DAVE ROSS

Is there anyone whose password hasn’t been stolen?

Apr 10, 2014, 6:19 AM | Updated: 8:38 am

Heartbleed is a security breach in a widely-used type of encryption software. The very software des...

Heartbleed is a security breach in a widely-used type of encryption software. The very software designed to keep things like your password secret.

There is another major computer security breach – nicknamed “heartbleed” – and here’s what makes this one so special: It’s a security breach in a widely-used type of encryption software. The very software designed to keep things like your password secret!

Which means what we have here is literally a security breach in the software designed to prevent security breaches.

But not to worry – computer experts like Wolgfang Kandek have a way for you to protect yourself. “The prudent way is changing your passwords.”

Oh – but wait, you might have to change passwords twice, because Mr. Kandek says if you change your password before the website has patched its software, even your new password could be stolen.

“If that’s too troublesome, change it after you know the website has been fixed,” says Kandek.

And how might you know when it’s been fixed? Well, the site might send out an e-mail alert – but as Mr. Kandek points out, hackers, knowing you’re waiting for an e-mail alert, might send out phony e-mail alerts.

They’d say something like, “‘You should really change your password, click here to do this.’ And it would take you to a fake site that would then capture your username and password.”

So you have no way of knowing whether by trying to protect your information, you are in fact handing it over.

So let me see if I have this right: change your password now, and then just to be sure, change them again, but don’t trust anybody who tells you to change your password.

OK!

By the way – and I quote from a security website “the best passwords are ones that you can’t remember yourself and that can’t therefore be guessed by another human.”

So that’s the kind of password you want to choose. Because the only way for your information to be truly secure is if even you can’t get access to it.

Dave's Commentary

Dave Ross on KIRO Newsradio 97.3 FM
  • listen to dave rossTune in to KIRO Newsradio weekdays at 5am for Dave Ross on Seattle's Morning News.

Dave Ross

privacy pods...

Dave Ross

Ross: Tracking employees’ vital signs at work via privacy pods, what could go wrong?

I saw a Bloomberg story about the latest innovation to reduce your stress level at work: Privacy pods.

17 days ago

car culture...

Dave Ross

Ross: Are we killing car culture? Or is car culture killing the US?

I don’t think the question is whether we're going to "kill" our car culture. The real question is can we stop our car culture from killing the U.S.?

24 days ago

drivers data insurance...

Dave Ross

Ross: As cars release driving data to insurance, is your driving my business?

Every move you make, every swerve you take, every lane change you fake – someone’s watching you. Do drivers have a right to keep driving data private?

1 month ago

rent control...

Dave Ross

Ross: Rent control was never the answer in Wash.

The rent control bill died in the Washington State Legislature this week, even though Democrats control both houses.

2 months ago

end of democracy...

Dave Ross

Ross: Conservative activist earns applause for pledging an ‘end of Democracy’

The theme from Jack Posobiec's speech is that Jan. 6 was a righteous attack not on democracy, but on those who threaten democracy.

2 months ago

Image: Rep. Lauren Boebert, R-Colorado, is seen on Capitol Hill on Jan. 6, 2023. (Photo: Alex Brand...

Dave Ross

Ross: Voters can help cull bad politicians from the herd early

Let's remember that just about every occupant of a higher office once occupied a lower office, and was put there by us, Dave Ross says.

2 months ago

Is there anyone whose password hasn’t been stolen?