User avatar #12 - nought (08/24/2014) [-]
can you explain ECC to a nub
plz I'm really interested
User avatar #13 to #12 - securityexplain (08/24/2014) [-]
I'm not all that well familiar with cryptography when it comes to details, although I can understand it quite well, I'd say.

From what I know, elliptic curve cryptography is basically a way of setting up encryption of some kind of data (a key, for example) with a certain mathematical formula, and is based on concept in which it is possible in theory to brute-force it through mathematical equations, but it takes so long to do it so no one bothers with it.

Altogether, its a quirky concept. It works marvelously against any half-assed attempts by amateurs, but it generally doesn't stand all that well against attacks perpetrated by professionals with serious equipment.
User avatar #14 to #13 - securityexplain (08/24/2014) [-]
Addendum: After reading a bit more on it, apparently its more widespread and a lot harder to crack than I've anticipated. I'm gonna have to read more closely about it.
#3 - atrocitustheking (04/11/2014) [-]
Hey man, I've just recently heard the news on this new hearbleed glitch (or whatever you'd call it). What on Earth do I do to protect myself and my important information? I've already deleted any sensitive information from my computer but is there anything else I should be doing?
Sorry to bother you again, but this seems like the kind of thing your profile was made for.
User avatar #4 to #3 - securityexplain (04/11/2014) [-]
No problem, thats why I'm here.

Well, here's the deal with it. The dudes making OpenSSL library kinda screwed up. Thats a bit of a big deal, since OpenSSL is used widely. Like, extremely widely.

Whats that got to do with regular people? Well, the major concern is that any server thats ran on Apache or Nginx (which is majority of Internet) is vulnerable, including secured HTTP part, which is almost always used for sites where you use credit cards and stuff. If the site is vulnerable, that means that people who wish to do so can gain large amounts of information about traffic between server and visitors. 99% of that is just incoherent gibberish with which you can't even wipe your arse. But every once in a while, they can obtain your personal info that you've used on that site.

So, what can you do to protect yourself?
Simple, wait it out. Sort of like what you do with hurricanes. The patch has been finished within days and is still being deployed all over the world, depending on how responsive site owners are. It kinda takes a while to cover like 50% of the internet.

Until some further notice, simply don't buy anything from the internet. If you're worried about loosing your personal info, you might also consider thoroughly deleting cookies.
User avatar #8 to #4 - atrocitustheking (04/12/2014) [-]
So where can I find this patch when they release it? On that note, where do I go to find out when it's released?
User avatar #9 to #8 - securityexplain (04/12/2014) [-]
You don't. The patch is already released and is being deployed world-wide. Its a server-side thing.
User avatar #10 to #9 - atrocitustheking (04/12/2014) [-]
Oh, so it's not me that needs the patch, it's the guy on the other side? The one running the site as opposed to users of that site?
User avatar #5 to #4 - atrocitustheking (04/11/2014) [-]
Excellent! Thanks man.
User avatar #6 to #5 - securityexplain (04/11/2014) [-]
Small addendum: Once it all settles down, I'd suggest you change passwords. On as many accounts as you can.
User avatar #7 to #6 - atrocitustheking (04/12/2014) [-]
Sounds like a plan. Thanks again, securityexplain.
#1 - warioteam (04/04/2014) [-]
Would you like any changes?
User avatar #2 to #1 - securityexplain (04/04/2014) [-]
Perfect! Cheers mate.

If there's anything I can do to pay you back, let me know.
