SUBSIM Radio Room Forums

SUBSIM Radio Room Forums (https://www.subsim.com/radioroom/index.php)
-   General Topics (https://www.subsim.com/radioroom/forumdisplay.php?f=175)
-   -   subsim.com is NOT affected by Heartbleed (https://www.subsim.com/radioroom/showthread.php?t=212573)

Skybird 04-10-14 07:53 AM

subsim.com is NOT affected by Heartbleed
 
UPDATE:
OK, THERE IS NO ISSUE HERE,

Quote:

You are not vulnerable. You don't have Ssl enabled.
per my server manager.



-- Neal



.


.



.


.I just ran a test from this site:

http://possible.lv/tools/hb/

Result:

http://www7.pic-upload.de/10.04.14/g747vviz2575.jpg


Uncle Neal, take over!!!

A test being negative and concluding the tested site is not vulnerable, would look like this:

http://www7.pic-upload.de/10.04.14/c9n1opit8crm.jpg

Once Neal has fixed this, change of passwords is on order, guys. The risk lies in malicious trolls abuzsing your identity, and maybe even in the linking from subsim to Amazon - I do not know the latter, just remind that such a link exists on this website via the direct-buttons that Neal advertises. Whether your Amazon account could become corrupted if contacting Amazon via the subsim-buttons, I do not know. This heartbleed thing just is a core meltdown, and so I say: better safe than sorry.

kranz 04-10-14 08:32 AM

I read '...is affected by butthurt'.

well, not much of a difference.

STEED 04-10-14 08:34 AM

NOOOOOOOOOOOOO........:/\\!!

Jimbuna 04-10-14 08:43 AM

I'll run a few of my usuals through this...cheers.

BossMark 04-10-14 08:55 AM

Oh bugger!! so what does that mean?

STEED 04-10-14 09:08 AM

OK I have changed my password for here to sexysod@sexy4589. :03:

Rhodes 04-10-14 09:18 AM

Quote:

Originally Posted by STEED (Post 2196018)
sexysod@sexy4589. :03:

uhhhhhh.....

STEED 04-10-14 09:23 AM

Quote:

Originally Posted by Rhodes (Post 2196023)
uhhhhhh.....

That was a password but no longer.

That is to say not here but else where.

adrian_airbaby 04-10-14 09:40 AM

Apparently it's not an actual threat just yet. It's a future threat though,
and hi everyone, long time lurker here :)

Skybird 04-10-14 11:14 AM

No, it is a thread coming from data that since long has been copied from servers. Since that data already is lost and the security certificates are corrupted, one must assume that all data that can be lost indeed IS lost. That data can reveal your identity can contain relevant codes and data allowing access to accounts you use, can decypher encrypted emails, and much more. You cannot press that genie back into the bottle anymore, it escaped. Possible that some people will get hit by that. Even if certificates and SSL software on servers can changed and patched, the already lost data remains to be lost, and can be used against you.

It's like a bottle leaking. The liquid already lost, remains to be lost, and may ruin your carpet. You can tighten the cap and replace it, and it then is properly sealed - but the liquid that already escaped, doe snot come back, and when it hit the carpet, you still will see the effect, no matter new cap or not.

Maybe this will heal some of the many incorrigible digital optimists who never see no harm coming from destruction of data protection and privacy, and from new technology in general, but I doubt it. Some cattle may stumble and drown when crossing a river. But the mass of the herd will just move on, uncaring. :dead:

Wolferz 04-10-14 11:42 AM

Somebody changed my password to... 12345:stare:

the_tyrant 04-10-14 12:44 PM

There is nothing to worry about guys, nothing to see here.

heartbleed is an ssl vulnerability. AKA, what you thought was encrypted may very well not have been encrypted.

However, subsim never even used SSL! In fact, if you read the message in the first picture, it said "error connecting" on port 443, well of course it would say that, subsim doesn't support SSL in the first place!


Now Neal, if you would like to enable SSL encryption for subsim, I'll gladly buy a certificate for you. PM me.

Onkel Neal 04-10-14 01:00 PM

I'm on it. :salute:

Although Subsim is not https

Jimbuna 04-10-14 01:02 PM

Quote:

Originally Posted by adrian_airbaby (Post 2196031)
Apparently it's not an actual threat just yet. It's a future threat though,
and hi everyone, long time lurker here :)

Welcome :sunny:

Jimbuna 04-10-14 01:03 PM

Quote:

Originally Posted by BossMark (Post 2196014)
Oh bugger!! so what does that mean?

Your bank account details are now in my possession :smug:

STEED 04-10-14 01:37 PM

Quote:

Originally Posted by Jimbuna (Post 2196132)
Your bank account details are now in my possession :smug:

BossMarks passes on all his love as you have all his debts now. :har:

BTW: BossMark is swimming in a lake of beer and is enjoying every moment of it. :DL

Onkel Neal 04-10-14 02:06 PM

OK, THERE IS NO ISSUE HERE,

Quote:

You are not vulnerable. You don't have Ssl enabled.
per my server manager.

All; in the future, please contact me via PM if you have any questions or concerns of this nature. We don't need false alarms.

Neal

.

STEED 04-10-14 02:09 PM

Great now we can stand down from strong coffee back to beer.

BossMark will be pleased. :()1:

Skybird 04-10-14 02:47 PM

Quote:

Originally Posted by Neal Stevens (Post 2196153)
OK, THERE IS NO ISSUE HERE,


per my server manager.

All; in the future, please contact me via PM if you have any questions or concerns of this nature. We don't need false alarms.

Neal

.

Glad to learn that!

mapuc 04-10-14 02:59 PM

about this Heartbleed and other "Anti-internet" stuff

For years I had an idea of a 110 % secure line between my homepage and a member/customer.

The idea

When a person open my Internet page and this person want to become a member or order something. He or she can't

First he or she have to filled in their fully name and adress
There after I will send them aRecommended mail.

In this mail there will be a Disk with a safetyprogram * , which this new member shall install on his or her computer

* It will be more than 256(forgot the name)

Thereby the will be a secure line* between my homepage and the member/customer

* I resume that this person have the lastest update on his or her Antivirus, firewall and windows update or other OS update.

As my cousin said, no one want to much work, they want it simple very simple, so my idea was no good.

Markus


All times are GMT -5. The time now is 04:29 AM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright © 1995- 2025 Subsim®
"Subsim" is a registered trademark, all rights reserved.