Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Heartbleed Bug: Could It Teach People To Behave Responsibly?
Articles

The Heartbleed Bug: Could It Teach People To Behave Responsibly?

ISBuzz TeamBy ISBuzz TeamMay 2, 2014Updated:January 5, 20264 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
heartbleed
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

By now, you are probably aware of the Heartbleed Bug. There are many people who have heard about it, but don’t understand what it is.

This is the simple explanation from Codenomicon, “The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users.”

The recommendation for computer users is for them to change their passwords for systems that are known to be patched for the Heartbleed bug, since attackers may have stolen them from vulnerable systems. Here’s a dynamic list of common sites and their status.

This next step of changing passwords points to another vulnerability, people. Many computer users don’t know how to build and remember strong passwords and they also tend use the same weak password across all of their applications.

Cybercriminals who have known about the Heartbleed bug for some time have had the opportunity to steal many passwords. Since many people use the same password across many applications, the cybercriminals can take the passwords they’ve already collected (before the bug was identified) and break into numerous accounts for each computer user, from their facebook page, to their email, to their bank account. As the saying goes, “the world is their oyster.”

Now that the bug has been identified the responsibility is on the everyday computer user to create new passwords for all of these compromised, now patched, systems. Wouldn’t it be great if this time around everyone got it right? What if we all created unique and strong passwords for each site so that in the event another vulnerability is identified. Then the overall risk to each individual user would be less?

Here are some tips for creating strong passwords:

– In short, the key is to create one separate unique strong password for each activity where you provide sensitive information for example when purchasing online, doing online banking, registering for classes, and email in the cloud (Gmail, Microsoft Office 365).

– A strong password should not be easy to guess and therefore shouldn’t include yours or your family’s address, birthday, anniversary, etc.

– It must be at least eight characters long and include capital letters, symbols and numbers.

– One way to apply these tips is to create a password family which makes passwords easy to remember. For example you could create a password family around automobiles.  Bl&ckVo1vo (Black Volvo) might be for secure use such as your online banking and then R3dF#rr$ri (Red Ferrari) might be for more risky activities such as online shopping, and then perhaps email in the cloud could be Wh^t3Pri9s (White Prius).

A recent report from Enterprise Management Associates shows that password management is one of the top five security education topics that security officers want their end users to complete. Based upon the list of 25 worst passwords above I think we know why.

While software developers have a large role in rectifying the Heartbleed bug, the computer user community has a responsibility too. To learn safe behaviors, either on their own or through their employer, that makes it harder for cyber criminals to take advantage of them.

Joe Ferrara is the President and CEO of Wombat Security Technologies

Today, Wombat Security Technologies is a leading provider of cyber security training and filtering solutions. Its software-based training solutions are designed to be engaging and effective, and have been scientifically proven to be significantly more effective than other traditional training solutions. Wombat’s anti-phishing filtering solutions have been shown to catch significantly more phishing attacks than other filters. Wombat’s products are used in sectors as diverse as finance, government, telecom, health care, retail, education, transportation and utilities. – See more at: http://www.wombatsecurity.com/about-wombat-security-technologies#sthash.Vp3Hb0QE.dpuf

Wombat Security Technologies is a leading provider of cyber security training and filtering solutions. Its software-based training solutions are designed to be engaging and effective, and have been scientifically proven to be significantly more effective than other traditional training solutions. Wombat’s anti-phishing filtering solutions have been shown to catch significantly more phishing attacks than other filters. Wombat’s products are used in sectors as diverse as finance, government, telecom, health care, retail, education, transportation and utilities.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}