Re: CVE-2014-0160 is putting bitcoin sites at risk
by
nibor
on 08/04/2014, 21:39:03 UTC
That has got to be bug of the century... if not ever.
Implies that for 2 years since code was released anyone running a server using openssl 1.0.1 (upto 1.0.1f inclusive) an attacker could silently (i.e. no logging or trail) download the ssl private key off the server. And then if they could intercept any ssl traffic between server and client they could then decrypt that data (again silently leaving no trace). And could have been doing that for 2 years.
Or have I got the wrong end of the stick here?
This implies that every users need to change every password on every site that was using 1.0.1?