NEW YORK (AP) — Passwords, credit cards and other sensitive data are at risk after security researchers discovered a problem with an encryption technology used to securely transmit email, e-commerce transactions, social networking posts and other Web traffic.
Security researchers say the threat, known as Heartbleed, is serious, partly because it remained undiscovered for more two years. Attackers can exploit the vulnerability without leaving any trace, so anything sent during that time has potentially been compromised. It's not known, though, whether anyone has actually used it to conduct an attack.
Researchers are advising people to change all of their passwords.
The breach involves SSL/TLS, an encryption technology marked by the small, closed padlock and "https:" on Web browsers to signify that traffic is secure. With the Heartbleed flaw, traffic was subject to snooping even if the padlock had been closed.
The problem affects only the variant of SSL/TLS known as OpenSSL, but that happens to be one of the most common on the Internet.
Researchers say that OpenSSL is used by two of the most widely used Web server software, Apache and nginx. That means many websites potentially have this security flaw. OpenSSL is also used to secure email, chats and virtual private networks, which are used by employees to connect securely with corporate networks.
A fix came out Monday, but websites and service providers must install the update.
Yahoo Inc.'s Tumblr blogging service uses OpenSSL. In a blog post Tuesday, officials said they had no evidence of any breach and had immediately implemented the fix.
"But this still means that the little lock icon (HTTPS) we all trusted to keep our passwords, personal emails, and credit cards safe, was actually making all that private information accessible to anyone who knew about the exploit," Tumblr's blog post read. "This might be a good day to call in sick and take some time to change your passwords everywhere — especially your high-security services like email, file storage, and banking, which may have been compromised by this bug."
The flaw was discovered independently by researchers at Google Inc. and the Finnish security firm Codenomicon.
Copyright 2014 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.
The San Diego Humane Society today urged residents to volunteer their homes as foster spaces for the influx of animals typically lost after Fourth of July.
A man was critically injured Friday night when he chased a ball into the street and was hit by a car.
Clayton Richard pitched three-hit ball over six innings for his fourth consecutive win and the San Diego Padres beat the San Francisco Giants 6-2 on Friday night.
A powerful show of support for migrants being held in detention facilities has hundreds of interfaith leaders gathered Friday night for a vigil and demonstration at the border.
As the number of migrants in custody continues to grow, the Navy is making plans to house thousands of them in temporary shelters at military bases.
A man suspected of threatening deadly violence while robbing three San Diego-area banks over the last two weeks was indicted by a grand jury Friday on a slate of federal charges.
On Friday, more pups across the country will join their masters at the office, gym and other businesses for the 20th annual Take Your Dog to Work Day.
There is controversy over a TIME Magazine cover showing a crying toddler superimposed next an image of President Trump.
Hoover High School took a trip into the past by opening a time capsule from 1978. The capsule was dug up in a construction project several years before it was meant to be unearthed.