Close Menu
Syracuse New TimesSyracuse New Times
    Facebook X (Twitter) Instagram
    • Jump to Category…
    • All Events
    • Club Dates
    • Comedy
    • Exhibits
    • Film
    • Fundraisers
    • Learning
    • Literati
    • Outings
    • Other
    • Specials
    • Sports
    • Stage
    • Trivia
    Facebook X (Twitter) Instagram YouTube
    Syracuse New TimesSyracuse New Times
    Demo
    • CNY Events Calendar
      • Add My Event
      • Advertise On Calendar
    • News
      • News
      • Business
      • Sports
    • Arts
      • Art
      • Stage
      • Music
      • Film
      • Television
    • Lifestyle
      • Food
      • Wellness
      • Fashion
      • Travel
    • Opinion & Blogs
      • Things That Matter (Luke Parsnow)
      • New York Skies (Cheryl Costa)
    • Photos
    • Special Editions
      • 2019 Spring Times
      • 2019 Winter Times Edition
      • 2018 Holiday Times
      • 2018 SALT Awards
      • 2018 Best of Syracuse
      • 2018 Autumn Times
      • 2018 SNT Student Survival Guide
      • The 2018 Arts Issue
      • 2018 Summer Times
    • Family Times Magazine
    • CNY Community Guide
    Syracuse New TimesSyracuse New Times
    Home»News»Cover Story»A HOLE IN THE ’NET
    Cover Story

    A HOLE IN THE ’NET

    Julia AngwinBy Julia AngwinMay 7, 2014Updated:May 14, 2014No Comments5 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Heartbleed computer security bug is many things: a catastrophic tech failure, an open invitation to criminal hackers and yet another reason to upgrade our passwords on dozens of websites. But more than anything else, Heartbleed reveals our neglect of Internet security.

    The United States spends more than $50 billion a year on spying and intelligence, while the folks who build important defense software — in this case, a program called OpenSSL, which ensures that your connection to a website is encrypted —are four core programmers, only one of whom calls it a full-time job.

    Heartbleed-NYTOption
    New York Times

    In a typical year, the foundation that supports OpenSSL receives $2,000 in donations. The programmers have to rely on consulting gigs to pay for their work.

    “There should be at least a half dozen full time OpenSSL team members, not just one, able to concentrate on the care and feeding of OpenSSL without having to hustle commercial work,” says Steve Marquess, who raises money for the project.
    Is it any wonder that this Heartbleed bug slipped through the cracks?

    Dan Kaminsky, a security researcher who saved the Internet from a similarly fundamental flaw in 2008, says that Heartbleed shows that it’s time to get “serious about figuring out what software has become critical infrastructure to the global economy, and dedicating genuine resources to supporting that code.”

    The Obama administration has said it is doing that with its national cybersecurity initiative, which establishes guidelines for strengthening the defense of our technological infrastructure — but it does not provide money for the implementation of those guidelines.

    Instead, the National Security Agency, which has responsibility to protect U.S. infrastructure, has worked to weaken encryption standards. And so private websites — such as Facebook and Google, which were affected by Heartbleed — often use open-source tools such as OpenSSL, where the code is publicly available and can be verified to be free of NSA backdoors.

    The federal government spent at least $65 billion between 2006 and 2012 to secure its own networks, according to a February report from the Senate Homeland Security and Government Affairs Committee. And many critical parts of the private sector — such as nuclear reactors and banking — follow sector-specific cybersecurity regulations.

    But private industry has also failed to pay for its critical tools. As cryptographer Matthew Green says, “Maybe in the midst of patching their servers, some of the big companies that use OpenSSL will think of tossing them some real no-strings-attached funding so they can keep doing their job.”

    465165427
    “the rest of us are left with the unfortunate job of changing all our passwords”

    In the meantime, the rest of us are left with the unfortunate job of changing all our passwords, which may have been stolen from websites that were using the broken encryption standard. It’s unclear whether the bug was exploited by criminals or intelligence agencies. (The NSA says it didn’t know about it.)

    It’s worth noting, however, that the risk of your passwords being stolen is still lower than the risk of your passwords being hacked from a website that failed to  protect them properly. Criminals have so many ways to obtain your information these days — by sending you a fake email from your bank or hacking into a retailer’s unguarded database — that it’s unclear how many would have gone through the trouble of exploiting this encryption flaw.

    The problem is that if your passwords were hacked by the Heartbleed bug, the hack would leave no trace. And so, unfortunately, it’s still a good idea to assume that your passwords might have been stolen.

    So, you need to change them. If you’re like me, you have way too many passwords. So I suggest starting with the most important ones: your email passwords. Anyone who gains control of your email can click “forgot password” on your other accounts and get a new password emailed to them. As a result, email passwords are the key to the rest of your accounts. After email, I’d suggest changing banking and social media account passwords.

    But before you change your passwords, you need to check if the website has patched their site. You can test whether a site has been patched by typing the URL here: lastpass.com/heartbleed/. (Look for the green highlighted “Now Safe” result.)

    If the site has been patched, then change your password. If the site has not been patched, wait until it has been patched before you change your password.

    A reminder about how to make passwords:

    Forget all the password advice you’ve been given about using symbols and not writing down your passwords. There are only two things that matter: Don’t reuse passwords across websites, and the longer the password, the better.

    I suggest using password management software, such as 1Password or LastPass, to generate the vast majority of your passwords. And for email, banking and your password to your password manager, I suggest a method of picking random words from the dictionary, called Diceware. If that seems too hard, just make your password super long — at least 30 or 40 characters long, if possible.

    ProPublica is an independent, non-profit newsroom that produces investigative journalism in the public interest.

    Heartbleed-NYTOptionCLICK HERE to read New Times tech writer Joe Cunningham’s recent ‘Heartbleed’ article.

    FIRST LOOK! Sign up for our weekly e-newsletter and get a look at Wednesday’s New Times before everyone else!



    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Julia Angwin

    Related Posts

    Is the U.S. Experiencing a New Online Poker Boom? The Numbers Say Yes

    July 15, 2025

    Under-the-Radar Breakout Candidates for the 2025 NFL Preseason

    June 16, 2025

    Your Guide to Using Telematics Software to Streamline Your Sales and Service Operations

    April 15, 2025

    The Most Common Causes of Manufacturing Downtime & How to Prevent Them

    March 27, 2025

    How Quality Monitoring Reduces Employee Burnout in Call Centers

    March 5, 2025

    A Historical Look at March Madness Champions

    February 26, 2025

    Comments are closed.

    • CNY Events Calendar
    • Club Dates
    • Food & Drink
    • Destinations
    • Sports & Outdoors
    • Family Times
    • Facebook
    • Instagram
    • Community Code of Conduct
    • Staff/Contact Us
    • Careers
    • SALT Academy Applications & Awards Process
    • Family Times
    • CNY Tix
    • Spinnaker Custom Products

    Syracuse New Times
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.