MAMEWorld >> The Loony Bin
View all threads Index   Threaded Mode Threaded  

Pages: 1

TriggerFin
Gnu Truth
Reged: 09/21/03
Posts: 5266
Loc: Stuck in a hole
Send PM


OK, so... everyone needs to change all the passwords for everything now. Right? (nt)
#324306 - 04/08/14 06:03 PM





Tomu Breidah
No Problems, Only Solutions
Reged: 08/14/04
Posts: 6820
Loc: Neither here, nor there.
Send PM


Re: everyone needs to change all the passwords for everything now. Right? new [Re: TriggerFin]
#324354 - 04/09/14 04:52 AM


http://www.mameworld.info/ubbthreads/sho...amp;o=&vc=1

I probably wouldn't've remembered this if I didn't have to get on my old XP.


Or just click here.


Edit: since it's a few degrees away...



Edited by Tomu Breidah (04/09/14 07:20 AM)



LEVEL-4



Waremonger
Reged: 01/18/05
Posts: 910
Send PM


Re: everyone needs to change all the passwords for everything now. Right? new [Re: Tomu Breidah]
#324416 - 04/10/14 06:02 AM


> http://www.mameworld.info/ubbthreads/sho...amp;o=&vc=1
>
> I probably wouldn't've remembered this if I didn't have to get on my old XP.
>
>
> Or just click here.
>
>
> Edit: since it's a few degrees away...

It's a lot easier just to go here.



GatKongModerator
Tetris Mason
Reged: 04/20/07
Posts: 5907
Loc: Sector 9
Send PM


Re: OK, so... everyone needs to change all the passwords for everything now. Right? (nt) new [Re: TriggerFin]
#324562 - 04/12/14 03:20 AM


Seems really a theoretical breech, tho, isn't it? Are there any known cases of actual exploit? In other words, the fact that I'm lazy to reset all my passwords... is that being just plain dumb?







Vas Crabb
BOFH
Reged: 12/13/05
Posts: 4462
Loc: Melbourne, Australia
Send PM


Re: OK, so... everyone needs to change all the passwords for everything now. Right? (nt) new [Re: GatKong]
#324576 - 04/12/14 09:33 AM


> Seems really a theoretical breech, tho, isn't it? Are there any known cases of actual
> exploit? In other words, the fact that I'm lazy to reset all my passwords... is that
> being just plain dumb?

Yes there is evidence that that the bad guys knew about this already.



MooglyGuy
Renegade MAME Dev
Reged: 09/01/05
Posts: 2261
Send PM


Re: OK, so... everyone needs to change all the passwords for everything now. Right? (nt) new [Re: GatKong]
#324581 - 04/12/14 02:45 PM


> Are there any known cases of actual exploit?

Yes. I pointed ssltest.py at mail.yahoo.com and immediately saw usernames and passwords in unencrypted plaintext.



TriggerFin
Gnu Truth
Reged: 09/21/03
Posts: 5266
Loc: Stuck in a hole
Send PM


Re: OK, so... everyone needs to change all the passwords for everything now. Right? (nt) new [Re: MooglyGuy]
#324584 - 04/12/14 04:06 PM


> > Are there any known cases of actual exploit?
>
> Yes. I pointed ssltest.py at mail.yahoo.com and immediately saw usernames and
> passwords in unencrypted plaintext.

Which would mean yahoo isn't fixed yet, and changing your password there is pointless?



MooglyGuy
Renegade MAME Dev
Reged: 09/01/05
Posts: 2261
Send PM


Re: OK, so... everyone needs to change all the passwords for everything now. Right? (nt) new [Re: TriggerFin]
#324585 - 04/12/14 04:31 PM


> > > Are there any known cases of actual exploit?
> >
> > Yes. I pointed ssltest.py at mail.yahoo.com and immediately saw usernames and
> > passwords in unencrypted plaintext.
>
> Which would mean yahoo isn't fixed yet, and changing your password there is
> pointless?

Back when the exploit was first announced, I mean. It's since been fixed.



Bad A Billy
Oop Ack!
Reged: 12/27/07
Posts: 1076
Loc: Outland
Send PM


Re: OK, so... everyone needs to change all the passwords for everything now. Right? (nt) new [Re: Vas Crabb]
#324595 - 04/12/14 07:53 PM


So they had your info weeks ago and have done nothing with it. Now they are going to go ahead with their plans and hope you were too lazy to change things up? Just saying...

I'd still change anything important though.



Pessimist: Oh, this can't get any worse!
Optimist: Yes, it can!



