As a regular Internet user, you expect the background of the Internet to just work. Everything that goes on behind the scenes, all the encryption, all of the handshakes, and every little transaction should be able to provide you with a safe way to communicate and do your business online without having to worry about hackers prowling at your every move. Unfortunately that’s not how the Internet works, and the OpenSSL “Heartbleed” bug is definitive proof of this. There are some things you should know about this bug because, in all likelihood, it pertains to you more than you think.

What Is OpenSSL?!

OK, so I mentioned OpenSSL twice and didn’t even explain it to you. Do you see the little lock icon next to the “https://” on your browser when you enter “secure” sites? It looks something like this on Google’s Chrome web browser:

opensslbug-paypal

When you see that, you’re using a special form of encryption known as secure socket layer (SSL) or transport layer security (TLS). To provide services with this encryption, you need an algorithm that will provide the encryption/decryption for the packets you exchange with the server. This means that they need to have a way to translate your text into unreadable gibberish and then translate it back from that into the readable form on their own end. Using this technology, if a hacker somehow manages to interfere with your connection to the server, all he’ll read is a long string of babble.

Now, we get to the part (finally) where we explain what OpenSSL is: It’s a free and open-source implementation of SSL/TLS protocols. With this technology, anyone can provide encrypted services to you. Many companies you have accounts with may use OpenSSL to encrypt your data.

But what if OpenSSL has a bug that completely defeats the purpose of encryption?

The Bug Explained

opensslbug-heartbleed

On April 10, 2014, the folks at PerfectCloud, an identity security company, have reported on a massive hole in OpenSSL’s coding known as the “Heartbleed” bug. For two years, we haven’t seen a new version of OpenSSL, and during that time it had a problem in its code which exposed a bit of server memory. This memory chunk could contain the private keys that are used to encrypt/decrypt data. Ouch!

What this means is that a hacker could discover the server’s cryptographic keys and simply decrypt everything you send to it, including your username, your password, and everything else that’s important and dear to you.

The bug was fixed on April 7th, 2014, but that doesn’t mean that everyone’s followed through with an update to their implementations of OpenSSL. Major Internet companies like Amazon and Yahoo have taken care of the issue, but that still doesn’t mean you’re in the clear! A hacker could have your username and password on a list right now ready to be used to try to access any other accounts you may have elsewhere.

What Should You Do?

So, even if a company upgrades to the latest OpenSSL implementation, you’re still at risk for previous exposures. However, if there are any further hacking attempts, they won’t succeed. What you can do in this situation is change your password everywhere. Don’t let it wait. Just change everything so that you’re prepared if a hacker ever decides to try out your accounts.

Any More Thoughts?

This bug simply shows how delicate and interwoven the Internet is. Despite its booming security awareness and unregulated awesomeness, the Internet is still the internet, and it will always be under siege. What recommendations do you have for companies that use OpenSSL? How did your understanding of security ecosystems change? Are you confused about something? Post your thoughts on anything related to OpenSSL in the comments area below!

Turn Multi-Page Articles Into a Continuously Scrolling Single Page

Have you ever clicked on an article that was broken up into numerous pages? Those multi-page articles can be really annoying and time-consuming. If you’re tired of clicking “next” over and over again, here’s how to turn those multi-page articles into a single page.

Why You Should Have Local Backups Of Your Cloud Backup

When it comes to cloud storage, one of the things you shouldn’t do is to place all your eggs in one basket. You should also take the precaution to backup the data to somewhere you can physically access. Allow me to explain why.

4 Reasons Why A Third Party DNS Server Is Better Than What Your ISP Gives You

You’ve probably heard of alternate DNS servers and how they could probably help you in some way or another. You may also wonder why you need to switch over. I’m going to give you some reasons why you probably should be using third party DNS server. You will end up wondering why you haven’t done it yet.

Get a Better Extension Manager In Chrome With SimpleExtManager

The extension manager in Chrome has always given users the bare minimum to work with when dealing with extensions, themes and apps. The SimpleExtManager for Chrome gives users the functionality they deserve.

How to Encrypt Your Gmail Message and Protect Your Privacy

If you are really concern about the privacy of your email, you should really consider encrypt your Gmail message so even Google can’t view it.

Don’t Like Gmail’s New Always Display External Images Feature? Here’s How to Disable It

By default, Google has decided to make it so that Gmail will always display external images in your email. If you don’t like this, here’s how to disable it.

7 YouTube Channels Where You Can Find Computer Help

If you find video content more gripping, there is a gamut of YouTube channels that are waiting to help you solve your technology woes. Here are 7 of them.

Using the Google Drive Form Feature as an Organizational Tool

Google Drive has a hidden function with Forms, and while it creates great surveys and quizzes, it can also be used as a useful organizational tool.

3 Reasons Why Encryption Is Not as Safe as You May Believe

What if I tell you that your encrypted data may already be cracked by the hackers? Here are some examples why encryption is not as safe as you may believe.

How to Copy Multiple Texts in Firefox

For those who like copying text from multiple web pages, Text MultiCopy for Firefox allows you to copy multiple texts and paste them all at the same time.

Should I Use a Website Creator or Hire a Web Designer?

If you are starting to setup your website, it can be hard to decide whether to hire a web designer or go with the different DIY website creators out there. Here are some points you should consider.

How to Stop Firefox from Sending Downloaded File Information to Google

Firefox version 31 comes with a feature that checks your downloaded file with Google for malware. You can disable it if you are concerned about your privacy.