Heartbleed: 5 things you need to do right now

Heartbleed
The Heartbleed bug is revealing itself as a serious security risk

The Heartbleed vulnerability - otherwise known as CVE-2014-0160 - is one of the most serious security flaws ever to emerge. Its impact has yet to be fully assessed and, given that it has gone undetected for two years, it is likely that we will never know exactly how much damage its responsible for. To stop yourself from becoming one of the victims, here are five things you need to do now to save yourself from Heartbleed.

1. Check whether websites or services you use are safe

Most big websites such as Google or Amazon can be considered safe. There is a continually-updated list of vulnerable websites currently sitting on GitHub. The initial leaderboard has 10,000 websites obtained from Analytics company, Alexa. While the BBC and Apple are not at risk, others like online retailer Farnell or PR website, Cision, were still vulnerable at the time of writing. You can check individual websites for the Heartbleed vulnerability using this online service.

2. Don't panic

There's no need to buy additional security package if you already have a decent, recently updated antivirus suite. There will inevitably be scams that aim to capitalize on the uncertainty surrounding Heartbleed, but don't let concerns about one vulnerability lead you to expose yourself to something even more malicious. Only 600 out of the top 10,000 websites on the web are vulnerable and that number is decreasing by the hour.

3. Change your password

You should change your password regularly anyway. But make sure that you do that after the service or site has been updated, otherwise your new passwords will be exposed too. Check out our tutorial on how to make your passwords more secure. If you're a business owner, you might want to evaluate security across your company at the same time.

4. Keep a close eye on your online transactions

Your personal details could have already been compromised given that knowledge of the bug was already in the wild for a few days already. While it might be too late to take preventive action, you should still check your bank accounts regularly - this is where criminals are likely to hit first. If you haven't already done it, we strongly advise you to enable two-step authentication which is an additional obstacle for hackers and often requires some sort of physical interaction.

5. Demand action

As a consumer, it is only fair to know whether your data is securely stored or whether websites you visit have been properly patched. So, ask online retailers or services you use whether they have taken remedial actions to eradicate the Heartbleed bug.

Desire Athow
Managing Editor, TechRadar Pro

Désiré has been musing and writing about technology during a career spanning four decades. He dabbled in website builders and web hosting when DHTML and frames were in vogue and started narrating about the impact of technology on society just before the start of the Y2K hysteria at the turn of the last millennium.

Latest in Pro
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
ai quantization
Shadow AI: the hidden risk of operational chaos
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Digital clouds against a blue background.
Navigating the growing complexities of the cloud
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Latest in News
FiiO FX17 IEMs
Our favorite budget audiophile brand unveils wired earbuds with 26(!) drivers, electrostatic units, USB-C ultra-Hi-Res Audio, and a not-so-budget price
girl using laptop hoping for good luck with her fingers crossed
Windows 11 24H2 seems to be a massive fail – so Microsoft apparently working on 25H2 fills me with hope... and fear
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
ChatGPT Advanced Voice mode on a smartphone.
Talking to ChatGPT just got better, and you don’t need to pay to access the new functionality
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
Apple Watch Ultra 2 timer
The Apple Watch is getting a sleep alarm upgrade it probably should have had 10 years ago