Newsletters
Customer Relationship Management News NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Click for more information, or
Home CRM Systems Customer Service Contact Centers Business Intelligence More Topics...
UCS Invicta: Integrated Flash
Deploy flash memory technology to
deliver peak workload performance.

Find out more>>
Computing
Is your endpoint data protected?
Average Rating:
Rate this article:  
Heartbleed Fallout: Thousands of Systems Still Exposed

Heartbleed Fallout: Thousands of Systems Still Exposed
By Jennifer LeClaire

Share
Share on Facebook Share on Twitter Share on Linkedin Share on Google Plus

When the Heartbleed vulnerability was announced, researchers at Errata Security found 600,000 systems that were vulnerable to the bug. A month later, they found that half had been patched, and only 300k were vulnerable,” Now, slightly over two months after Heartbleed, the researchers found 300k (309,197) systems were still vulnerable.
 


It’s been more than two months since the Heartbleed bug rocked the Internet world. Although some rushed to patch their systems, a new report reveals that many are still vulnerable to what has been called one of the worst-ever vulnerabilities.

First revealed in April, Heartbleed could give hackers access to user passwords and even trick people into using fake versions of popular Web sites. According to the security engineers at Codenomicon who found the bug, the vulnerability is in the OpenSSL cryptographic software library. The weakness, they said, steals information typically protected by the SSL/TLS encryption used to secure the Internet.

“The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software,” according to the Web site dedicated to providing information about the bug. “This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users.”

A Decade From Now . . .

Robert Graham, an analyst at advanced persistent cybersecurity solutions Errata Security, is now offering some new facts and figures on Heartbleed. When the vulnerability was announced, the firm found 600,000 systems vulnerable.

“A month later, we found that half had been patched, and only 300k were vulnerable,” Graham wrote in a blog post. “Last night, now slightly over two months after Heartbleed, we scanned again, and found 300k (309,197) still vulnerable. This is done by simply scanning on port 443, I haven't check other ports.”

As Graham sees it, the stats indicate that IT admins have stopped even trying to patch against Heartbleed. He also predicted a slow decrease over the next decade as older systems are slowly replaced.

“Even a decade from now, though, I still expect to find thousands of systems, including critical ones, still vulnerable,” Graham said. “I'll scan again next month, then at the six-month mark, and then yearly after that to track the progress.”

The Long Tail

We caught up with Kasper Lindgaard, Director of Research and Security at information security firm Secunia, to get his take on the latest news. He offered us some stats of his own. To date, he said, Secunia has recorded 590 different products from 100 different vendors as vulnerable thanks to the Heartbleed vulnerability.

“We have written 206 advisories on products affected by Heartbleed. We certainly agree that the patch numbers are leveling out, and while we are waiting for the remaining big vendors to publish the final patches, we don’t expect to see the numbers increase much,” Lindgaard said.

“Quite frankly anyone who hasn’t patched at this stage is not likely to do so now," he added. "There will always be some who fail to apply patches. In any case the vulnerability has a long tail, and the industry must keep vigilant on patching to keep their customers secure.”
 

Tell Us What You Think
Comment:

Name:



Protect 100% of your Data The prevalence of laptops and mobile devices in the enterprise makes corporate data increasingly vulnerable to loss and breach. And yet, workforce productivity is now inextricably linked to mobility. Click here to access the white paper "Top 10 Endpoint Backup Mistakes" to learn more about how to confidently protect data across platforms and devices while also providing features designed to enhance the end user experience.


 Computing
1.   Price Wars Hitting Laptop Market?
2.   Concerto 2200: Dedupe, Compression
3.   9 Norton Security Products Are Now 1
4.   Infor Buys Cloud CRM App Saleslogix
5.   Data Stolen from U.S. Health Network


advertisement
China Puts Microsoft Under the Lens
Official anti-monopoly probe launched.
Average Rating:
Concerto 2200: Dedupe, Compression
Firms save money by saving space.
Average Rating:
9 Norton Security Products Are Now 1
Symantec takes software-as-service tack.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Chinese Hackers Nab Info on Millions of U.S. Patients
A group of Chinese hackers has stolen the personal information, including names and Social Security numbers, of about 4.5 million patients at hospitals operated by Community Health Systems.
 
Premier FBI Cybersquad in U.S. To Add Agents
After helping prosecutors charge Chinese army officials with stealing trade secrets from major companies and by snaring a Russian-led hacking ring, the premier FBI cyber-squad is getting a boost.
 
Apple Opens iCloud Data Center in China
Treading lightly, Apple acknowledged it has started to store encrypted iCloud personal data of some Chinese users on servers in mainland China, operated by the state-owned China Telecom.
 

Enterprise Hardware Spotlight
Compression, Deduplication Come to Violin Concerto 2200
Violin Memory has announced that data deduplication and compression capabilities are now available on its Concerto 2200 solution. Typically, users will experience deduplication rates between 6:1 and 10:1.
 
Cisco Axes 6,000 Employees in Restructuring Plan
Faced with declining profits, Cisco is laying off up to 6,000 employees in the months ahead -- a whopping 8 percent of its global workforce. That's in addition to the 4,000 jobs Cisco cut last year.
 
Web Slows, Have Internet Routers Reached The Limit?
If you encountered problems connecting to the Internet on August 12, you weren't alone. Networking experts blame the wide-scale slowdown on outdated routing systems that are reaching their limits.
 

Mobile Technology Spotlight
HTC Debuts Windows Phone Version of One M8 Smartphone
HTC is bringing the Windows Phone mobile OS to its flagship One M8 device -- the first time any mainstream flagship smartphone has been offered with a choice of operating systems.
 
Verizon Earns Top Rating in Mobile Network Comparison
A new report says Verizon Wireless was the top-performing U.S. cellphone service provider in the first half of 2014, on a nationwide and state-by-state basis, as well as in metro areas.
 
Sprint Comes Out with Data Guns Blazing
As its new CEO promised, Sprint has rolled out a new aggressively competitive price plan. The shared data plans promise twice the high-speed data and at lower prices than AT&T and Verizon Wireless.
 

Navigation
CRM Daily
Home/Top News | CRM Systems | Customer Service | Contact Centers | Business Intelligence | Sales & Marketing | Customer Data | CRM Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.