Monday, April 14, 2014

HeartBleed and Banks

The password manager Lastpass has added a function to test all the sites it manages and let you know what to do about that site with respect to the HeartBleed defect.  When I ran that function I got back a list of a dozen or so sites, including banks, along with Lastpass's determination of whether or not the defect had been patched and whether or not the new certificate had been issued.  I address this at more length in a subsequent blog entry.  It did tell me that I should change the password for Barclays.
I went to the Barclays web site and, after logging in, found this on the left side of the main page:
I clicked the link and the instructions were as follows:
Conclusion:  we all have some work to do.  Fortunately, I use Lastpass, so I have a list of all the sites where I have user ids and passwords.  Plus Lastpass has offered this service to help me prioritize what I should be doing.  


No comments:

Post a Comment

Printfriendly

Print Friendly and PDF