Welcome!

Apache Authors: Liz McMillan, Pat Romanski, Elizabeth White, Christopher Harrold, John Mertic

Blog Feed Post

Heartbleed, la plus grosse faille de l’Internet

Le 7 Avril 2014 a été décelé la plus sérieuse faille de sécurité de l’histoire d’internet, impactant l’intégrité de bases de données les plus sécurisées du monde. Cette brèche permet à un attaquant chevronné d’accéder à des informations sensibles incluant potentiellement les identifiants, mots de passe, numéros de cartes bancaires… et d’emporter la clé de sécurité du serveur qui héberge ces données.

Le moteur (OpenSSL) qui assure les connexions sécurisées et chiffrées entre un utilisateur et un site web est reconnaissable par un « https » dans la barre d’adresse ou un cadenas en bas à droite de votre navigateur. Une attaque Heartbleed ne laisse aucune trace sur le serveur, c’est pourquoi il est d’autant plus important de le combler. Car aucune attaque ne pourra être tracée, rendant une enquête impossible.

Les patchs de correction ont été livrés en 49 minutes. Mais l’ampleur des dégâts n’est pas encore connue car on ne sait pas si la faille a déjà été exploitée avant son identification. Vos mots de passe pourraient déjà avoir été dérobés. Facebook, Google, Gmail, Yahoo !, Dropbox, Pinterest, Instagram, Twitter, Tumblr … Aucuns de ces sites précisent avoir constatés des utilisations irrégulières de leurs services. Les éditeurs indiquent qu’ils ont évalués cette vulnérabilité et qu’ils recommandent toutefois aux utilisateurs de changer leurs mots de passe.

L’offre Microsoft de Provectio est-elle sensible à la faille HeartBleed ?

Les configurations par défaut de Windows ne comprennent pas OpenSSL, donc ne sont pas affectés par cette vulnérabilité. Windows est livré avec son propre composant de chiffrement appelé Secure Channel (aka SChannel ) , qui n’est pas sensible à la vulnérabilité Heartbleed . Cela s’applique à tous les systèmes d’exploitation Windows et IIS versions , jusqu’à et y compris IIS 8.5 fonctionnant sur tous les systèmes d’exploitation suivants : Windows Server 2003 et 2003R2, Windows Server 2008, Windows Server 2008R2, Windows Server 2012, Windows Server 2012R2. Les clients logiciels sur Windows qui utilisent OpenSSL au lieu de SChannel (livré dans Apache pour Windows) peuvent être vulnérables.

L’offre Linux de Provectio est-elle sensible à la faille HeartBleed ?

Les versions openssl impactés sont : 1.0.1 et 1.0.2-beta releases inclut aussi les versions 1.0.1f and 1.0.2-beta1. Sur notre plateforme OpenVPN nous exploitons la version OpenSSL 0.9.8k. Les distributions Linux Protection Suite, Linux Data Suite, Linux Virtual Hoster, Linux eMail Control ne sont pas impactés par cette faille de sécurité.

Nos éditeurs de sécurité déjà sur la brèche

Sophos, dont Provectio travaille sur l’obtention du statut Platinium, a d’ores et déjà commencé à déployer son patch de sécurité et documenté le sujet. L’ensemble du parc Sophos UTM de nos clients est déjà à jour.

Identification des services impactés

Toutefois, certains services hébergés par Provectio sont sensibles à cette faille, nous menons actuellement un programme de mise à niveau :

  •  VPN sites à sites et nomades : Nous déployons en ce moment les correctifs. Vous serez prévenu de prochaines interruptions de service momentanées si elles étaient nécessaires. Nous effectuerons le renouvellement des certificats pour les utilisateurs nomades du VPN. Nous vous contacterons pour effectuer la mise à jour sur vos postes de travail.
  • Serveurs Web hébergés : Renouvellement des certificats et changement de mot de passe.

