Here's some really bad Heartbleed bug advice about changing your passwords

Here's some really bad Heartbleed bug advice about changing your passwords
Heartbleed - this is the advice you need

A lot of folks are going around at the moment telling the public to change all of their passwords in response to the serious Heartbleed internet security bug.

For instance, here's what the Tumblr website (owned by Yahoo) has told its users: "This might be a good day to call in sick and take some time to change your passwords everywhere - especially your high-security services like email, file storage, and banking, which may have been compromised by this bug"

That's awful advice.

You should only change your password in response to the Heartbleed bug after a website or internet company has:

  1. Checked to see if it is vulnerable
  2. Patched its systems
  3. Grabbed a new SSL certificate
  4. Told you it is fixed

Ideally they would initiate a mandatory change of passwords at that point. (By the way, when you do change your password, remember to also enable two factor authentication if the website or service offers it - as it will increase your overall level of security in the long run).

The danger is that if you change your passwords before a website has been fixed, you might actually be exposing your credentials to greater risk of being snarfled up by people exploiting the vulnerability in the buggy versions of OpenSSL.

Don't forget - there are an awful lot more people now testing to see how well the vulnerability can be exploited now that details are public.

Sadly, mainstream media are proving to be a little guilty of parroting the advice of the likes of Tumblr.

Check out this BBC News article, for instance, entitled "Heartbleed Bug: Tech firms urge password reset". You have to scroll way down the article before you realise that actually you shouldn't change all your passwords, but instead wait until a website has fixed the flaw.

And, if a website you use hasn't made clear if they have fixed the problem (or indeed if they were ever vulnerable) then the best thing you can do is badger them into telling you.

This article was originally posted at Graham Cluley's blog.

Latest in Computing Security
ensure data security for your business
The complete data protection system for your business
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Man uses a laptop in a hotel room
4 ways to avoid misinformation on social media and retain control of your newsfeed
Apple
"We will never build a backdoor" – Apple kills its iCloud's end-to-end encryption feature in the UK
DeepSeek
DeepSeek accused of sharing users' data with TikTok's ByteDance in another blow around privacy concerns
This photograph shows wordmark of Siri, a digital assistant developed by Apple Inc., displayed on a smartphone
Did Siri break the law? Apple's latest privacy complaint in France doesn't bode well
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day