theymos (OP)
Administrator
Legendary
Offline
Activity: 5334
Merit: 13305
|
|
October 15, 2014, 10:47:22 PM |
|
The POODLE vulnerability in TLS/SSL could have allowed a man-in-the-middle attacker to read encrypted forum traffic. For example, Tor exit nodes could have used this attack against anyone using Tor to access the forum. I disabled SSLv3 to prevent this attack in the future, and I logged everyone out to invalidate any possibly-compromised cookies. If you used a proxy or ISP that you don't absolutely trust to access the forum, then you should also change your password.
Most other sites are similarly affected.
|
1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
|
|
|
Quickseller
Copper Member
Legendary
Offline
Activity: 2982
Merit: 2371
|
|
October 15, 2014, 10:54:20 PM |
|
Should we consider PIA to be an untrusted proxy, or should be generally be safe with them?
|
|
|
|
haploid23
Legendary
Offline
Activity: 812
Merit: 1002
|
|
October 15, 2014, 11:01:34 PM |
|
So only "untrustworthy ISP" and TOR users are affected, everyone else safe? I hate changing PW's. More susceptible to forget them.
|
|
|
|
theymos (OP)
Administrator
Legendary
Offline
Activity: 5334
Merit: 13305
|
|
October 15, 2014, 11:18:40 PM |
|
Should we consider PIA to be an untrusted proxy, or should be generally be safe with them?
So only "untrustworthy ISP" and TOR users are affected, everyone else safe? I hate changing PW's. More susceptible to forget them.
You'll have to use your own judgement on that. Do you trust that your VPN/ISP didn't use this attack against you to steal your password? Some things to know: - It's an active attack, so if your ISP was just recording traffic, this wouldn't help them now. - If you didn't actually use your password to log in within the last couple of days (ie, not just logging in using "remember me"), then your ISP only could have stolen your password if they'd known about the vulnerability before it was publicly announced.
|
1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
|
|
|
peligro
|
|
October 15, 2014, 11:21:14 PM |
|
Doesn't sound too dangerous as I use only ISP directly, changed my password anyway.
Btw, POODLE? Quite a letdown, after cool names like Heartbleed and Shellshock.
|
|
|
|
theymos (OP)
Administrator
Legendary
Offline
Activity: 5334
Merit: 13305
|
|
October 15, 2014, 11:24:02 PM |
|
Btw, POODLE? Quite a letdown, after cool names like Heartbleed and Shellshock.
Yeah, it's a terrible name. The vulnerability isn't nearly as bad as Heartbleed or Shellshock, though.
|
1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
|
|
|
elitenoob
|
|
October 15, 2014, 11:39:24 PM |
|
Thanks for the info...hate to change pwd's but it's (almost) never too late
|
|
|
|
Vortex20000
|
|
October 16, 2014, 02:48:05 AM |
|
I've logged in through Cyberghost, but they have decent reviews so I'm not changing PW.
|
|
|
|
ranochigo
Legendary
Offline
Activity: 3038
Merit: 4418
Crypto Swap Exchange
|
|
October 16, 2014, 04:04:55 AM |
|
If you used a WIFI that is unsecured or using WEP or vulnerable WPS encryption, you should change your password. Attacks may have been executed on the network, so your accounts may be compromised.
|
|
|
|
goozman96
|
|
October 16, 2014, 05:19:08 AM |
|
It seems never ending. Every other month some new vulnerability is discovered. This sucks
|
BTC: 19DKtsdGfQyFzNiEze9KuFQrWGiLDvg6F1 | LTC: LbV6UGyjYbVP49NvQFmuAnkADcaFYvNagK | NMC: NDCdMJmTmGH54Cezmo3CwSxAC7grAoZJbj
|
|
|
dserrano5
Legendary
Offline
Activity: 1974
Merit: 1029
|
|
October 16, 2014, 07:02:39 AM |
|
Thank you theymos. Password changed—again .
|
|
|
|
Beastlymac
|
|
October 16, 2014, 07:03:51 AM |
|
Btw, POODLE? Quite a letdown, after cool names like Heartbleed and Shellshock.
Yeah, it's a terrible name. The vulnerability isn't nearly as bad as Heartbleed or Shellshock, though. It is an acronym it stands for "Padding Oracle On Downgraded Legacy Encription"
|
Message me if you have any problems
|
|
|
Vortex20000
|
|
October 16, 2014, 07:05:34 AM |
|
Btw, POODLE? Quite a letdown, after cool names like Heartbleed and Shellshock.