En bon utilisateur, nous vous recommandons :

  1. Changez immédiatement les mots de passe des comptes Internet que vous considérez comme sensibles (par exemple votre banque, vos comptes email, votre compte PayPal, …) en générant des mots de passe forts et uniques
  2. Attendez 10 jours avant de changer vos autres mots de passe afin de laisser le temps aux différents sites web d’éliminer la faille Heartbleed. Il est inutile de changer vos autres mots de passe avant.
  3. Dans 10 jours, changez à nouveau les mots de passe de vos comptes sensibles en générant des mots de passe forts et uniques.
  4. Une fois l’étape 3 terminée, vous pouvez changer les mots de passe de vos comptes moins sensibles.

Nous vous recommandons l’utilisation d’un produit français Dashlane, pour la gestion sécurisée de vos mots de passe.

Le point le plus important est de vous assurer que vous utilisez des mots de passe différents sur chaque site, car si votre mot de passe est volé sur un site, il ne pourra pas être utilisé sur un autre ; c’était important avant Heartbleed et c’est devenu essentiel aujourd’hui.

 Si vous êtes vulnérable à ce type de failles et que votre prestataire ne vous suit pas, vous connaissez le chemin !

The post Heartbleed, la plus grosse faille de l’Internet appeared first on Provectio - Cloud Computing et Infogérance.

Read the original blog entry...

More Stories By Maxime Charlès

Maxime Charlès is co-founder and CEO of Provectio, a French organization dedicated to Cloud Computing, IT and Outsourcing. His motto : "to surround himself with the best without fear that they will exceed"

