Author Topic: OpenSSL Heartbleed Vulnerability ?  (Read 2005 times)

0 Members and 1 Guest are viewing this topic.

Offline xeroc

  • Board Moderator
  • Hero Member
  • *****
  • Posts: 12922
  • ChainSquad GmbH
    • View Profile
    • ChainSquad GmbH
  • BitShares: xeroc
  • GitHub: xeroc
If you have RPC enabled on a public interface and allow other ip addresses to open a SSL connection you SHOULD be concerned and upgrade/disable immediatelly

Offline unimercio

  • Sr. Member
  • ****
  • Posts: 245
  • The opportunity of a lifetime comes by every 7 day
    • View Profile
    • Conscious Entrepreneurship Foundation (CEF)
  • BitShares: unimercio
theres no issue unless you use RPC over SSL!

thanks, so http port 80 connections are safe just not encrypted.  I wonder why Vertcoin, etc.. are issuing wallet alerts?

http://www.bitcoinfeed.net/news/vertcoin-please-upgrade-your-wallet-immediately-due-to-heartbleed-bug-in-openssl-which-could-allow-your-vertcoins-to-be-stolen
Conscious Entrepreneurship Foundation (CEF)

Offline xeroc

  • Board Moderator
  • Hero Member
  • *****
  • Posts: 12922
  • ChainSquad GmbH
    • View Profile
    • ChainSquad GmbH
  • BitShares: xeroc
  • GitHub: xeroc
theres no issue unless you use RPC over SSL!

Offline unimercio

  • Sr. Member
  • ****
  • Posts: 245
  • The opportunity of a lifetime comes by every 7 day
    • View Profile
    • Conscious Entrepreneurship Foundation (CEF)
  • BitShares: unimercio
Any thoughts, concerns on the OpenSSL Heartbleed vulnerability and PTS.

http://www.bitcoinfeed.net/news/bitcoin-bitcoin-security-company-bitgo-responds-to-the-heartbleed-security-threat

“It’s fundamental to tell everyone to check all their servers and update ASAP [...] I can’t obviously be positive about it, but bitcoin-specific software (local wallets, etc.) should not be affected even if they use OpenSSL, since the bug is only triggerable in live TLS connections.”


Ps. Vertcoin has released an update to their wallet.

Bump
+5% thanks fuzz
Conscious Entrepreneurship Foundation (CEF)

Offline fuzzy

Any thoughts, concerns on the OpenSSL Heartbleed vulnerability and PTS.

http://www.bitcoinfeed.net/news/bitcoin-bitcoin-security-company-bitgo-responds-to-the-heartbleed-security-threat

“It’s fundamental to tell everyone to check all their servers and update ASAP [...] I can’t obviously be positive about it, but bitcoin-specific software (local wallets, etc.) should not be affected even if they use OpenSSL, since the bug is only triggerable in live TLS connections.”


Ps. Vertcoin has released an update to their wallet.

Bump
WhaleShares==DKP; BitShares is our Community! 
ShareBits and WhaleShares = Love :D

Offline unimercio

  • Sr. Member
  • ****
  • Posts: 245
  • The opportunity of a lifetime comes by every 7 day
    • View Profile
    • Conscious Entrepreneurship Foundation (CEF)
  • BitShares: unimercio
Any thoughts, concerns on the OpenSSL Heartbleed vulnerability and PTS.

http://www.bitcoinfeed.net/news/bitcoin-bitcoin-security-company-bitgo-responds-to-the-heartbleed-security-threat

“It’s fundamental to tell everyone to check all their servers and update ASAP [...] I can’t obviously be positive about it, but bitcoin-specific software (local wallets, etc.) should not be affected even if they use OpenSSL, since the bug is only triggerable in live TLS connections.”


Ps. Vertcoin has released an update to their wallet.
« Last Edit: April 09, 2014, 06:29:55 am by unimercio »
Conscious Entrepreneurship Foundation (CEF)