The heart bleed security bug

Print

The BBC has published a story about the 'heartbleed' bug: http://www.bbc.co.uk/news/technology-26935905: Dan Miller, Principle Engineer, Adapt comments on the scramble to fix the 'heartbleed' security bug: "The BBC and other news outlets have reported over the last 24 hours on a vulnerability in a popular implementation of the Secure Socket Layer (SSL) technology used to secure internet transactions. This allows sophisticated attackers to read parts of a system’s memory that may contain sensitive details.

"The press has dubbed this issue a 'heartbleed' attack and as something businesses should be discussing with their service providers to ensure they are protected and that all services remain secure.

The first step is to assess the risk. If an organisation suspects any of its servers is vulnerable, it should work quickly to patch or disable affected services. Working closely with a service provider or the Operating System vendor during this process is advised to mitigate risk and keep operations running smoothly."