryption that normally protects data as it is sent between computers and servers, leaving personal and sensitive data vulnerable. It is commonly recognised as the closed padlock that appears in the corner of the web browser to show your connection is secure.

more courts articles

Former DUP leader Jeffrey Donaldson arrives at court to face sex charges Former DUP leader Jeffrey Donaldson arrives at court to face sex charges
Case against Jeffrey Donaldson to be heard in court Case against Jeffrey Donaldson to be heard in court
Defendant in Cobh murder case further remanded in custody Defendant in Cobh murder case further remanded in custody

More in this section

Melanoma mRNA jab ‘Real hope’ for cancer cure as personal mRNA vaccine for melanoma trialled
Number of Catholic marriages fall in 2023 with almost a third opting for civil ceremonies Number of Catholic marriages fall in 2023 with almost a third opting for civil ceremonies
Trudder House protests Five charged as garda commissioner condemns 'unacceptable scenes' at Newtownmountkennedy
War_map
Cookie Policy Privacy Policy Brand Safety FAQ Help Contact Us Terms and Conditions

© Examiner Echo Group Limited