SUBSCRIBE
SUBSCRIBE
EXPLORE +
  • About infoDOCKET
  • Academic Libraries on LJ
  • Research on LJ
  • News on LJ
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Libraries
    • Academic Libraries
    • Government Libraries
    • National Libraries
    • Public Libraries
  • Companies (Publishers/Vendors)
    • EBSCO
    • Elsevier
    • Ex Libris
    • Frontiers
    • Gale
    • PLOS
    • Scholastic
  • New Resources
    • Dashboards
    • Data Files
    • Digital Collections
    • Digital Preservation
    • Interactive Tools
    • Maps
    • Other
    • Podcasts
    • Productivity
  • New Research
    • Conference Presentations
    • Journal Articles
    • Lecture
    • New Issue
    • Reports
  • Topics
    • Archives & Special Collections
    • Associations & Organizations
    • Awards
    • Funding
    • Interviews
    • Jobs
    • Management & Leadership
    • News
    • Patrons & Users
    • Preservation
    • Profiles
    • Publishing
    • Roundup
    • Scholarly Communications
      • Open Access

April 8, 2014 by Gary Price

Privacy: Critical Crypto Bug in OpenSSL Opens Two-Thirds of Web to Eavesdropping

April 8, 2014 by Gary Price

If your organization or vendors utilize OpenSSL (as you’ll read below, you/they probably do) please take note of this important story. Also, as the ars technica story points out simply patching the bug might not be enough.
If this news is not a concern it is another real-world example that it’s very important to be aware of potential privacy issues that could involve your privacy and the privacy of library users/customers.
Of course, encryption is only one of many privacy concerns that info pros should not only know about/understand at a basic level but should also educate users about. In other words, your privacy and user privacy should not simply be an issue for systems and info tech specialists.
Now, to Today’s News…
From PC World:

Computer security experts are advising administrators to patch a severe flaw in a software library used by millions of websites to encrypt sensitive communications.
The flaw, nicknamed “Heartbleed,” is contained in several versions of OpenSSL, a cryptographic library that enables SSL (Secure Sockets Layer) or TLS (Transport Security Layer) encryption. Most websites use either SSL or TLS, which is indicated in browsers with a padlock symbol.
The flaw, which was introduced in December 2011, has been fixed in OpenSSL 1.0.1g, which was released on Monday.
The vulnerable versions of OpenSSL are 1.0.1 through 1.0.1f with two exceptions: OpenSSL 1.0.0 branch and 0.9.8, according to a special website set up by researchers who found the problem.
[Our emphasis] If exploited, the flaw could allow attackers to monitor all information passed between a user and a Web service or even decrypt past traffic they’ve collected.

From ars technica:

The researchers [who discovered the bug], who work at Google and software security firm Codenomicon, said even after vulnerable websites install the OpenSSL patch, they may still remain vulnerable to attacks. The risk stems from the possibility that attackers already exploited the vulnerability to recover the private key of the digital certificate, passwords used to administer the sites, or authentication cookies and similar credentials used to validate users to restricted parts of a website. Fully recovering from the two-year-long vulnerability may also require revoking any exposed keys, reissuing new keys, and invalidating all session keys and session cookies. Members of the Tor anonymity project have a brief write-up of the bug here, and a this analysis provides useful technical details.
[Clip]
[Our emphasis] OpenSSL is by far the Internet’s most popular open-source cryptographic library and TLS implementation. It is the default encryption engine for Apache, nginx, which according to Netcraft runs 66 percent of websites.
OpenSSL also ships in a wide variety of operating systems and applications, including the Debian Wheezy, Ubuntu, CENTOS, Fedora, OpenBSD, FreeBSD, and OpenSUSE distributions of Linux. The missing bounds check in the handling of the Transport Layer Security (TLS) heartbeat extension affects OpenSSL 1.0.1 through 1.0.1f.

Learn More About the Bug and What Could Happen if Not Patched via the Heartbleed.com Website and FAQ

Filed under: Companies (Publishers/Vendors), Libraries, News, Patrons and Users

SHARE:

About Gary Price

Gary Price (gprice@gmail.com) is a librarian, writer, consultant, and frequent conference speaker based in the Washington D.C. metro area. He earned his MLIS degree from Wayne State University in Detroit. Price has won several awards including the SLA Innovations in Technology Award and Alumnus of the Year from the Wayne St. University Library and Information Science Program. From 2006-2009 he was Director of Online Information Services at Ask.com. Gary is also the co-founder of infoDJ an innovation research consultancy supporting corporate product and business model teams with just-in-time fact and insight finding.

ADVERTISEMENT

Archives

Job Zone

ADVERTISEMENT

Related Infodocket Posts

Journal Article: "What are Library Graduate Students Learning about Disability and Accessibility?: A Syllabus Analysis"

The article linked below was recently published by Urban Library Journal. Title What are Library Graduate Students Learning about Disability and Accessibility?: A Syllabus Analysis Author JJ Pionke University of ...

