Go Back   Flash Flash Revolution > General Discussion > Chit Chat
Register FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
Old 04-15-2014, 02:20 PM   #1
Litodude
FFR Player
 
Join Date: Feb 2006
Location: state of awesome
Age: 33
Posts: 4,548
Send a message via AIM to Litodude
Default psa heartbleed

https://filippo.io/Heartbleed/
__________________
Quote:
Originally Posted by t-rogdor View Post
i finally got a weed hookup again and i texted the dude asking where to meet him tomorrow and the dude just said "out west"

dude
out west?
the fuck kinda location is west?
am i buying weed off a gotdamn pirate


Quote:
Originally Posted by lurker View Post
remind everyone that i am an outed racist neo-nazi who no one in their right mind should ever interact with in any way whatsoever

http://imgur.com/a/Ww9g3
Litodude is offline   Reply With Quote
Old 04-15-2014, 02:21 PM   #2
Untimely Friction
D6 Challeneged
Retired StaffFFR Veteran
 
Untimely Friction's Avatar
 
Join Date: Aug 2012
Age: 31
Posts: 1,267
Default Re: psa heartbleed

If I remember correctly this is a site used to determine if an https enabled site is vulnerable to the exploit?? you should say that cause if I wasnt already aware I wouldn't know, and nor will others.
Untimely Friction is offline   Reply With Quote
Old 04-15-2014, 02:24 PM   #3
choof
Banned
Retired StaffFFR Simfile AuthorD7 Elite KeysmasherFFR Veteran
 
Join Date: Nov 2013
Posts: 8,563
Default Re: psa heartbleed

Quote:
Originally Posted by Untimely Friction View Post
If I remember correctly this is a site used to determine if an https enabled site is vulnerable to the exploit?? you should say that cause if I wasnt already aware I wouldn't know, and nor will others.
if you click on the link it tells you what this is for
choof is offline   Reply With Quote
Old 04-15-2014, 02:24 PM   #4
Litodude
FFR Player
 
Join Date: Feb 2006
Location: state of awesome
Age: 33
Posts: 4,548
Send a message via AIM to Litodude
Default Re: psa heartbleed

Quote:
Originally Posted by Untimely Friction View Post
i don't know how to read
excuse me i find your avatar offensive please take it down before i report your post
__________________
Quote:
Originally Posted by t-rogdor View Post
i finally got a weed hookup again and i texted the dude asking where to meet him tomorrow and the dude just said "out west"

dude
out west?
the fuck kinda location is west?
am i buying weed off a gotdamn pirate


Quote:
Originally Posted by lurker View Post
remind everyone that i am an outed racist neo-nazi who no one in their right mind should ever interact with in any way whatsoever

http://imgur.com/a/Ww9g3
Litodude is offline   Reply With Quote
Old 04-15-2014, 02:26 PM   #5
Untimely Friction
D6 Challeneged
Retired StaffFFR Veteran
 
Untimely Friction's Avatar
 
Join Date: Aug 2012
Age: 31
Posts: 1,267
Default Re: psa heartbleed

Quote:
Originally Posted by choof View Post
if you click on the link it tells you what this is for
I'm curious what it is before I click a random link, sorry ^^
Untimely Friction is offline   Reply With Quote
Old 04-15-2014, 03:09 PM   #6
Charu
Snivy! Dohoho!
FFR Simfile AuthorFFR Veteran
 
Charu's Avatar
 
Join Date: Mar 2006
Age: 33
Posts: 6,161
Default Re: psa heartbleed

Oh dear...

Also, with the heartbleed thingy. Even though it's a very real threat and all that good stuff, can't help but feel it's being blown out of proportion, lmao.
__________________


Quote:
Originally Posted by JohnRedWolf87 View Post
Charu the red-nosed Snivy
Had a very shiny nose
And if you ever saw it
You could even say it glows

All of the other Snivies
Used to laugh and call him names
They never let poor Charu
Join in any Snivy games

(Click the arrow to see the rest)


Quote:
Originally Posted by Vendetta21 View Post
All in all I would say that Charu not only won this game, his play made me reconsider how I play it.
Charu is offline   Reply With Quote
Old 04-15-2014, 03:10 PM   #7
One Winged Angel
Anime Avatars ( ◜◡^)っ✂╰⋃╯
Retired StaffFFR Simfile AuthorD8 Godly KeysmasherFFR Veteran
 
