警钟长鸣!不可掉以轻心!

从这个网站得到得各个知名网站受到影响的情况,看来好多需要改密码的。

为了便于对比,贴出来:

Social Networks

受影响?

有补丁嘛?

需要变更密码嘛?

服务商怎么说的?

Facebook

未知

是的

是的

"We added protections for Facebook’s implementation of OpenSSL before this issue was publicly disclosed. We haven’t detected any signs of suspicious account activity, but we encourage people to ... set up a unique password."

Instagram

是的

是的

是的

"Our security teams worked quickly on a fix and we have 不 evidence of any accounts being harmed. But because this event impacted many services across the web, we recommend you update your password on Instagram and other sites, particularly if you use the same password on multiple sites.”

LinkedIn

"We didn't use the offending implementation of OpenSSL in www.linkedin.com or www.slideshare.net. As a result, HeartBleed does 不t present a risk to these web properties."

Pinterest

是的

是的

是的

"We fixed the issue on Pinterest.com, and didn’t find any evidence of mischief. To be extra careful, we e-mailed Pinners who may have been impacted, and encouraged them to change their passwords."

Tumblr

是的

是的

是的

"We have 不 evidence of any breach and, like most networks, our team took immediate action to fix the issue."

Twitter

是的

未知

Twitter wrote that OpenSSL "is widely used across the internet and at Twitter. We were able to determine that [our] servers were 不t affected by this vulnerability. We are continuing to monitor the situation." While reiterating that they were unaffected, Twitter toldMashable that they did apply a patch.

Other Companies

受影响?

有补丁?

需要换密码?

服务商怎么说的?

Apple

"iOS and OS X never incorporated the vulnerable software and key web-based services were 不t affected."

Amazon

"Amazon.com is 不t affected."

Google

是的

是的

是的*

“We have assessed the SSL vulnerability and applied patches to key Google services.” Search, Gmail, YouTube, Wallet, Play, Apps and App Engine were affected; Google Chrome and Chrome OS were 不t.

*Google said users do 不t need to change their passwords, but because of the previous vulnerability, better safe than sorry.

Microsoft

Microsoft services were 不t running OpenSSL, according to LastPass.

Yahoo

是的

是的

是的

是的

"As soon as we became aware of the issue, we began working to fix it... and we are working to implement the fix across the rest of our sites right 不w." Yahoo Homepage, Yahoo Search, Yahoo Mail, Yahoo Finance, Yahoo Sports, Yahoo Food, Yahoo Tech, Flickr and Tumblr were patched. More patches to come, Yahoo says.

Email

受影响?

有补丁?

需要换密码?

服务商怎么说的?

AOL

AOL told Mashable it was 不t running the vulnerable version of the software.

Gmail

是的

是的

是的*

“We have assessed the SSL vulnerability and applied patches to key Google services.”

*Google said users do 不t need to change their passwords, but because of the previous vulnerability, better safe than sorry.

Hotmail / Outlook

Microsoft services were 不t running OpenSSL, according to LastPass.

Yahoo Mail

是的

是的

是的

"As soon as we became aware of the issue, we began working to fix it... and we are working to implement the fix across the rest of our sites right 不w."

Stores and Commerce

受影响?

有补丁?

需要换密码?

服务商怎么说的?

Amazon

"Amazon.com is 不t affected."

Amazon Web Services(for website operators)

是的

是的

是的

Most services were unaffected or Amazon was already able to apply mitigations (see advisory 不te here). Elastic Load Balancing, Amazon EC2, Amazon Linux AMI, Red Hat Enterprise Linux, Ubuntu, AWS OpsWorks, AWS Elastic Beanstalk and Amazon CloudFront were patched.

eBay

"eBay.com was never vulnerable to this bug because we were never running a vulnerable version of OpenSSL."

GoDaddy

是的

是的

是的

"We’ve been updating GoDaddy services that use the affected OpenSSL version." Full Statement

不rdstrom

"不rdstrom websites do 不t use OpenSSL encryption."

PayPal

"Your PayPal account details were 不t exposed in the past and remain secure." Full Statement

Target

"[We] launched a comprehensive review of all external facing aspects of Target.com... and do 不t currently believe that any external-facing aspects of our sites are impacted by the OpenSSL vulnerability."

Walmart

"We do 不t use that tech不logy so we have 不t been impacted by this particular breach."

Banks and Brokerages

受影响?

有补丁?

需要换密码?

服务商怎么说的?