Yeah, it's a terrible name. The vulnerability isn't nearly as bad as Heartbleed or Shellshock, though. It is an acronym it stands for "Padding Oracle On Downgraded Legacy Encription" Oh. Thank you for the clarification and explanation
|
|
|
|
sgk
Legendary
Offline
Activity: 1470
Merit: 1002
!! HODL !!
|
|
October 16, 2014, 07:15:39 AM |
|
Btw, POODLE? Quite a letdown, after cool names like Heartbleed and Shellshock.
Yeah, it's a terrible name. The vulnerability isn't nearly as bad as Heartbleed or Shellshock, though. It is an acronym it stands for "Padding Oracle On Downgraded Legacy Encription" The vulnerability was discovered by Google, so most likely they came up with DOODLE acronym first and then worked their way back to generate a plausible-sounding full form
|
|
|
|
Vortex20000
|
|
October 16, 2014, 07:17:24 AM |
|
Btw, POODLE? Quite a letdown, after cool names like Heartbleed and Shellshock.
Yeah, it's a terrible name. The vulnerability isn't nearly as bad as Heartbleed or Shellshock, though. It is an acronym it stands for "Padding Oracle On Downgraded Legacy Encription" The vulnerability was discovered by Google, so most likely they came up with DOODLE acronym first and then worked their way back to generate a plausible-sounding full form DOODLE and POODLE - D and P Dire and Padding?
|
|
|
|
sgk
Legendary
Offline
Activity: 1470
Merit: 1002
!! HODL !!
|
|
October 16, 2014, 07:31:38 AM |
|
Btw, POODLE? Quite a letdown, after cool names like Heartbleed and Shellshock.
Yeah, it's a terrible name. The vulnerability isn't nearly as bad as Heartbleed or Shellshock, though. It is an acronym it stands for "Padding Oracle On Downgraded Legacy Encription" The vulnerability was discovered by Google, so most likely they came up with DOODLE acronym first and then worked their way back to generate a plausible-sounding full form DOODLE and POODLE - D and P Dire and Padding? My bad! Although they both don't look much different to me
|
|
|
|
fronti
Legendary
Offline
Activity: 2912
Merit: 1309
|
|
October 16, 2014, 07:32:10 AM |
|
maybe to add also in the "News" that all useres are automaticly logged out. I was very surprised if I see me logged out.
Ok first I do was to go (still logged out) to meta and see in this thread that all are logged out by you..
|
If you like to give me a tip: bc1q8ht32j5hj42us5qfptvu08ug9zeqgvxuhwznzk
"Bankraub ist eine Unternehmung von Dilettanten. Wahre Profis gründen eine Bank." Bertolt Brecht
|
|
|
zetaray
|
|
October 16, 2014, 08:27:52 AM |
|
This is the reason I was logged out from bitcointalk. Took me a few minutes to figure out my own password, the one I changed in a rush after the previous SSL bug.
|
|
|
|
shorena
Copper Member
Legendary
Offline
Activity: 1498
Merit: 1530
No I dont escrow anymore.
|
|
October 16, 2014, 09:17:14 AM |
|
This is the reason I was logged out from bitcointalk. Took me a few minutes to figure out my own password, the one I changed in a rush after the previous SSL bug.
Dont get used to it, just change it again
|
Im not really here, its just your imagination.
|
|
|
Kluge
Donator
Legendary
Offline
Activity: 1218
Merit: 1015
|
|
October 16, 2014, 09:26:29 AM |
|
This is the reason I was logged out from bitcointalk. Took me a few minutes to figure out my own password, the one I changed in a rush after the previous SSL bug.
I was pretty pleased to find I still had it saved. I thought I forgot to save it when I last changed it and talked to theymos about an account recovery. Maybe just a weird dream... ever have that? Sometimes dream about weird, mundane stuff like shampooing hair, then forget to take a shower in the morning because I thought I already had. -Or I'll think the dog died a year ago, then see it when I wake up... scares the bejesus out of me. Anyway - not sure what's wrong with the name. Poodles are bad news. If it derived from BEAST attack, POODLE seems like a pretty reasonable name for a successor.
|
|
|
|
|