Bitcoin Forum
December 12, 2024, 12:38:46 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Is your exchange protected from heartbleed?  (Read 667 times)
enrapha (OP)
Newbie
*
Offline Offline

Activity: 52
Merit: 0


View Profile WWW
April 19, 2014, 07:22:05 PM
 #1

This isn't anything new, but we also haven't heard much about it. With everything that's already happened can we afford to put our already fragile price of Bitcoin up for more risk? Even this thread has put out information about the heartbleed fix. We are aware of several different exchanges but how many have confirmed the openssl fix? Ask your exchange to confirm the fix. It's your money on the line. BTCPD will do our part and post a list of exchanges who have taken the proper measures. If you have information please let us know.

Thank you
inBitweTrust
Hero Member
*****
Offline Offline

Activity: 658
Merit: 501



View Profile
April 19, 2014, 11:01:01 PM
 #2

Most servers were quickly fixed once news spread. Individuals can check themselves. Here are some exchanges I tested which are fine from the heartbleed attack:

https://sslanalyzer.comodoca.com/?url=coinbase.com
https://sslanalyzer.comodoca.com/?url=bitcoin.de
https://sslanalyzer.comodoca.com/?url=bitsource.org
https://sslanalyzer.comodoca.com/?url=bittylicious.com
https://sslanalyzer.comodoca.com/?url=btc.sx
https://sslanalyzer.comodoca.com/?url=bitnz.com
https://sslanalyzer.comodoca.com/?url=bitstamp.net
https://sslanalyzer.comodoca.com/?url=btcmarkets.net
https://sslanalyzer.comodoca.com/?url=btc-e.com
https://sslanalyzer.comodoca.com/?url=campbx.com
https://sslanalyzer.comodoca.com/?url=bitcoin.it
https://sslanalyzer.comodoca.com/?url=hitbtc.com
https://sslanalyzer.comodoca.com/?url=kapiton.se
https://sslanalyzer.comodoca.com/?url=localbitcoins.com
https://sslanalyzer.comodoca.com/?url=moneypaktrader.com
https://sslanalyzer.comodoca.com/?url=therocktrading.com
https://sslanalyzer.comodoca.com/?url=vircurex.com
https://sslanalyzer.comodoca.com/?url=cavirtex.com
https://sslanalyzer.comodoca.com/?url=virwox.com
https://sslanalyzer.comodoca.com/?url=weexchange.co
https://sslanalyzer.comodoca.com/?url=bitbargain.co.uk
https://sslanalyzer.comodoca.com/?url=btcchina.com


This being said, I see a lot of exchanges with other security concerns that need to be fixed.

Please do not leave your Bitcoins in a hot wallet or exchange until security is taken more seriously. Make the trade and get out.








enrapha (OP)
Newbie
*
Offline Offline

Activity: 52
Merit: 0


View Profile WWW
April 19, 2014, 11:37:32 PM
 #3


excellent information! if you wouldn't mind providing more information about the other security issues?
inBitweTrust
Hero Member
*****
Offline Offline

Activity: 658
Merit: 501



View Profile
April 19, 2014, 11:46:52 PM
 #4

Some have weak encryption, aren't up to date with all the patches, don't use 2FA, are vulnerable to DDOS attacks, are vulnerable to SSL CRIME attack, ect....

The bigger threat is still the owners running off with the money though. I would only trust either a well regulated exchange in a country that prosecutes thieves like the US or an exchange that is insured or are using other means of protecting their clients like muti-sig authentications. Even than so I would still suggest securing your assets yourself and only using exchanges as a place to perform the trade. 

enrapha (OP)
Newbie
*
Offline Offline

Activity: 52
Merit: 0


View Profile WWW
April 19, 2014, 11:50:08 PM
 #5

Some have weak encryption, aren't up to date with all the patches, don't use 2FA, are vulnerable to DDOS attacks, are vulnerable to SSL CRIME attack, ect....

The bigger threat is still the owners running off with the money though. I would only trust either a well regulated exchange in a country that prosecutes thieves like the US or an exchange that is insured or are using other means of protecting their clients like muti-sig authentications. Even than so I would still suggest securing your assets yourself and only using exchanges as a place to perform the trade. 

well said
Bit_Happy
Legendary
*
Offline Offline

Activity: 2114
Merit: 1040


A Great Time to Start Something!


View Profile
April 20, 2014, 01:12:20 AM
 #6


Most exchanges should have responded the first day.
Good to see it confirmed that the SSL bug is fixed on all of those.
I wonder if many hackers knew about the hole, or only "the Gov" was using it?

moni3z
Hero Member
*****
Offline Offline

Activity: 899
Merit: 1002



View Profile
April 20, 2014, 01:16:22 AM
 #7

Since most exchangers are using Cloudflare, and since Cloudflare was given early notice of heartbleed and patched before it went public they weren't affected. OpenVPN was still affected until a day or so ago because it uses a bundled SSL library that was vuln to heartbleed as well, so for about a week somebody went crazy bypassing multi-auth by jacking sessions and stealing private keys. http://arstechnica.com/security/2014/04/heartbleed-exploited-to-hack-network-with-multifactor-authentication/

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!