Heartbleed: Please Change Your Password 2014-04-14

Hey folks, so like 66% of the Web, we were affected by the Heartbleed bug, a massive security vulnerability that was announced last week and potentially allowed malicious actors to spy on encrypted information. On iNat, your data is encrypted whenever you connect to https://www.inaturalist.org (note the https, not http) and you see the little security lock icon in your browser's address bar. We also encrypt all submissions from our mobile apps. We don't really deal in particularly revealing information on iNat, but there is a risk that your password was exposed.

All of our systems were patched last week soon after the announcement, thereby protecting us against any new attacks, but we were only able to renew our potentially compromised SSL certificate this weekend (this is a file provided by a third party that we use to prove to your browser that we are who we say we are and not someone else pretending to be us).

The upshot of all this is that you should change your password at https://www.inaturalist.org/users/edit.

You should probably change your password on most of the rest of the web sites you use as well. For more about Heartbleed, check out

הועלה ב-יולי 11, 2020 07:25 אחה"צ על ידי hannahsun99 hannahsun99

תגובות

לא קיימות הערות בינתיים

הוספת תגובה

כניסה או הרשמה להוספת הערות