Wednesday, April 16, 2014

Comment firm IDC Research on the loophole "Hartbled" security

By: MB Kumar , director of software research , company IDC Middle East , Turkey and Africa

 The spread of exploiting a loophole " Hartbled " Heartbleed reaffirms that hackers are still pursuing the discovery of vulnerabilities in software applications , puts a huge responsibility on the shoulders of developers and increases the importance of a safe programming methods . This gap allows hackers to obtain passwords and access information to Web sites without leaving any trace behind in the activity log . This " compiler error " led to the exposure of many sites , users and exposing their information to theft and loss , and increased concern of people on the subject of privacy on the Internet , not to mention the issues of privacy and confidentiality that have been raised about the practices and the U.S. National Security Agency .

 And users in the Middle East are not immune to the dangers of exploiting a loophole Hartbled , where this gap has affected many of the global social networking sites , in addition to their impact on content sites and e-mail and Web services . Given that this gap has existed for about two years , it is likely to have been leaked through some sensitive information , such as credit card payments . Now, companies operate affected by the Vulnerability to address the problem , which is continuing with its users and urging them to change their passwords .

 Will not work , one that is quick to change the words of his secret , as his information will remain vulnerable unless emphasizes social networking sites and web services , e-mail first they have addressed this gap . It is noteworthy that some companies put forward solutions to test sites that deal with it or you visit, and notify you if those sites may have been exploited through this gap . In the meantime , users are advised to take caution and change their passwords on a regular basis , and do not use one password in more than one location , while companies that it is worth considering the possibility of adopting a mechanism to double check logons to better protect users .

 This kind of security problems happen between now and then , so companies must invest in technical programming and encryption mechanisms more robust and secure. It also highlights these problems need to increase user awareness on the issues of security and safety on the Internet

No comments:

Post a Comment