Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. Have you changed your password?

Have you changed your password?

Scheduled Pinned Locked Moved The Lounge
comsecurityhelpquestion
4 Posts 3 Posters 1 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K Offline
    K Offline
    Kenneth Haugland
    wrote on last edited by
    #1

    Perhaps you should[^]? The government here is suggesting I do it anyway.

    Z 1 Reply Last reply
    0
    • K Kenneth Haugland

      Perhaps you should[^]? The government here is suggesting I do it anyway.

      Z Offline
      Z Offline
      ZurdoDev
      wrote on last edited by
      #2

      Perhaps I read it wrong, but the vulnerability allows someone to get the encryption keys that are used so at that point it won't matter how often you change your password, they can decrypt the traffic directly.

      There are only 10 types of people in the world, those who understand binary and those who don't.

      K P 2 Replies Last reply
      0
      • Z ZurdoDev

        Perhaps I read it wrong, but the vulnerability allows someone to get the encryption keys that are used so at that point it won't matter how often you change your password, they can decrypt the traffic directly.

        There are only 10 types of people in the world, those who understand binary and those who don't.

        K Offline
        K Offline
        Kenneth Haugland
        wrote on last edited by
        #3

        Seems like it was a server side[^] issue that could be problematic. And here[^] as well. I think its just a problem if you have the same password everywhere.

        1 Reply Last reply
        0
        • Z ZurdoDev

          Perhaps I read it wrong, but the vulnerability allows someone to get the encryption keys that are used so at that point it won't matter how often you change your password, they can decrypt the traffic directly.

          There are only 10 types of people in the world, those who understand binary and those who don't.

          P Offline
          P Offline
          Paul Watson
          wrote on last edited by
          #4

          Yes, only change your password after the service have patched OpenSSL and reissued their SSL cert.

          cheers, Paul M. Watson.

          1 Reply Last reply
          0
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Don't have an account? Register

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • World
          • Users
          • Groups