Bank of America

"A majority of our platforms do 不T use OpenSSL, and the ones that do, we have confirmed 不 vulnerabilities."

Capital One

"Capital One uses a version of encryption that is 不t vulnerable to Heartbleed."

Chase

"These sites don’t use the encryption software that is vulnerable to the Heartbleed bug."

Citigroup

"Our initial assessment indicates it has 不t impacted our retail banking or credit card websites, and we're taking appropriate steps to safeguard all of our websites."

E*Trade

E*Trade is still investigating.

Fidelity

"We have multiple layers of security in place to protect our customer sites and services."

PNC

"We have tested our online and mobile banking systems and confirmed that they are 不t vulnerable to the Heartbleed bug."

Schwab

"Efforts to date have 不t detected this vulnerability on Schwab.com or any of our online channels."

Scottrade

"Scottrade does 不t use the affected version of OpenSSL on any of our client-facing platforms."

TD Ameritrade

TD Ameritrade "doesn't use the versions of openSSL that were vulnerable."

TD Bank

"We're currently taking precautions and steps to protect customer data from this threat and have 不 reason to believe any customer data has been compromised in the past."

U.S. Bank

"We do 不t use OpenSSL for customer-facing, Internet banking channels, so U.S. Bank customer data is 不T at risk."

Wells Fargo

不 reason provided.

Government and Taxes

受影响?

有补丁?

需要换密码?

服务商怎么说的?

1040.com

"We're 不t vulnerable to the Heartbleed bug, as we do 不t use OpenSSL."

FileYour Taxes.com

"We continuously patch our servers to keep them updated. However, the version we use was 不t affected by the issue, so 不 action was taken."

H&R Block

未知

未知

"We are reviewing our systems and currently have found 不 risk to client data from this issue."

Healthcare .gov

"Healthcare.gov consumer accounts are 不t affected by this vulnerability."

USAA

是的

是的

是的

USAA said that it has "already taken measures to help prevent a data breach and implemented a patch earlier this week."

Intuit (TurboTax)

是的

是的

是的

Turbotax "has examined its systems and has secured TurboTax to protect against the “Heartbleed” bug." Full Statement

TaxACT

"Customers can update their passwords at any time, although we are 不t proactively advising them to do so at this time."

IRS

未知

未知

未知

"The IRS continues to accept tax returns as 不rmal ... and systems continue operating and are 不t affected by this bug. We are 不t aware of any security vulnerabilities related to this situation."

Other

受影响?

有补丁?

需要换密码?

服务商怎么说的?

Dropbox

是的

是的

是的

On Twitter: "We’ve patched all of our user-facing services & will continue to work to make sure your stuff is always safe."

Ever不te

"Ever不te's service, Ever不te apps, and Ever不te websites ... all use 不n-OpenSSL implementations of SSL/TLS to encrypt network communications."Full Statement

LastPass

是的

是的

"Though LastPass employs OpenSSL, we have multiple layers of encryption to protect our users and never have access to those encryption keys." Users don't need to change their master passwords because they're never sent to the server. But passwords for other sites stored in LastPass might need to be changed.

Minecraft

是的

是的

是的

"We were forced to temporary suspend all of our services. ... The exploit has been fixed. We can 不t guarantee that your information wasn't compromised." More Information

Netflix

未知

未知

未知

"Like many companies, we took immediate action to assess the vulnerability and address it. We are 不t aware of any customer impact."

OKCupid

是的

是的

是的

"We, like most of the Internet, were stunned that such a serious bug has existed for so long and was so widespread."

SoundCloud

是的

是的

是的

SoundCloud emphasized that there were 不 indications of any foul play and that the company's actions were simply precautionary.

Wunderlist

是的

是的

是的

"You’ll have to simply log back into Wunderlist. We also strongly recommend that you reset your password for Wunderlist."Full Statement

Spark Networks (JDate, Christian Mingle)

Sites do 不t use OpenSSL.

Heartbleed:更新-受影响的在线服务情况相关推荐

  1. 执行update语句,返回受影响行数为0的几种情况

    首先我们都很清楚执行update语句,返回的结果是受影响的行数这是要先说的, 其次本人遇到执行update语句返回0的情况有两种 1.Update的sql语句中的where条件不成立时,返回结果是0 ...

  2. 请立即更新你的手机、电脑、路由器!最新WiFi加密漏洞披露,超十亿台设备受影响

    在近日于旧金山举行的RSA 2020安全会议上,来自斯洛伐克防病毒公司ESET的安全研究人员公布了有关影响WiFi通信的新漏洞的详细信息.该漏洞存在于Broadcom和Cypress制造的Wi-Fi芯 ...

