Stopping the Bleeding

Heartbleed has been big news in both the security industry and mainstream media for more than a week now.  Our partners and customers tend to be very security conscious so they have been doing their due diligence. As a result, we have fielded many inquiries asking if Heartbleed impacts WinMagic and SecureDoc. We looked into this and it doesn’t.

If you are reading this blog you  probably already know all about Heartbleed, but if not, this is a good site to check out: heartbleed.com to learn more. In short, Heartbleed is a serious bug that affects servers that utilize some versions of the open source “OpenSSL” cryptographic library. By some counts OpenSSL is used by over half of the world’s servers (mostly Linux based) so it’s definitely a wide spread problem. Since the bug can be exploited to read a servers memory and potentially expose encryption keys, usernames, passwords and other sensitive data it is a very serious problem too.

While Heartbleed is a serious problem, it’s also a relatively easy problem to detect and correct if your site has it. I used this tool ssllabs.com/ssltest  to check websites for the bug. After you run it, look for the sentence “This server is not vulnerable to the Heartbleed attack. (Experimental)” in the output.

Heartbleed is also relatively easy to address because the newest version of OpenSLL has a fix.

As I stated up front, WinMagic is not impacted by Heartbleed. Our website doesn’t have the Heartbleed bug nor does SecureDoc. The SecureDoc Enterprise Server (SES) has a web console interface but it doesn’t use OpenSSL to protect the connection to the browser. OpenSSL’s SSL/TLS is not used to protect the communication between the encryption client on the end point and SES/SDConnex either.

To sum up, SecureDoc and WinMagic are not impacted by Heartbleed and while it’s a widespread and serious bug, it’s one that is easy to detect and fix.  Most mainstream services should have it patched within a week if they haven’t already done so. Personally I am going to follow the advice of the service providers and change my passwords once they have applied the patch.

Previous Post
Managing BitLocker in the Enterprise
Next Post
SecureDoc Updates Are Here!

Related Posts

Human Error with Big Consequences

Everyone makes mistakes, after all we are only human, and no one is perfect. We are prone to mistakes, but what happens when these mistake have high consequences, not only affecting the individual that made the mistake, but millions of…
Read more

An offer you can’t refuse

This post is going to be a lot of shameless self-promotion for WinMagic but it’s something we think is important as it’s tied directly to the recent launch of SecureDoc 6.1. (more…)

Educating with Data Security

Education institutions have numerous important and sensitive documents stored that they are responsible for. This sensitive information belongs to students, parents and faculty and comes in the form of loans, financial records, employment records, etc. (more…)
Read more

Leave a Reply

Your email address will not be published. Required fields are marked *

Fill out this field
Fill out this field
Please enter a valid email address.

Menu