One Winged Angel's Avatar
 
Join Date: Mar 2007
Location: Squat Rack
Age: 34
Posts: 10,837
Default Re: psa heartbleed

Stay on topic and stop flamebaiting. If you legitimately think favoritism or lack of clarity in forum rules is an issue, contact admins via PM or some other facet.
__________________


Quote:
Originally Posted by ilikexd View Post
i want to be cucked by cirno
One Winged Angel is offline   Reply With Quote
Old 04-15-2014, 03:17 PM   #8
SC_coolguy44
Harmonoize
FFR Veteran
 
SC_coolguy44's Avatar
 
Join Date: Sep 2007
Location: In a house
Age: 32
Posts: 1,040
Send a message via Skype™ to SC_coolguy44
Default Re: psa heartbleed

Quote:
Originally Posted by Charu View Post
Oh dear...

Also, with the heartbleed thingy. Even though it's a very real threat and all that good stuff, can't help but feel it's being blown out of proportion, lmao.
Ditto. Internet safety is a really good practice, but this probably isn't nearly as big of a threat as the media is blowing it out to be.
SC_coolguy44 is offline   Reply With Quote
Old 04-15-2014, 03:21 PM   #9
Izzy
Snek
FFR Simfile AuthorFFR Veteran
 
Izzy's Avatar
 
Join Date: Jan 2003
Location: Kansas
Age: 34
Posts: 9,192
Default Re: psa heartbleed

I find it weird that this is even a real exploit. I remember learning about memory hacks like this and how to avoid them with error checking when writing C code in school. What were the developers thinking when they wrote this code? I was kind of under the impression that all of these developers were incredibly smart. Not saying I could have done any better, but when writing internet security libraries I would kind of be paranoid as fuck about this exact kind of problem.
Izzy is offline   Reply With Quote
Old 04-15-2014, 03:24 PM   #10
dAnceguy117
new hand moves = dab
FFR Simfile AuthorFFR Veteran
 
dAnceguy117's Avatar
 
Join Date: Dec 2002
Location: he/they
Age: 33
Posts: 10,094
Default Re: psa heartbleed

I think it's worth coverage from the media. it affected a ton of the internet, and the internet is used by a lot of people.

tumblr and Slack () both sent out emails warning that the sites were using vulnerable versions of OpenSSL. change your passwords! and if you use the same password across multiple sites, take extra caution. shame on you, by the way.
dAnceguy117 is offline   Reply With Quote
Old 04-15-2014, 03:32 PM   #11
choof
Banned
Retired StaffFFR Simfile AuthorD7 Elite KeysmasherFFR Veteran
 
Join Date: Nov 2013
Posts: 8,563
Default Re: psa heartbleed

Quote:
Originally Posted by SC_coolguy44 View Post
Ditto. Internet safety is a really good practice, but this probably isn't nearly as big of a threat as the media is blowing it out to be.
this vulnerability itself isn't a huge deal. it was patched pretty quickly

it's just that this exploit has been available for about a year and a half
that may not seem like a long time but... a fatal flaw, in what is easily the most widely used security protocol, that's been in circulation for nearly 1.5 years
choof is offline   Reply With Quote
Old 04-15-2014, 04:29 PM   #12
Reincarnate
x'); DROP TABLE FFR;--
Retired StaffFFR Veteran
 
Reincarnate's Avatar
 
Join Date: Nov 2010
Posts: 6,332
Default Re: psa heartbleed

Most of the big sites have fixed things up, so hopefully good to go from there
Reincarnate is offline   Reply With Quote
Old 04-15-2014, 04:42 PM   #13
Litodude
FFR Player
 
Join Date: Feb 2006
Location: state of awesome
Age: 33
Posts: 4,548
Send a message via AIM to Litodude
Default Re: psa heartbleed

Quote:
Originally Posted by One Winged Angel View Post
Stay on topic and stop flamebaiting. If you legitimately think favoritism or lack of clarity in forum rules is an issue, contact admins via PM or some other facet.
i already won
__________________
Quote:
Originally Posted by t-rogdor View Post
i finally got a weed hookup again and i texted the dude asking where to meet him tomorrow and the dude just said "out west"

dude
out west?
the fuck kinda location is west?
am i buying weed off a gotdamn pirate