TriggerFin
Gnu Truth
Reged: 09/21/03
Posts: 5266
Loc: Stuck in a hole
Send PM


Re: OK, so... everyone needs to change all the passwords for everything now. Right? (nt) new [Re: Bad A Billy]
#324600 - 04/12/14 08:53 PM


> So they had your info weeks ago and have done nothing with it. Now they are going to
> go ahead with their plans and hope you were too lazy to change things up? Just
> saying...
>
> I'd still change anything important though.

I end up changing important things all the time anyway. Can't remember password, get a reset key, can't pick a password I've used before, repeat next time.



DMala
Sleep is overrated
Reged: 05/09/05
Posts: 3989
Loc: Waltham, MA
Send PM


Re: OK, so... everyone needs to change all the passwords for everything now. Right? (nt) new [Re: TriggerFin]
#324609 - 04/13/14 05:36 AM


> I end up changing important things all the time anyway. Can't remember password, get
> a reset key, can't pick a password I've used before, repeat next time.

If you get sick of this, I highly recommend the combination of KeePass + Dropbox. You save your passwords in KeePass, encrypted with a strong password, and save the database to Dropbox. My passwords are available on any device I use, and when I have to make a new account, I just add it, save, and it syncs instantly.



twistyAdministrator
Space Lord
Reged: 09/18/03
Posts: 15570
Send PM


Re: OK, so... everyone needs to change all the passwords for everything now. Right? (nt) new [Re: TriggerFin]
#324674 - 04/14/14 06:03 PM


Here's a compiled list of the major websites that were and were not initially vulnerable...

http://mashable.com/2014/04/09/heartbleed-bug-websites-affected/







Foxhack
Furry guy
Reged: 01/30/04
Posts: 2409
Loc: Spicy Canada
Send PM


Re: OK, so... everyone needs to change all the passwords for everything now. Right? (nt) new [Re: DMala]
#324678 - 04/14/14 08:06 PM


> > I end up changing important things all the time anyway. Can't remember password,
> get
> > a reset key, can't pick a password I've used before, repeat next time.
>
> If you get sick of this, I highly recommend the combination of KeePass + Dropbox. You
> save your passwords in KeePass, encrypted with a strong password, and save the
> database to Dropbox. My passwords are available on any device I use, and when I have
> to make a new account, I just add it, save, and it syncs instantly.

I've been trying out KeePass but can't figure something out.

I want to use a specific file as an unlock key, but after picking it out, the program asks me if I want to overwrite the unlock key.

Wouldn't that uh, destroy the unlock key or is there something I'm missing?



DMala
Sleep is overrated
Reged: 05/09/05
Posts: 3989
Loc: Waltham, MA
Send PM


Re: OK, so... everyone needs to change all the passwords for everything now. Right? (nt) new [Re: Foxhack]
#324695 - 04/15/14 06:03 AM


> I've been trying out KeePass but can't figure something out.
>
> I want to use a specific file as an unlock key, but after picking it out, the program
> asks me if I want to overwrite the unlock key.
>
> Wouldn't that uh, destroy the unlock key or is there something I'm missing?

I've got it set up with a password, I haven't used an unlock key in a long time. As far as I know, though, the way it works is: you generate the key file once when you set up the database. Then when you open the database, you just point it to the file and KeePass reads it. If it's asking you to overwrite the key file when you open the database, I'm not sure what's going on.



Foxhack
Furry guy
Reged: 01/30/04
Posts: 2409
Loc: Spicy Canada
Send PM


Re: OK, so... everyone needs to change all the passwords for everything now. Right? (nt) new [Re: DMala]
#324701 - 04/15/14 06:56 AM


> > I've been trying out KeePass but can't figure something out.
> >
> > I want to use a specific file as an unlock key, but after picking it out, the
> program
> > asks me if I want to overwrite the unlock key.
> >
> > Wouldn't that uh, destroy the unlock key or is there something I'm missing?
>
> I've got it set up with a password, I haven't used an unlock key in a long time. As
> far as I know, though, the way it works is: you generate the key file once when you
> set up the database. Then when you open the database, you just point it to the file
> and KeePass reads it. If it's asking you to overwrite the key file when you open the
> database, I'm not sure what's going on.

It's asking me if I want to overwrite the key file when I -create- a new database.


Pages: 1

MAMEWorld >> The Loony Bin
View all threads Index   Threaded Mode Threaded  

Extra information Permissions
Moderator:  GatKong 
0 registered and 395 anonymous users are browsing this forum.
You cannot start new topics
You cannot reply to topics
HTML is enabled
UBBCode is enabled
Thread views: 2027