Marvel's Spider Man
releases on September 26, 2025!

Preorder now on CardKingdom Preorder now on TcgPlayer

Marvel's Spider Man
releases on September 26, 2025!

Preorder now on CardKingdom Preorder now on TcgPlayer
7 total results       Page 1 of 1
You must login or register to post a new reply
Posts [ 1 to 7 ]
Trade score 0 (100%)
Members
Registered: 15-Nov-2013 20:25
Posts: 34
10-Apr-2014 14:20 (Last edited: 24-Sep-2025 12:59)
1
Sorry Sebi. As of right now, I'm not using Deckbox until is is updated against the OpenSSL Heartbleed exploit. Scanning the site on LastPass shows it is still vulnerable.

Couldn't come at a worse time for you, considering how you're busy with the market features and recovering from TCGPlayer's abrupt changes, but security comes before Magic cards.

Please send out emails when things are patched.

For anyone who doesn't know what the heck I'm talking about, google "heartbleed".

Attachment: lastpass.png Size: 36.3 KB

Trade score 146 (100%)
Members
Registered: 28-Oct-2013 02:12
Posts: 73
No it is not. Lastpass is notorious for false positives on Heartbleed. Please do some research before trying to cause a scare. I tested it with both Qualys Lab and filipp.io testers and it passed.
Trade score 13 (100%)
Administrators
Registered: 18-May-2009 18:29
Posts: 3444
We've patched it yesterday. Not sure where you saw it's vulnerable.
Trade score 13 (100%)
Administrators
Registered: 18-May-2009 18:29
Posts: 3444
Trade score 0 (100%)
Members
Registered: 15-Nov-2013 20:25
Posts: 34
bactgudz wrote:No it is not. Lastpass is notorious for false positives on Heartbleed. Please do some research before trying to cause a scare. I tested it with both Qualys Lab and filipp.io testers and it passed.
Its true, LastPass only checks to see if OpenSSL is in use, not whether it is patched. However, Qualys Lab's test is still experimental (they admit this). I don't know anything about filippo.io.

sebi wrote:We've patched it yesterday. Not sure where you saw it's vulnerable.
First, good job on patching it.

According to LastPass, your certificates are still 6 months old. As I understand it, servers need both a patch and new certificates. Check this article (point #6) for a reference, though the article is not written for a technical audience.
http://www.motherjones.com/politics/2014/04/heartbleed-bug-internet-security-ssl
Trade score 62 (100%)
Members
Registered: 20-Jun-2011 01:11
Posts: 848
Xan wrote:
bactgudz wrote:No it is not. Lastpass is notorious for false positives on Heartbleed. Please do some research before trying to cause a scare. I tested it with both Qualys Lab and filipp.io testers and it passed.
Its true, LastPass only checks to see if OpenSSL is in use, not whether it is patched. However, Qualys Lab's test is still experimental (they admit this). I don't know anything about filippo.io.

sebi wrote:We've patched it yesterday. Not sure where you saw it's vulnerable.
First, good job on patching it.

According to LastPass, your certificates are still 6 months old. As I understand it, servers need both a patch and new certificates. Check this article (point #6) for a reference, though the article is not written for a technical audience.
http://www.motherjones.com/politics/2014/04/heartbleed-bug-internet-security-ssl

Yes, new certs will be needed, as the private key of the cert may have been compromised while Open SSL was still vulnerable.
Trade score 13 (100%)
Administrators
Registered: 18-May-2009 18:29
Posts: 3444
Yep, we'll be getting new certs.

The security issues are not finished looks like, there are other vulnerabilities discovered, so it might be wise to keep current certs and buy new ones when the waters settle.
Posts [ 1 to 7 ]
7 total results       Page 1 of 1
You must login or register to post a new reply