[Announcement] Heartbleed Security Breach
2014-04-09 16:42:00
A bug was found in the OpenSSL cryptographic library that could affect your services, if you use it.
A serious vulnerability bug (Heartbleed) in the popular OpenSSL cryptographic software library was discovered on 08/04/2014. This weakness allows stealing protected information, under normal conditions, by the SSL/TLS encryption used to secure the Internet.
Until the vulnerability was discovered, it was affecting a large part of the internet services. We are happy to announce that our system servers, including our client database and billing/support system was never affected by this security bug. Thus your data with us is and has always been secure. However as you have full control over your server, we cannot guarantee that the service is/was patched against this security threat. We suggest that you use an online tool to make sure your server is secure. The tool can be found here at http://possible.lv/tools/hb/.
If your server is not affected to the security threat no further actions are required to be taken. However in case the test shows positive for the vulnerability we suggest that you take an immediate action to:
- Disable all activity of transferring sensitive data (admin/client logins, signups, etc).
- Patch your OpenSSL to a version that won't be affected to this security issue.
- Generate new keys. This is necessary because the bug might have allowed an attacker to obtain the old private key. Follow the same procedure you used initially.
* If you use certificates signed by a certification authority, submit your new public keys to your CA. When you get the new certificate, install it on your server.
* If you use self-signed certificates, install it on your server.
* Either way, move the old keys and certificates out of the way (but don't delete them, just ensure they aren't getting used any more).
- Make sure your old certificates are revoked
- If you're running a service that allows password authentication, then the user passwords may be compromised. Therefore they need to be resetted.
- Also invalidate all session cookies, as they may have been compromised.
- Restart your server and enable transferring sensitive data.
More information regarding this security issue is available on following website http://heartbleed.com/.
Should you have any questions regarding this, please don't hesitate to be in touch with us at support@oneprovider.com!