TheJakartaPost

Please Update your browser

Your browser is out of date, and may not be compatible with our website. A list of the most popular web browsers can be found below.
Just click on the icons to get to the download page.

Jakarta Post

News Flash: More than 300,000 still at risk from Heartbleed

JAKARTA: More than 300,000 servers remain vulnerable to the Heartbleed security hole, a month after the critical vulnerability bug was first revealed, a security researcher has said

The Jakarta Post
Tue, May 20, 2014 Published on May. 20, 2014 Published on 2014-05-20T12:59:32+07:00

Change text size

Gift Premium Articles
to Anyone

Share the best of The Jakarta Post with friends, family, or colleagues. As a subscriber, you can gift 3 to 5 articles each month that anyone can read—no subscription needed!
News Flash: More than 300,000 still at risk from Heartbleed

J

AKARTA: More than 300,000 servers remain vulnerable to the Heartbleed security hole, a month after the critical vulnerability bug was first revealed, a security researcher has said.

Security researcher Robert David Graham conducted a global internet scan and found that 1.5 million servers still support OpenSSL'€™s '€œheartbeat'€ feature that allows the bug. OpenSSL is an open-source version of Secure Socket Layer (SSL) protocol.

'€œIt'€™s been a month since the Heartbleed bug was announced, so I thought I'€™d rescan the internet (port 443) to see how many systems remain vulnerable,'€ Graham wrote in his report.

'€œWhereas my previous scan a month ago found 600,000 vulnerable systems, today'€™s scan found roughly 300,000 thousand systems (318,239 to be precise).'€

The number only includes confirmed cases. Other systems may have escaped Graham'€™s search due to spam blocking or unorthodox OpenSSL setups.

Major services like Google have already patched their servers, but smaller and less-secure services could still be harmed. Attackers could manipulate vulnerable servers and use Heartbleed to eavesdrop on communications, steal data or impersonate services and users.

The original flaw was detected last month. Sites affected include Gmail, YouTube, Facebook, Tumblr, Yahoo! and Dropbox.

Heartbleed is a security bug in OpenSSL'€™s cryptography library for implementing the Internet'€™s Transport Layer Security (TLS) protocol. The bug allows anyone on the Internet to read the memory of the systems protected by vulnerable versions of OpenSSL.

The bug exploits an OpenSSL feature called '€œheartbeat'€. When your computer makes a request, the heartbeat will normally only send back the amount of data your computer sent. When they are bugged, however, hackers can make a request to the server for data from the server'€™s memory beyond the total data of the initial request.

Your Opinion Matters

Share your experiences, suggestions, and any issues you've encountered on The Jakarta Post. We're here to listen.

Enter at least 30 characters
0 / 30

Thank You

Thank you for sharing your thoughts. We appreciate your feedback.

Share options

Quickly share this news with your network—keep everyone informed with just a single click!

Change text size options

Customize your reading experience by adjusting the text size to small, medium, or large—find what’s most comfortable for you.

Gift Premium Articles
to Anyone

Share the best of The Jakarta Post with friends, family, or colleagues. As a subscriber, you can gift 3 to 5 articles each month that anyone can read—no subscription needed!

Continue in the app

Get the best experience—faster access, exclusive features, and a seamless way to stay updated.