Même Mail :) ------------------------------ ovd <[email protected]> ________________________________ De : Philippe Gras<mailto:[email protected]> Envoyé : 12/04/2014 11:22 À : Debian Users (Liste en Français) <mailto:[email protected]> Objet : Fwd: [HS] Faille "Heartbleed" d'Openssl
On dirait que le problème sur OpenSSL a aussi des répercussions sur les affaires… Début du message réexpédié : > De : CloudFlare Team <[email protected]> > Date : 12 avril 2014 07:12:08 HAEC > À : <[email protected]> > Objet : Your website is secure from the OpenSSL Heartbleed > vulnerability > Répondre à : <[email protected]> > > You're protected from the Heartbleed vulnerability because you have > CloudFlare turned on for your website. We fixed the flaw on March > 31 for all CloudFlare customers, a week before it was publicly > announced. > > Heartbleed (CVE-2014-0160, http://www.openssl.org/) is a flaw in > OpenSSL, encryption software used by the vast majority of websites > to protect sensitive information. This vulnerability in OpenSSL > allows an attacker to reveal up to 64KB of memory to a connected > client or server. This flaw could expose sensitive data such as > passwords or usernames - even when you thought it was encrypted. > > NO IMPACT ON CLOUDFLARE SERVICE. Our team has conducted a > comprehensive security review to ensure our customers were not > impacted. One concern is that an attacker had access to the exploit > before March 31 since the flaw was present since December 2011. > We've seen no evidence of this, but we're proceeding as if it is a > possibility. > > PRIVATE KEY DATA. Our security and cryptographic team has been > testing the possibility that private SSL key data may have been > retrieved. We have been unable to replicate a situation where > private SSL key data would leak. We have set up a challenge to see > if others can exploit the bug. See more information on our blog: > > http://blog.cloudflare.com/answering-the-critical-question-can-you- > get-private-ssl-keys-using-heartbleed > > NEW CERTIFICATES FOR EVERYONE. Even though we have not been able to > use the exploit to leak public key data, we're proceeding out of an > abundance of caution. We've begun the process of reissuing and > revoking the keys CloudFlare manages on behalf of our customers. To > ensure that we don't overburden the certificate authority resources > given the scale at which CloudFlare operates, we are staging this > process. We expect that it will be complete by early next week. > > GENERAL RECOMMENDATIONS FOR SAFE WEB HYGIENE > There are some precautions you can take to protect yourself from > the Heartbleed bug. > > 1. GET CUSTOM CERTIFICATES ISSUED. If you're using CloudFlare > custom certificates, have your certificate authority reissue you a > new certificate. After it is installed and confirmed working, > revoke all previous certificates. > > 2. UPGRADE OPENSSL ON YOUR SERVER. While CloudFlare is protecting > your server from receiving Heartbleed attacks, you should still > upgrade to the latest version of OpenSSL as soon as possible. Get > version 1.0.1g here: > > https://www.openssl.org/. > > If you can't upgrade immediately, you can recompile OpenSSL with - > DOPENSSL_NO_HEARTBEATS. > > 3. CHANGE PASSWORDS. Even with these fixes, we recommend that you > change your password for CloudFlare and any other online services > you may use. You should also consider enabling 2-factor > authentication, which will help protect your account even if your > password is compromised. > > MORE INFORMATION AND FAQs. We have documented Frequently Asked > Questions (FAQs) here: > > https://support.cloudflare.com/hc/en-us/articles/201660084-Update- > on-the-Heartbleed-OpenSSL-Vulnerability > > If you have further questions, please contact www.cloudflare.com/ > support > > CloudFlare was one of the companies originally contacted by the > researchers who discovered the bug and has been working closely to > ensure that sites are protected. This is a serious issue for the > Internet as a whole and, as we learn more details, we'll continue > to update you on actions you can take to protect your online presence. > > Thanks again for your support! > > The CloudFlare Team > > > > P.S. CloudFlare cryptography expert, Nick Sullivan, will be on a > webcast this Wednesday, April 16th, at 10:00AM Pacific, to answer > any questions you may have about Heartbleed. Register here: > > https://cc.readytalk.com/cc/s/registrations/new?cid=it1914v5pbc0

