Click here to Skip to main content
15,890,512 members

Welcome to the Lounge

   

For discussing anything related to a software developer's life but is not for programming questions. Got a programming question?

The Lounge is rated Safe For Work. If you're about to post something inappropriate for a shared office environment, then don't post it. No ads, no abuse, and no programming questions. Trolling, (political, climate, religious or whatever) will result in your account being removed.

 
GeneralRe: Misuse of the Quick Answers Forum Pin
Duncan Edwards Jones15-Apr-14 4:59
professionalDuncan Edwards Jones15-Apr-14 4:59 
GeneralRe: Misuse of the Quick Answers Forum Pin
gggustafson15-Apr-14 5:08
mvagggustafson15-Apr-14 5:08 
GeneralTaking a Bus - From this quarter's MERG bulletin... Pin
Ger Hayden13-Apr-14 8:12
Ger Hayden13-Apr-14 8:12 
GeneralRe: Taking a Bus - From this quarter's MERG bulletin... Pin
dan!sh 13-Apr-14 8:21
professional dan!sh 13-Apr-14 8:21 
GeneralRe: Taking a Bus - From this quarter's MERG bulletin... Pin
dan!sh 13-Apr-14 8:22
professional dan!sh 13-Apr-14 8:22 
GeneralRe: Taking a Bus - From this quarter's MERG bulletin... Pin
Ger Hayden14-Apr-14 8:31
Ger Hayden14-Apr-14 8:31 
RantI hate Cengage's SAM system Pin
Brisingr Aerowing13-Apr-14 6:58
professionalBrisingr Aerowing13-Apr-14 6:58 
GeneralThe Heartbleed Bug Pin
Espen Harlinn13-Apr-14 5:03
professionalEspen Harlinn13-Apr-14 5:03 
I guess just about all of us have now heard about the heartbleed bug[^].

From the rather massive media coverage it appears that this can be exploited in ways that allows an attacker to potentially retrieve logon information such as user names and passwords.

If this is possible, it also means that the actual password, and not a cryptographic digest, has been sendt to the server - and that the actual real password is kept in memory, and that it is either stored locally by the server, or the server can retrieve the password from another server on the network, or farward it to another server for authentication.

Even if there was no heartbleed bug, this sounds like a f***up on a much grander scale than the heartbleed bug, because it makes it likely that a lot of people believe they have implemented strong security, while actually implementing something that is quite vulnerable.

Thoughts anybody? or jokes (if you can come up with good ones)

[Update]
Just to be clear: I think we should allways use transport level security, and even then we should never send the password in a form that can be easily reconstructed.
Espen Harlinn
Principal Architect, Software - Goodtech Projects & Services AS

Projects promoting programming in "natural language" are intrinsically doomed to fail. Edsger W.Dijkstra


modified 14-Apr-14 6:00am.

GeneralRe: The Heartbleed Bug Pin
Jörgen Andersson13-Apr-14 5:25
professionalJörgen Andersson13-Apr-14 5:25 
GeneralRe: The Heartbleed Bug Pin
Espen Harlinn13-Apr-14 8:50
professionalEspen Harlinn13-Apr-14 8:50 
GeneralRe: The Heartbleed Bug Pin
OriginalGriff13-Apr-14 5:39
mveOriginalGriff13-Apr-14 5:39 
JokeRe: The Heartbleed Bug Pin
Wes Aday13-Apr-14 5:56
professionalWes Aday13-Apr-14 5:56 
GeneralRe: The Heartbleed Bug Pin
OriginalGriff13-Apr-14 6:09
mveOriginalGriff13-Apr-14 6:09 
GeneralRe: The Heartbleed Bug Pin
dan!sh 13-Apr-14 8:09
professional dan!sh 13-Apr-14 8:09 
GeneralRe: The Heartbleed Bug Pin
Wes Aday13-Apr-14 10:34
professionalWes Aday13-Apr-14 10:34 
GeneralRe: The Heartbleed Bug Pin
Espen Harlinn13-Apr-14 8:56
professionalEspen Harlinn13-Apr-14 8:56 
GeneralRe: The Heartbleed Bug Pin
Chris Maunder13-Apr-14 16:41
cofounderChris Maunder13-Apr-14 16:41 
GeneralRe: The Heartbleed Bug Pin
OriginalGriff13-Apr-14 20:24
mveOriginalGriff13-Apr-14 20:24 
GeneralRe: The Heartbleed Bug Pin
Munchies_Matt13-Apr-14 6:37
Munchies_Matt13-Apr-14 6:37 
GeneralRe: The Heartbleed Bug Pin
Espen Harlinn13-Apr-14 9:04
professionalEspen Harlinn13-Apr-14 9:04 
GeneralRe: The Heartbleed Bug Pin
dan!sh 13-Apr-14 9:27
professional dan!sh 13-Apr-14 9:27 
GeneralRe: The Heartbleed Bug Pin
Munchies_Matt13-Apr-14 13:10
Munchies_Matt13-Apr-14 13:10 
GeneralRe: The Heartbleed Bug Pin
J. Adam Armstrong13-Apr-14 14:49
J. Adam Armstrong13-Apr-14 14:49 
GeneralRe: The Heartbleed Bug Pin
Espen Harlinn13-Apr-14 23:41
professionalEspen Harlinn13-Apr-14 23:41 
GeneralRe: The Heartbleed Bug Pin
Chris Maunder13-Apr-14 16:46
cofounderChris Maunder13-Apr-14 16:46 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.