Why am I receiving this message?
We wanted to provide an update on the Heartbleed situation and remind you to change your RIT passwords. The Heartbleed bug has been widely reported and will require action on your part.
- Heartbleed bug background—there is a flaw in versions of OpenSSL that allows access to information that would normally be protected through secure connections. The Heartbleed bug allows anyone on the Internet access to see what's in the memory of systems protected by Open SSL, leaving no evidence that they’ve done so. Approximately 2/3 of all websites are affected. Researchers reported the bug on April 7, but the vulnerability has existed since 2011. Note that this is not a breach of a password databases. Website owners and vendors worldwide are in the process of updating/patching the servers hosting these websites.
- Current Heartbleed status-there are a lot of varying recommendations on what computer users should do in response to the Heartbleed bug and which websites were affected, and you may find it confusing. You have been affected. Many of you have been contacted by the owners of various websites and services and have been asked to update your passwords. Popular websites such as Dropbox, Yahoo, Twitter, and others were affected and many of them are requesting password changes.
- Android—there are reports circulating that older Android devices (4.1.1) may be vulnerable to the Heartbleed bug. Google has stated that less than 10% of devices run on vulnerable versions.
What You Need To Do
- For RIT passwords, please change your passwords. Given the scale of this vulnerability, there is concern that passwords may be at risk.
- For personal passwords, we recommend that you change your passwords. Priority should be given to sites accessing private information, financial accounts and email. Note that if the website is still vulnerable, you may need to change your password again after the site is patched.
- Stop using the same password for multiple sites! Create a new unique password for each site. Yes, this is painful.
- Be alert for phishing attempts leveraging the publicity around the OpenSSL bug.
- Be patient. It may take several weeks (at least) for companies to fix the Heartbleed bug and there may be disruption to Internet services.
What RIT is Doing
- RIT has successfully secured the vast majority of our computing infrastructure with patches and other mitigations. Some lower profile services have been taken offline until patches are released and mitigations applied. This is a necessary step to protect RIT.
- RIT continues to work with vendors to implement patches and other mitigations.
- The RIT Information Security Office continues to conduct vulnerability scanning of the RIT network until all vulnerabilities have been addressed.
- RIT is quarantining the small number of systems currently affected until they are remediated.
- Many thanks to the RIT information technology community that has been working around the clock to patch and protect RIT!
For More Information
- The Heartbleed Bug <http://heartbleed.com/>
- Heartbleed is about to get worse, and it will slow the Internet to a crawl <http://www.washingtonpost.
com/blogs/the-switch/wp/2014/ 04/14/heartbleed-is-about-to- get-worse-and-it-will-slow- the-internet-to-a-crawl/>
- Heartbleed Bug Puts Millions Of Android Devices At Riskhttp://www.huffingtonpost.com/
- Lookout Android Heartbleed Detector <https://blog.lookout.com/
- Heartbleed: 95% of detection tools 'flawed', claim researchers <http://www.theguardian.com/
technology/2014/apr/16/ heartbleed-bug-detection- tools-flawed >
- LastPass Heartbleed checker <https://lastpass.com/
heartbleed/>. This allows you to put in a website address to determine if it’s been fixed.