@ThingsExpo Stories
WebRTC is about the data channel as much as about video and audio conferencing. However, basically all commercial WebRTC applications have been built with a focus on audio and video. The handling of “data” has been limited to text chat and file download – all other data sharing seems to end with screensharing. What is holding back a more intensive use of peer-to-peer data? In her session at @ThingsExpo, Dr Silvia Pfeiffer, WebRTC Applications Team Lead at National ICT Australia, looked at differ...
With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo 2016 in New York. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be! Internet of @ThingsExpo, taking place June 6-8, 2017, at the Javits Center in New York City, New York, is co-located with 20th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry p...
IoT offers a value of almost $4 trillion to the manufacturing industry through platforms that can improve margins, optimize operations & drive high performance work teams. By using IoT technologies as a foundation, manufacturing customers are integrating worker safety with manufacturing systems, driving deep collaboration and utilizing analytics to exponentially increased per-unit margins. However, as Benoit Lheureux, the VP for Research at Gartner points out, “IoT project implementers often un...
SYS-CON Events announced today that Technologic Systems Inc., an embedded systems solutions company, will exhibit at SYS-CON's @ThingsExpo, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Technologic Systems is an embedded systems company with headquarters in Fountain Hills, Arizona. They have been in business for 32 years, helping more than 8,000 OEM customers and building over a hundred COTS products that have never been discontinued. Technologic Systems’ pr...
SYS-CON Events announced today that IoT Now has been named “Media Sponsor” of SYS-CON's 20th International Cloud Expo, which will take place on June 6–8, 2017, at the Javits Center in New York City, NY. IoT Now explores the evolving opportunities and challenges facing CSPs, and it passes on some lessons learned from those who have taken the first steps in next-gen IoT services.
SYS-CON Events announced today that WineSOFT will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Based in Seoul and Irvine, WineSOFT is an innovative software house focusing on internet infrastructure solutions. The venture started as a bootstrap start-up in 2010 by focusing on making the internet faster and more powerful. WineSOFT’s knowledge is based on the expertise of TCP/IP, VPN, SSL, peer-to-peer, mob...
SYS-CON Events announced today that delaPlex will exhibit at SYS-CON's @CloudExpo, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. delaPlex pioneered Software Development as a Service (SDaaS), which provides scalable resources to build, test, and deploy software. It’s a fast and more reliable way to develop a new product or expand your in-house team.
You think you know what’s in your data. But do you? Most organizations are now aware of the business intelligence represented by their data. Data science stands to take this to a level you never thought of – literally. The techniques of data science, when used with the capabilities of Big Data technologies, can make connections you had not yet imagined, helping you discover new insights and ask new questions of your data. In his session at @ThingsExpo, Sarbjit Sarkaria, data science team lead ...
The Internet of Things can drive efficiency for airlines and airports. In their session at @ThingsExpo, Shyam Varan Nath, Principal Architect with GE, and Sudip Majumder, senior director of development at Oracle, discussed the technical details of the connected airline baggage and related social media solutions. These IoT applications will enhance travelers' journey experience and drive efficiency for the airlines and the airports.
The security needs of IoT environments require a strong, proven approach to maintain security, trust and privacy in their ecosystem. Assurance and protection of device identity, secure data encryption and authentication are the key security challenges organizations are trying to address when integrating IoT devices. This holds true for IoT applications in a wide range of industries, for example, healthcare, consumer devices, and manufacturing. In his session at @ThingsExpo, Lancen LaChance, vic...
With billions of sensors deployed worldwide, the amount of machine-generated data will soon exceed what our networks can handle. But consumers and businesses will expect seamless experiences and real-time responsiveness. What does this mean for IoT devices and the infrastructure that supports them? More of the data will need to be handled at - or closer to - the devices themselves.
SYS-CON Events announced today that Dataloop.IO, an innovator in cloud IT-monitoring whose products help organizations save time and money, has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Dataloop.IO is an emerging software company on the cutting edge of major IT-infrastructure trends including cloud computing and microservices. The company, founded in the UK but now based in San Fran...
In his session at @ThingsExpo, Sudarshan Krishnamurthi, a Senior Manager, Business Strategy, at Cisco Systems, will discuss how IT and operational technology (OT) work together, as opposed to being in separate siloes as once was traditional. Attendees will learn how to fully leverage the power of IoT in their organization by bringing the two sides together and bridging the communication gap. He will also look at what good leadership must entail in order to accomplish this, and how IT managers ca...
SYS-CON Events announced today that CA Technologies has been named “Platinum Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY, and the 21st International Cloud Expo®, which will take place October 31-November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. CA Technologies helps customers succeed in a future where every business – from apparel to energy – is being rewritten by software. From ...
SYS-CON Events announced today that Cloud Academy will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Cloud Academy is the industry’s most innovative, vendor-neutral cloud technology training platform. Cloud Academy provides continuous learning solutions for individuals and enterprise teams for Amazon Web Services, Microsoft Azure, Google Cloud Platform, and the most popular cloud computing technologies. Ge...
The best way to leverage your Cloud Expo presence as a sponsor and exhibitor is to plan your news announcements around our events. The press covering Cloud Expo and @ThingsExpo will have access to these releases and will amplify your news announcements. More than two dozen Cloud companies either set deals at our shows or have announced their mergers and acquisitions at Cloud Expo. Product announcements during our show provide your company with the most reach through our targeted audiences.
20th Cloud Expo, taking place June 6-8, 2017, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy.
SYS-CON Events announced today that Outlyer, a monitoring service for DevOps and operations teams, has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Outlyer is a monitoring service for DevOps and Operations teams running Cloud, SaaS, Microservices and IoT deployments. Designed for today's dynamic environments that need beyond cloud-scale monitoring, we make monitoring effortless so you...
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend @CloudExpo | @ThingsExpo, June 6-8, 2017, at the Javits Center in New York City, NY and October 31 - November 2, 2017, Santa Clara Convention Center, CA. Learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
Have you ever noticed how some IT people seem to lead successful, rewarding, and satisfying lives and careers, while others struggle? IT author and speaker Don Crawley uncovered the five principles that successful IT people use to build satisfying lives and careers and he shares them in this fast-paced, thought-provoking webinar. You'll learn the importance of striking a balance with technical skills and people skills, challenge your pre-existing ideas about IT customer service, and gain new in...