Massive security bug in OpenSSL

Here is a really great explanation of things. Just a few words I know, but everyone will be able to understand what the issue is all about after reading it. Also how to test if sites you use have still got the bug.

http://support.emsisoft.com/topic/14146-heartbleed-threat/?do=findComment&comment=107651

That was good.

Another post there suggested

Posted 2 minutes ago

Heartbleed test - Which services are or have been exposed: (10 000 sites)

https://github.com/musalbas/heartbleed-masstest/blob/master/top10000.txt

That list is defective.

After listing 639 vulnerable sites,

it list another group of 10,000 others which are mostly "Not Vulnerable" or "No SSL"

Banks that I use now or in the past are NOT shown as vulnerable,

Unfortunately they are shown as "No SSL" - INSTEAD IT SHOULD SAY UNTESTED,

because the home pages are HTTP, but as soon as you click LOGIN the site switched to HTTPS before you enter anything.

Must try harder :wacko: