NEW YORK (AP) — Passwords, credit cards and other sensitive data are at risk after security researchers discovered a problem with an encryption technology used to securely transmit email, e-commerce transactions, social networking posts and other Web traffic.
Security researchers say the threat, known as Heartbleed, is serious, partly because it remained undiscovered for more two years. Attackers can exploit the vulnerability without leaving any trace, so anything sent during that time has potentially been compromised. It's not known, though, whether anyone has actually used it to conduct an attack.
Researchers are advising people to change all of their passwords.
The breach involves SSL/TLS, an encryption technology marked by the small, closed padlock and "https:" on Web browsers to signify that traffic is secure. With the Heartbleed flaw, traffic was subject to snooping even if the padlock had been closed.
The problem affects only the variant of SSL/TLS known as OpenSSL, but that happens to be one of the most common on the Internet.
Researchers say that OpenSSL is used by two of the most widely used Web server software, Apache and nginx. That means many websites potentially have this security flaw. OpenSSL is also used to secure email, chats and virtual private networks, which are used by employees to connect securely with corporate networks.
A fix came out Monday, but websites and service providers must install the update.
Yahoo Inc.'s Tumblr blogging service uses OpenSSL. In a blog post Tuesday, officials said they had no evidence of any breach and had immediately implemented the fix.
"But this still means that the little lock icon (HTTPS) we all trusted to keep our passwords, personal emails, and credit cards safe, was actually making all that private information accessible to anyone who knew about the exploit," Tumblr's blog post read. "This might be a good day to call in sick and take some time to change your passwords everywhere — especially your high-security services like email, file storage, and banking, which may have been compromised by this bug."
The flaw was discovered independently by researchers at Google Inc. and the Finnish security firm Codenomicon.
Copyright 2014 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.
This year marks the 50th anniversary of one of San Diego's most treasured attractions - SeaWorld's Bayside Skyride. Since 1967, more than 20 million guests have soared above Mission Bay on its iconic gondolas.
Investigators working to identify and track down a man who fatally assaulted a well-liked transient in downtown Ocean Beach released surveillance-camera footage of the suspected killer Friday.
A woman who stole $565,000 from the Escondido concrete business where she worked and gambled the money away at local casinos was sentenced Friday to six years in state prison.
San Diego civic and business leaders are scheduled to travel to Vancouver next week to strengthen trade ties with Canada.
San Diego-based ships and sailors in the carrier strike group led by the USS Carl Vinson returned to San Diego Friday after a deployment of more than five months.
Gayle King, “CBS This Morning” co-host and editor at-large of “O, the Oprah Magazine,” will join Oprah Winfrey this summer as they embark on their maiden "Share Your Adventure” expedition.
News 8's Ashley Jacobs introduces us to a smorgasbord of exciting entertainment from around the globe as the San Diego Zoo Safari Park kicks off Summer Safari fun.
The coauthors of an international best-seller took a break from their cross-country tour to inspire positive change in the lives of women in San Diego.
Residents are concerned at a local dog park after at least one dog got sick and died after spending time there.