{"id":723,"date":"2014-04-09T18:46:24","date_gmt":"2014-04-09T18:46:24","guid":{"rendered":"http:\/\/paulgurney.com\/whats_new_blog\/?p=723"},"modified":"2014-04-10T18:47:56","modified_gmt":"2014-04-10T18:47:56","slug":"be-aware-of-the-heartbleed-bug","status":"publish","type":"post","link":"https:\/\/paulgurney.com\/whats_new_blog\/2014\/04\/be-aware-of-the-heartbleed-bug\/","title":{"rendered":"Be aware of the Heartbleed bug"},"content":{"rendered":"<p>On April 8 I was notified by WiredTree, our hosting company, that their servers had been patched against a newly discovered (and serious) flaw in the SSL encryption technology which underpins secure browsing over https.<\/p>\n<p>It is called the Heartbleed bug.<\/p>\n<p>Our servers were not affected, as they ran CentOS5 and did not use Litespeed. Other sites which did use LiteSpeed were affected.<\/p>\n<p>Read more at:<br \/>\n<a href=\"http:\/\/heartbleed.com\/\">http:\/\/heartbleed.com\/<\/a><br \/>\n<a href=\"https:\/\/blog.cloudflare.com\/staying-ahead-of-openssl-vulnerabilities\">https:\/\/blog.cloudflare.com\/staying-ahead-of-openssl-vulnerabilities<\/a><\/p>\n<p><strong>UPDATE<\/strong><\/p>\n<p>An <a title=\"heartbleed bug creator\" href=\"http:\/\/www.dailydot.com\/technology\/heartbleed-bug-robin-seggelmann\/\" target=\"_blank\">article on Thursday<\/a> explains how the bug crept in the Open Source software.<\/p>\n<blockquote>\n<p dir=\"ltr\"><a href=\"http:\/\/www.dailydot.com\/tags\/heartbleed\/\">Heartbleed<\/a>, a \u201c<a href=\"https:\/\/www.schneier.com\/blog\/archives\/2014\/04\/heartbleed.html\">catastrophic<\/a>\u201d security flaw in the OpenSSL cryptographic protocol that has affected two-thirds of the entire Internet\u2019s communications, was\u00a0<a href=\"http:\/\/git.openssl.org\/gitweb\/?p=openssl.git;a=commit;h=4817504d069b4c5082161b02a22116ad75f822b1\">committed\u00a0<\/a>at 10:59 pm on New Year\u2019s Eve by Seggelmann, a 31-year-old M\u00fcnster, Germany-based programmer.<\/p>\n<p dir=\"ltr\">That night, he made an error that has been compared to the misspelling of Mississippi, a careless but almost inevitable mistake that went undetected for over two years.<\/p>\n<\/blockquote>\n<p dir=\"ltr\">\n","protected":false},"excerpt":{"rendered":"<p>On April 8 I was notified by WiredTree, our hosting company, that their servers had been patched against a newly discovered (and serious) flaw in the SSL encryption technology which underpins secure browsing over https. It is called the Heartbleed bug. Our servers were not affected, as they ran CentOS5 and did not use Litespeed. &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/paulgurney.com\/whats_new_blog\/2014\/04\/be-aware-of-the-heartbleed-bug\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Be aware of the Heartbleed bug&#8221;<\/span><\/a><\/p>\n","protected":false},"author":55,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[8,22,15,9,12],"tags":[],"class_list":["post-723","post","type-post","status-publish","format-standard","hentry","category-programming","category-security","category-technology","category-webhosting","category-website"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p415hC-bF","_links":{"self":[{"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/posts\/723","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/comments?post=723"}],"version-history":[{"count":2,"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/posts\/723\/revisions"}],"predecessor-version":[{"id":725,"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/posts\/723\/revisions\/725"}],"wp:attachment":[{"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/media?parent=723"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/categories?post=723"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/paulgurney.com\/whats_new_blog\/wp-json\/wp\/v2\/tags?post=723"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}