Illinois and Iowa Propose Book Ban Legislation With Opposing Goals; Louisiana: ACLU Of Louisiana Releases Open Letter on...

Connecticut: CT Librarians Raise Their Voices About Banned Books. ‘We Don’t Have Porn.’ (via CT Post) Illinois and Iowa Propose Book Ban Legislation With Opposing Goals (via WQAD) Iowa: Librarian ...

Not Real News: An Associated Press Roundup of Untrue Stories Shared Widely on Social Media This Week

From the Associated Press: A roundup of some of the most popular but completely untrue stories and visuals of the week. None of these are legit, even though they were ...

Judge Issues Opinion in Hachette Book Group, Et Al v. Internet Archive, Et Al; Plaintiffs Motion For Summary...

We Will Be Updating this Post with Media Reports, Statements, Analysis, etc. as They Become Available Statements Association of American Publishers “Publishers Prevail in Summary Judgement Against Internet Archive for ...

Journal Article: "The Case of the Disappearing Librarians: Analyzing Documentation of Librarians' Contributions to Systematic Reviews"

The article linked below was published today by the Journal of the Medical Library Association (JMLA). Title The Case of the Disappearing Librarians: Analyzing Documentation of Librarians’ Contributions to Systematic ...

Podcast: The Open Research Knowledge Graph, A Conversation with Vinodh Ilangovan and Jennifer D'Souza

A new Access 2 Perspectives podcast is now online. The conversation is hosted by Dr. Jo Havemann. From the Podcast Description Vinodh Ilangovan and Jennifer D’Souza work on the Open Research ...

AI Tools Are Generating Convincing Misinformation. Engaging With Them Means Being on High Alert; Report From Fully OA...

AI Tools Are Generating Convincing Misinformation. Engaging with Them Means Being on High Alert (via The Conversation) Guests at the Next DPLA Open Board + Community Meeting (April 10, 2023) ...

American Library Association Reports Record Number of Demands to Censor Library Books and Materials in 2022: Book Challenges...

From the American Library Association: The American Library Association (ALA) today released new data documenting* 1,269 demands to censor library books and resources in 2022, the highest number of attempted book ...

Penn State University Libraries: Expanded Judy Chicago Research Portal Relaunches With Five Unified Collections

From a PSU Libraries Blog Post: Penn State University Libraries has announced the relaunch of an expanded Judy Chicago Research Portal, a searchable gateway to the archives of this prominent feminist ...

Two Ebook Bill Hearings; New Digital Collections From South Africa, India, Nepal and Georgia Now Available Online From...

Clarivate Announces Gordon Samson as President, Intellectual Property and Nominates Dr. Saurabh Saha as New Independent Director Here Come the First ChatGPT Plugins (via OpenAI); More via TechCrunch Illinois House ...

Registration Now Open -- May 24-26 Nobel Prize Summit on Misinformation and Trust in Science (In-Person & Virtual)

From the U.S. National Academy of Science: Registration is now open for the Nobel Prize Summit Truth, Trust and Hope — which will convene Nobel Prize laureates and other world-renowned experts and ...

Report: "Top Missouri Lawmaker Moves To Strip Library Funding"

From the Associated Press (AP):  A powerful Missouri state lawmaker on Tuesday moved to strip state funding for public libraries over a fight about books. Republican House Budget Committee Chairman ...

ADVERTISEMENT

FOLLOW US ON TWITTER

Tweets by infoDOCKET

ADVERTISEMENT

This coverage is free for all visitors. Your support makes this possible.

This coverage is free for all visitors. Your support makes this possible.

Primary Sidebar

  • News
  • Reviews+
  • Technology
  • Programs+
  • Design
  • Leadership
  • People
  • COVID-19
  • Advocacy
  • Opinion
  • INFOdocket
  • Job Zone

Reviews+

  • Booklists
  • Prepub Alert
  • Book Pulse
  • Media
  • Readers' Advisory
  • Self-Published Books
  • Review Submissions
  • Review for LJ

Awards

  • Library of the Year
  • Librarian of the Year
  • Movers & Shakers 2022
  • Paralibrarian of the Year
  • Best Small Library
  • Marketer of the Year
  • All Awards Guidelines
  • Community Impact Prize

Resources

  • LJ Index/Star Libraries
  • Research
  • White Papers / Case Studies

Events & PD

  • Online Courses
  • In-Person Events
  • Virtual Events
  • Webcasts
  • About Us
  • Contact Us
  • Advertise
  • Subscribe
  • Media Inquiries
  • Newsletter Sign Up
  • Submit Features/News
  • Data Privacy
  • Terms of Use
  • Terms of Sale
  • FAQs
  • Careers at MSI


© 2023 Library Journal. All rights reserved.


© 2022 Library Journal. All rights reserved.