Page 1 of 1

Heartbleed bug, change passwords?

Posted: Wed Apr 09, 2014 2:05 am
by Tzupy
Should SPCR forum members change their passwords, since they may have been compromised due to the OpenSSL heartbleed bug?

Re: Heartbleed bug, change passwords?

Posted: Wed Apr 09, 2014 8:13 am
by HFat
I'd be grateful if you didn't change my password. :-)

Your passwords on more sensitive sites than SPCR might or might not have been compromised years ago by bugs you never heard about, by breaches unrelated to bugs or even by design.
The new announcement about this old bug is mainly for people who run servers or sites.
But of course it never hurts to periodically change your important passwords and not use the same ones on many sites (or equivalent). Don't forget to change other stuff as well because it's not only passwords which are affected. The important thing to realize is that this isn't something you should do only this once.

Re: Heartbleed bug, change passwords?

Posted: Wed Apr 09, 2014 11:16 am
by johannes
SPCR does not use HTTPS and is thus not affected by Heartbleed.

On the other hand, the lack of encryption means that anybody between you and the SPCR server (somebody on the same open WIFI, your ISP, routers in between) could read your password, so you might want to avoid reusing the password you use at SPCR. (And change it elsewhere if you reused it.)

Re: Heartbleed bug, change passwords?

Posted: Sun Apr 20, 2014 6:32 pm
by aristide1
My precautions tend to be more like pull more cash out of the ATM and use that at Target and other stores for small purchases. I don't need this crap. The fewer transactions you create anywhere the safer you are.

Re: Heartbleed bug, change passwords?

Posted: Mon Apr 21, 2014 4:55 am
by Vicotnik
I don't trust the ATMs. Safer to use a card imo.

Re: Heartbleed bug, change passwords?

Posted: Mon Apr 21, 2014 8:05 am
by xan_user
Vicotnik wrote:I don't trust the ATMs. Safer to use a card imo.
I dont trust banks (and sure as hell dont want to give them any business after the meltdown/land-grab). safer to use cash.

Re: Heartbleed bug, change passwords?

Posted: Tue Apr 22, 2014 10:59 pm
by Vicotnik
xan_user wrote:I dont trust banks (and sure as hell dont want to give them any business after the meltdown/land-grab). safer to use cash.
For me it's more the danger of giving away too much information that bothers me with not using cash. My credit card is free, and they kick back 1% to me on everything I purchase. But they are watching me.. Feeding them bogus data as often as I can, buy stuff for friends etc. They give me money later, I get the 1% bonus, win-win.
I get the feeling that the risk of getting ripped off is bigger with cash though. I read about modified ATMs and such.

Not to use money at all is best. Gift economy for the win. :)

Re: Heartbleed bug, change passwords?

Posted: Wed Apr 23, 2014 3:12 am
by HFat
Vicotnik wrote:They give me money later, I get the 1% bonus, win-win.
Except for the person who sells you the goods (or service). They have to pay for it all.

I'm glad I live in a country where many merchants routinely charge customers extra if they insist on using this sort of credit card.

Re: Heartbleed bug, change passwords?

Posted: Wed Apr 23, 2014 7:50 am
by Vicotnik
HFat wrote:Except for the person who sells you the goods (or service). They have to pay for it all.
It hurts their bottom line, sure. But handling cash also costs money. Not doing business with them at all is also no good from their perspective.

When you use money; cash, card or whatever, you have already lost. ;) No ethical way to do it.
HFat wrote:I'm glad I live in a country where many merchants routinely charge customers extra if they insist on using this sort of credit card.
This sort of credit card? A VISA card is like any other VISA card, right? With my previous card I payed a yearly fee and got no kickback on my purchases. Did I hurt the merchants less with that card?

In Sweden adding a "card fee" is illegal. I think it would be proper on small purchases, since the transfer fee eats up the earnings and then some. I use cash for small stuff in the local grocery store for this reason.

Re: Heartbleed bug, change passwords?

Posted: Wed Apr 23, 2014 9:19 am
by HFat
Vicotnik wrote:When you use money; cash, card or whatever, you have already lost. ;) No ethical way to do it.
Do you always deny the facts the of the matter this way?

Doesn't Sweden have its own financial system?
Vicotnik wrote:This sort of credit card? A VISA card is like any other VISA card, right? With my previous card I payed a yearly fee and got no kickback on my purchases. Did I hurt the merchants less with that card?
This sort meaning the VISA sort obviously: gringo credit cards. The perks of lack thereof hardly matter.

Re: Heartbleed bug, change passwords?

Posted: Wed Apr 23, 2014 10:58 pm
by Vicotnik
Well, I'm stating my opinion and asks for the facts. You obviously have a better grasp than me when it comes to these things. Usually you are very helpful; one has to weed out the insults, but the gist of what you are saying makes sense. Most of the time. ;)

Re: Heartbleed bug, change passwords?

Posted: Thu Apr 24, 2014 6:07 am
by CA_Steve
I'm going to change the name of this thread to Eyebleed, soon.