Flaw Found in Key Method for Protecting Data on the Internet

Coverage Type: 

The tiny padlock icon that sits next to many web addresses, suggesting protection of users’ most sensitive information -- like passwords, stored files, bank details, even Social Security numbers -- is broken.

A flaw has been discovered in one of the Internet’s key encryption methods, potentially forcing a wide swath of websites to swap out the virtual keys that generate private connections between the sites and their customers.

Many organizations have been heeding the warning. Companies like Lastpass, the password manager, and Tumblr, the social network owned by Yahoo, said they had issued fixes and warned users to immediately swap out their usernames and passwords.

The vulnerability involves a serious bug in OpenSSL, the technology that powers encryption for two-thirds of web servers. It was revealed by a team of Finnish security researchers who work for Codenomicon, a security company in Saratoga (CA), and two security engineers at Google. Researchers are calling the bug “Heartbleed” because it affects the “heartbeat” portion of the OpenSSL protocol, which pings messages back and forth. It can and has been exploited by attackers. The bug allows attackers to access the memory on any web server running OpenSSL and take information like customer usernames and passwords, sensitive banking details, trade secrets and the private encryption keys that organizations use to communicate privately with their customers.

“It’s a serious bug in that it doesn’t leave any trace,” said David Chartier, the chief executive at Codenomicon. “Bad guys can access the memory on a machine and take encryption keys, usernames, passwords, valuable intellectual property, and there’s no trace they’ve been there.”


Flaw Found in Key Method for Protecting Data on the Internet