Quote:
Originally Posted by lurker View Post
remind everyone that i am an outed racist neo-nazi who no one in their right mind should ever interact with in any way whatsoever

http://imgur.com/a/Ww9g3
Litodude is offline   Reply With Quote
Old 04-15-2014, 04:46 PM   #14
adlp
FFR Veteran
FFR Veteran
 
adlp's Avatar
 
Join Date: Jul 2006
Posts: 1,757
Default Re: psa heartbleed

aw dangit i missed an argument. who was it with lito
__________________
adlp is offline   Reply With Quote
Old 04-15-2014, 04:50 PM   #15
choof
Banned
Retired StaffFFR Simfile AuthorD7 Elite KeysmasherFFR Veteran
 
Join Date: Nov 2013
Posts: 8,563
Default Re: psa heartbleed

it was with untimely friction: the mod that literally no one on staff knows anything about
choof is offline   Reply With Quote
Old 04-15-2014, 05:04 PM   #16
adlp
FFR Veteran
FFR Veteran
 
adlp's Avatar
 
Join Date: Jul 2006
Posts: 1,757
Default Re: psa heartbleed

lol
__________________
adlp is offline   Reply With Quote
Old 04-15-2014, 05:04 PM   #17
MrGiggles
Senior Member
FFR Veteran
 
MrGiggles's Avatar
 
Join Date: Aug 2005
Location: Skaia
Age: 22
Posts: 2,846
Send a message via AIM to MrGiggles Send a message via MSN to MrGiggles
Default Re: psa heartbleed

Quote:
Originally Posted by SC_coolguy44 View Post
Ditto. Internet safety is a really good practice, but this probably isn't nearly as big of a threat as the media is blowing it out to be.
The bug had been around for over a year without being noticed so some enterprising hacker may have been pulling gigabytes of 'secure' data over the past year. Facebook, instagram, bank websites, online stores, etc.

Just because there isn't a sudden epidemic of stolen accounts doesn't mean nobody took advantage of this. There's no way that I know of to determine what data, if any, has been wrongfully sent out.

But in practical terms yeah it's not a huge deal if you haven't already had accounts siezed. Just change your password after everyone patches their sites.
__________________
MrGiggles is offline   Reply With Quote
Old 04-15-2014, 08:45 PM   #18
arcnmx
nanodesu~
Retired StaffFFR Veteran
 
arcnmx's Avatar
 
Join Date: Jan 2013
Location: Ontario, Canada
Posts: 503
Send a message via Skype™ to arcnmx
Default Re: psa heartbleed

Link to old thread because can I just merge it?

Quote:
Originally Posted by Charu View Post
Oh dear...

Also, with the heartbleed thingy. Even though it's a very real threat and all that good stuff, can't help but feel it's being blown out of proportion, lmao.
It's really not that blown out of proportion - it's quite serious and affects a wide range of sites. The issue is that no one knows whether it had been previous discovered or exploited, so we all generally have to assume all HTTPS traffic from the past 2 years has been unencrypted (and so will all future communication if you don't revoke and create new keys).

It also doesn't help that corporations were slow as hell to react, making a large number of sites vulnerable for days after the general public already knew how to exploit the bug. It's... really bad.

Quote:
Originally Posted by Izzy View Post
I find it weird that this is even a real exploit. I remember learning about memory hacks like this and how to avoid them with error checking when writing C code in school. What were the developers thinking when they wrote this code? I was kind of under the impression that all of these developers were incredibly smart. Not saying I could have done any better, but when writing internet security libraries I would kind of be paranoid as fuck about this exact kind of problem.
Yup, all it takes is one wrong length passed to memcpy and/or the lack of a bounds check. Also OpenSSL is written by monkeys (yes, ironic SSL cert warning, ignore it)
__________________


FMO AAAs (1): Within Life :: FGO AAAs (1): Einstein-Rosen Bridge
arcnmx is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



All times are GMT -5. The time now is 06:23 AM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright FlashFlashRevolution