ICON customers and those on our infrastructure are not at risk

April 11, 2014 11:22 am

Home / Insights / ICON customers and those on our infrastructure are not at risk

All the websites and online applications developed by ICON and those who use ICON’s infrastructure are SAFE from the Heartbleed bug.

ICON do not use OpenSSL to terminate SSL connections. ICON uses the Microsoft Secure Channel (aka SChannel) which is not susceptible to the Heartbleed vulnerability.

imageprovider

What is the Heartbleed bug?

An encryption flaw called the Heartbleed bug has already coined the title for the biggest security threat the Internet has ever seen. Frustratingly the problem is very technical and because of this it is easy for regular users to ignore.

The root problem of Heartbleed is encryption. Think of encryption like a secret language between two people. In encryption terms this language works as a set of encryption keys.

The internet has a set of protocols for handling security commonly referred to as Secure Sockets Layer (SSL) and is a major part of how the modern web works. The most common implementation is a free and open source version of SSL known as OpenSSL.

Open SSL runs on about 66% of the web. Even if you don’t ever see it or understand it chances are you interact with it several times a day. Heartbleed is a vulnerability within Open SSL that allows a user access to the security keys for the server and can steal all the data for personal use without detection.

There is a fix in form of a patch that developers worldwide have been implementing and the problem is being reviewed. However all users of most major websites are being encouraged to change their passwords. We advise you do the same. Take a look at this great article by Mashable about the passwords you should really think about changing.

Need help with Web Development? See how we can help

Tags: , , , ,