We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Change Your Passwords

Options
SailorSam
SailorSam Posts: 22,754 Forumite
10,000 Posts Combo Breaker
Several tech companies including Tumblr are advising people to change all their passwords after the discovery of a major security flaw.

http://www.bbc.co.uk/news/technology-26954540
Liverpool is one of the wonders of Britain,
What it may grow to in time, I know not what.

Daniel Defoe: 1725.
«13

Comments

  • abibee
    abibee Posts: 441 Forumite
    Part of the Furniture
    edited 9 April 2014 at 9:34PM
    It's good practice to change your passwords from time to time anyway. Not that I do, I still use password123... do'h!

    Edit: I never read the article you posted before my reply, I've only just done so now. That sounds pretty serious. I use Lastpass and different passwords on every site e-mail etc, but still, I think I may change a few of them tonight.

    Thanks for posting.
  • Ant555
    Ant555 Posts: 1,596 Forumite
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    If you change your password on a site that is yet to be fixed/patched (and there will be millions of them) then you are still in the same boat.

    I was wondering how a person could tell if a site was unaffected and found this link
    http://filippo.io/Heartbleed/

    Ive tried out a few of the main sites I use and they all seem to be OK.
    MSE checks out fine according to them by the way.
  • wigglebeena
    wigglebeena Posts: 1,988 Forumite
    You can test here. https://www.ssllabs.com/ssltest/index.html

    What banks are safe? Why are none of them making any reference or announcement on their sites?
  • Jivesinger
    Jivesinger Posts: 1,221 Forumite
    Ninth Anniversary Combo Breaker
    Ant555 wrote: »
    If you change your password on a site that is yet to be fixed/patched (and there will be millions of them) then you are still in the same boat.
    Indeed. This article says much the same thing -you might want to wait a bit before diving in and changing passwords.

    http://nakedsecurity.sophos.com/2014/04/10/heartbleed-heartache-should-you-really-change-all-your-passwords-right-away/
  • RumRat
    RumRat Posts: 5,000 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    I think the publicity overtook the facts. It would seem that most mainstream sites were warned prior to disclosure of the vulnerability. As long as you don't use the same P/W for logging into sites like this and your banking etc. there should be no reason to over worry.
    A simpler check for site vulnerability here http://filippo.io/Heartbleed/
    Drinking Rum before 10am makes you
    A PIRATE
    Not an Alcoholic...!
  • googler
    googler Posts: 16,103 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    You can test here. https://www.ssllabs.com/ssltest/index.html

    What banks are safe? Why are none of them making any reference or announcement on their sites?

    You probably shouldn't be using a bank site that has a single-level, single password entry anyway.

    All of those that I use require entry of characters from security codes as well as passwords, or require selection of keyword characters from onscreen graphics, so there's no chance of grabbing a whole password/keyword combination from one user entry.
  • RumRat
    RumRat Posts: 5,000 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    Drinking Rum before 10am makes you
    A PIRATE
    Not an Alcoholic...!
  • radu_
    radu_ Posts: 23 Forumite
    abibee wrote: »
    It's good practice to change your passwords from time to time anyway. Not that I do, I still use password123... do'h!

    Edit: I never read the article you posted before my reply, I've only just done so now. That sounds pretty serious. I use Lastpass and different passwords on every site e-mail etc, but still, I think I may change a few of them tonight.

    Thanks for posting.

    Don't change all the passwords just yet.
    Apparently Lastpass will tell you when to change your passwords.
  • ciderboy2009
    ciderboy2009 Posts: 1,243 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Car Insurance Carver!
    If you use Lastpass then login to their web site and choose the security scan option. It'll go through all of the sites you've got info stored for and tell you which (if any) are affected and what you should do for each one.

    For 817 sites on mine only 4 are potentially affected.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.8K Banking & Borrowing
  • 253K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.8K Work, Benefits & Business
  • 598.6K Mortgages, Homes & Bills
  • 176.8K Life & Family
  • 257K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.