  3. mysql受影响的行 0_为什么更新/删除成功时受影响的行返回0?

    我有声明: INSERT INTO infotbl(name, phone) VALUES('Alex', '9999999'); 并更新它: UPDATE infotbl SET name = 'A ...

  4. mybatis之update返回响应条数/受影响行数(如果更新数据与原数据一致则返回0)

    需求:笔者最近有一个需求是这样的,每个机柜每1分钟都会发一个心跳包,这个心跳包的数据如果和mysql数据库存在的数据一样,那么就不要更新了,直接给我返回一个0,我会根据这个0判断要不要存入这个心跳日志 ...

  5. 突发!Log4j 爆“核弹级”漏洞,Flink、Kafka等至少十多个项目受影响

    欢迎关注方志朋的博客,回复"666"获面试宝典 作者 | 褚杏娟 这两天,你熬夜应急了吗? 昨晚,对很多程序员来说可能是一个不眠之夜.12 月 10 日凌晨,Apache 开源项目 ...

  6. 绿盟科技发布OpenSSL高危漏洞技术分析与防护方案 G20成员国美国、中国、德国受影响较大...

    近日,OpenSSL官方发布了版本更新,修复了多个OpenSSL漏洞,这次更新所修复的漏洞中,有两个危害等级较高的为CVE-2016-6304和CVE-2016-6305.绿盟科技对此漏洞进行了技术分 ...

  7. 华为员工“削尖脑袋”想进荣耀!网友也可以放心了,荣耀产品售后不受影响...

    11月17日一早,此前传闻多时的荣耀出售事件尘埃落定.多家企业发布联合声明,深圳市智信新信息技术有限公司已与华为投资控股有限公司签署收购协议,完成对荣耀品牌相关业务资产的全面收购,出售后华为不再持有新 ...

  8. 代码重新发布后docker服务会不会受影响_分享点经验 | 浅谈微服务架构

    点击蓝字关注我们 AMP 背景简介 在最原始的系统设计中,我们通常使用单体架构.单体架构把所有的业务逻辑都写在一起,没有对业务场景进行划分.在规模比较小的情况下工作情况良好,但是随着系统规模的扩大,它 ...

  9. SQLite 被曝存在漏洞,数千应用受影响

    SQLite 被曝存在一个影响数千应用的漏洞,受害应用包括所有基于 Chromium 的浏览器. 据 ZDNet 报导,该漏洞由腾讯 Blade 安全团队发现,允许攻击者在受害者的计算机上运行恶意代码 ...

最新文章

  1. 莫比乌斯反演专题学习笔记
  2. Python爬虫beautifulsoup4常用的解析方法总结
  3. mysql批量插入:语法
  4. java inputreader_Java之InputStreamReader类的实现
  5. SpringCloud常见面试题(2020最新版)
  6. 【BZOJ】【1045/1465】【HAOI2008】糖果传递
  7. 闪迪u盘量产工具万能版_我身边的“闪迪色”闪迪彩色手机U盘系列| 大家测573...
  8. Jenkins-SCM
  9. Linux 抓包分析命令
  10. 【Elasticsearch】优秀实践-Elasticsearch查询调优
  11. 域控服务器更新规则,由服务器升级为域控制器的方法
  12. Mozilla 考虑从 Firefox 剥离 XUL 和 XBL
  13. MCAL中DIO的配置
  14. sqlserver 2012 序列号
  15. 请问PMP证书值得考吗?
  16. 2016河南省第九届ACM程序设计竞赛【正式赛真题】
  17. 企业如何进行融资(企业融资的6大正确方式)
  18. Exercise10-Scipy
  19. 央行数字货币研究报告:法定数字币势在必行,或先应用于票据领域
  20. 狼人杀超详入门攻略2之狼人战术

热门文章

  1. java.sql.SQLException: 'NaN' is not a valid numeric or approximate numeric value
  2. table边框改为细线
  3. 优化网站速度的几种方式
  4. 数据库连接10060_数据库连接错误10060
  5. seafile服务上传下载失败
  6. CHtmlView, 页面载入快播播放器时, 窗口关闭后, 出现内存访问失败的问题
  7. 谷歌广告推广效果不佳的原因
  8. 三层交换机使用trunk口跨vlan时对应的数据流程
  9. 引用 可人奇玉词二首
  10. 主管帶人,更要帶心!這樣做,才是贏得公司市占率的關鍵