Bitcoin Forum
November 08, 2024, 07:46:09 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Is this site affected 1 of the 6 or so new openssl vulnerabilities ?  (Read 502 times)
Justin00 (OP)
Legendary
*
Offline Offline

Activity: 910
Merit: 1000


★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile
June 06, 2014, 12:35:40 PM
 #1

have not had a chance to fully vertify the new vulnerabilities.
hopefully theymos had ?

any chance you have been able to see if the site is vulnerable ?? from a quick glance one of them were quite serious...


Mikez
Hero Member
*****
Offline Offline

Activity: 508
Merit: 500



View Profile
June 06, 2014, 12:41:15 PM
 #2

As far as I know, and as theymos announced, bitcointalk is not heartbleed vulnerable anymore. Have new vulnerabilies surfaced?
I used a couple of SSL checkers just now and everything seemed fine.

abacus
Hero Member
*****
Offline Offline

Activity: 618
Merit: 500


a clockwork miner


View Profile
June 06, 2014, 05:06:12 PM
 #3

Have new vulnerabilies surfaced?
Yes, yesterday:
https://www.openssl.org/news/secadv_20140605.txt
BCwinning
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


View Profile
June 06, 2014, 05:07:46 PM
 #4

Those only affect systems that are affected by heartbleed. So if openssl has been upgraded from the
affected version there is no issues.

The New World Order thanks you for your support of Bitcoin and encourages your continuing support so that they may track your expenditures easier.
abacus
Hero Member
*****
Offline Offline

Activity: 618
Merit: 500


a clockwork miner


View Profile
June 06, 2014, 05:24:29 PM
 #5

Those only affect systems that are affected by heartbleed. So if openssl has been upgraded from the
affected version there is no issues.

Oh, good to know. Then there's a bit of FUD in many articles about this news.
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1540


No I dont escrow anymore.


View Profile
June 06, 2014, 05:50:13 PM
 #6

Those only affect systems that are affected by heartbleed. So if openssl has been upgraded from the
affected version there is no issues.

Oh, good to know. Then there's a bit of FUD in many articles about this news.

Its FUD that this only affects systems that are affected by the heartbleed bug. One of the new bugs is in code that the same person wrote who did the misstakes in heartbleed, maybe thats where this missunderstanding comes from.
From what I read noone uses DTLS anyway. Anonymous ECDH is not used by the forum and barely any homepage for that matter because most use certificates anyway. The only thing that could affect us would be the possible MITM for Bitcoin, but than not really doing any damage AFAIK. You can MITM with Bitcoin anyway, but not get the juicy stuff (private keys).

Im not really here, its just your imagination.
theymos
Administrator
Legendary
*
Offline Offline

Activity: 5376
Merit: 13407


View Profile
June 06, 2014, 05:52:18 PM
 #7

The forum's OpenSSL was updated yesterday.

Those only affect systems that are affected by heartbleed. So if openssl has been upgraded from the
affected version there is no issues.

No, it's unrelated to heartbleed

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
Justin00 (OP)
Legendary
*
Offline Offline

Activity: 910
Merit: 1000


★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile
June 07, 2014, 09:48:20 AM
 #8

good man theymos.

I must apologise for an hositility I have shown towards you in the past; however I will still keep you on your toes, espeaclly when security and what not is at stake Smiley



The forum's OpenSSL was updated yesterday.

Those only affect systems that are affected by heartbleed. So if openssl has been upgraded from the
affected version there is no issues.

No, it's unrelated to heartbleed

Mikez
Hero Member
*****
Offline Offline

Activity: 508
Merit: 500



View Profile
June 07, 2014, 10:05:05 AM
 #9

Here's another thread on the new vulnerabibilities: https://bitcointalk.org/index.php?topic=640430

Peter882
Hero Member
*****
Offline Offline

Activity: 543
Merit: 500



View Profile
June 07, 2014, 10:22:08 AM
 #10

Here's another thread on the new vulnerabibilities: https://bitcointalk.org/index.php?topic=640430

I believe that thread in "Development & Technical Discussion" focuses on the affects on the wallet client, while this one in "Meta" focuses on the forum itself. Smiley

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!