Skip to main content

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

What is the Heartbleed OpenSSL Bug, and how can you protect your PC?

heartbleed web bug potentially exposes untold amounts of private data heart bleed
Image used with permission by copyright holder
A serious vulnerability in the OpenSSL Internet encryption protocol known as the Heartbleed bug has potentially left the information of most Internet users vulnerable to hackers.

That’s according to a team of Codenomicon researchers, as well as Google Security researcher Neel Mehta. Codenomicon is a Web security firm whose clients include Microsoft, Verizon, and Cisco Systems. The Heartbleed bug reportedly affects as much as 66 percent of the world’s active websites, and has existed for roughly two years.

Recommended Videos

OpenSSL is a method of encryption employed by many websites that safeguard the data you type into your Web browser. OpenSSL contains a function known as a heartbeat option. With it, while a person is visiting a website that encrypts data using OpenSSL, his computer periodically sends and receives messages to check whether both his PC and the server on the other end are both still connected. The Heartbleed bug means hackers can send fake heartbeat messages, which can trick a site’s server into relaying data that’s stored in its RAM — including sensitive information such as usernames, passwords, credit card numbers, emails, and more.

“Considering the long exposure, ease of exploitation, and attacks leaving no trace, this exposure should be taken seriously,” Codenomicon warns.

The security researchers who uncovered the hole say that hackers who exploit the Heartbleed bug can steal all that and more, even instant messages and business documents. The researchers tested the flaw out for themselves, and discovered that they were able to steal such information without leaving any trace of their attack, and also without the benefit of any “privileged information,” including log-in credentials.

What can you do to protect yourself from the Heartbleed bug?

Aside from avoiding affected sites, which reportedly include Yahoo and OkCupid, and changing your passwords, there’s not much much you can do to safeguard your data. It’s up to individual companies to update their websites and services to use the fixed version of OpenSSL, which plugs the hole left by Heartbleed — stanching the bleeding, so to speak. The researchers that took the wraps off the bug say it’s the responsibility of operating system vendors, software makers, and network hardware vendors to use the new version, which they call FixedSSL.

At this point, both Amazon and Yahoo are working to apply the fix across all of their services, with the latter indicating that they’ve done so across most high-profile web properties, including Yahoo Homepage, Yahoo Search, Yahoo Mail, Yahoo Sports, and more. Meanwhile, Amazon states that it has applied the fix to the majority of its services as well. You can read Amazon’s statement on the matter here.

At this point, it’s unclear how much damage has been done by Heartbleed. In the meantime, here’s a list of sites which have reportedly been affected. Also, the U.S. Department of Homeland Security has published a blog post, offering these tips on how to secure yourself from Heartbleed.

  • “Many commonly used websites are taking steps to ensure they are not affected by this vulnerability and letting the public know. Once you know the website is secure, change your passwords.”
  • “Closely monitor your email accounts, bank accounts, social media accounts, and other online assets for irregular or suspicious activity, such as abnormal purchases or messages”
  • “After a website you are visiting has addressed the vulnerability, ensure that if it requires personal information such as login credentials or credit card information, it is secure with the HTTPS identifier in the address bar. Look out for the “s”, as it means secure.”

Be sure to read our guide to What Websites are affected by the Heartbleed bug and How to Protect Your Android from Heartbleed. We also have a robust list of Android, iOS, and Windows Apps Affected by Heartbleed and Video Game Services Affected by Heartbleed.

What do you think? Sound off in the comments below.

Konrad Krawczyk
Former Digital Trends Contributor
Konrad covers desktops, laptops, tablets, sports tech and subjects in between for Digital Trends. Prior to joining DT, he…
I tried a gadget that could totally change how you interact with your PC
new spatial computing gadget distance grab

While the best VR headsets of yesteryear were built for gaming, companies are moving toward augmented reality for virtual computing. Devices like Apple's Vision Pro promise spatial computing, and Meta has been chipping away at its vision of Augmented Reality (AR) for years. A lot of attention has been paid to the headsets you strap on, but not the interface with which you interact with the virtual world.

Afference, a team composed of a neural engineer, neural interface expert, and perceptual scientist based out of Boulder, Colorado is looking to change that, and it's developing a new tool that may just change how you interact with your PC forever.
Phantom Feelings
The problem Afference has set out to solve with its Phantom glove is simple: How can we create synchronized tactile sensations with what the user sees visually? Anyone who experiences VR outside of simple visual experiences understands this problem. When we interact with an object, or even something as simple as pressing a button, our brains anticipate force feedback. When what we're doing doesn't sync up with what our sensory organs expect, and that's where cybersickness can occur. The technology behind the Phantom intends to give our brains that feedback to complete the loop.

Read more
Here’s how you can win this insane, custom Starfield PC
custom starfield pc giveaway

Gaming PC Modeled After Starfield Control Panel?! [Giveaway]

Modders always come out with some wild PC designs for new game releases, but this custom Starfield PC from Skytech Gaming might be one of the coolest I've ever seen. It's a machine that comes from a collaboration between Skytech Gaming, Intel, and SignalRGB, and you can enter for a chance to win it.

Read more
OpenAI threatens lawsuit over student GPT-4 project, forgets you can use it for free
OpenAI's ChatGPT blog post is open on a computer monitor, taken from a high angle.

There's nothing quite like the nonprofit research group turned for-profit company OpenAI chasing down a computer science student over an open-source GPT-4 project. Sounds ridiculous, but it's true. The creators of ChatGPT are threatening a lawsuit against student Xtekky if he doesn't take down his GPT4free GitHub repository.

As reported by Tom's Hardware, GPT4free is an open-source project from a European computer science student. The student identifies as Xtekky, and his tool pings various websites that use GPT-4. You can clone the repository, set up the chatbot locally on your PC, and interact with GPT-4 without paying for OpenAI's ChatGPT Plus service.

Read more