Heartbleed Bug and Your Website – Message to our Clients

heartbleed_logoWe were made aware of this bug on the morning of April 8th and immediately worked with our partners on a scan of our infrastructure to assess the risk. As of April 9th, we can say the bug is fixed on all our servers. We’ve posted some of the common questions that we’ve been asked.

OpenSSL Heartbleed Vulnerability FAQ

Q. What is Heartbleed?
A. The Heartbleed Bug is a serious weakness which could allow the stealing the information protected, under normal conditions, by the SSL encryption (https) used to secure the Internet. SSL provides communication security and privacy over the Internet. This is what your bank, and ecommerce websites like TritonPestControl.com (shameless plug for our friend Wayne) use to secure your logins and transactions.

Warning! Technical Jargon – The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic , the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users. (Big problem! This means you don’t know who you can trust, can anyone else see what you’re doing, and is it really you!)

You can learn more about Heartbleed at heartbleed.com.

Q. Do I need to take action now?
A. NO. Our servers are already patched with an updated version of OpenSSL and any services using OpenSSL were restarted and tested.

Q. What other actions should I take after my servers are fully patched?
A. If you have portions of your environment which are highly sensitive, you may want to consider:

Generating new keys and certificate signing requests to re-issue your SSL certificates
Resetting critical passwords on the system

As always, please feel free to contact us with questions or if you would like us to take any additional actions.

Similar Posts