Categories: Science & Technology

Heartbleed bug: Canada Revenue Agency and Mumsnet hit by internet vulnerability

The Canadian tax authority and leading UK website for parents Mumsnet have both announced they have had data stolen by hackers exploiting the Heartbleed bug.

Mumsnet – which says it has 1.5 million registered members – said that it believed that the cyber thieves may have obtained passwords and personal messages before it patched its site.

The Canada Revenue Agency said that 900 people’s social insurance numbers had been stolen.

These are the first confirmed losses.

The Mumsnet said that user data was at risk when her own username and password were used to post a message online.

The site added that it was forcing its members to reset any password created on or before Saturday.

The Canada Revenue Agency said that 900 people’s social insurance numbers had been stolen

Canada’s tax agency was one of the first major organizations to cut services as a result of the flaw in OpenSSL – a cryptographic software library used by services to keep data transmissions private.

However, its action last Tuesday appears to have come too late.

“Regrettably, the CRA has been notified by the Government of Canada’s lead security agencies of a malicious breach of taxpayer data that occurred over a six-hour period,” the agency said on a message posted to its homepage.

“Based on our analysis to date, social insurance numbers (SIN) of approximately 900 taxpayers were removed from CRA systems by someone exploiting the Heartbleed vulnerability.”

“We are currently going through the painstaking process of analyzing other fragments of data, some that may relate to businesses, that were also removed.”

The Heartbleed bug was made public a week ago by Google and Codenomicon, a small Finnish security firm, which independently identified the problem.

OpenSSL is used to digitally scramble data as it passes between a user’s device and an online service in order to prevent others eavesdropping on the information.

It is used by many, but not all, sites that show a little padlock and use a web address beginning “https”.

The researchers discovered that because of a coding mishap hackers could theoretically access 64 kilobytes of unencrypted data from the working memory of systems using vulnerable versions of OpenSSL.

Although that is a relatively small amount, the attackers can repeat the process to increase their haul.

Mumsnet has been criticized for one aspect of its handling of the breach – its email to members contains an inline link that it suggests they click to reset their passwords.

By contrast Canada’s tax agency said it would not call or email the individuals it believed to be affected by its breach in order to avoid giving criminals a chance to exploit the situation.

Instead it said it would send out registered letters.

C6W0gxW2Jgs
Nancy Clayson

Nancy is a young, full of life lady who joined the team shortly after the BelleNews site started to run. She is focused on bringing up to light all the latest news from the technology industry. In her opinion the hi-tech expresses the humanity intellectual level. Nancy is an active person; she enjoys sports and delights herself in doing gardening in her spare time, as well as reading, always searching for new topics for her articles.

Recent Posts

Donald Trump and Elon Musk Celebrate Election Victory at UFC 309

Image source: Wikimedia Commons President-elect Donald Trump celebrated his election victory at the Ultimate Fighting…

5 days ago

White House 2024: Donald Trump Wins, Kamala Harris Calls Him to Concede Election

Millions of voters across the US chose to return Donald Trump to the White House…

2 weeks ago

Who Won? Donald Trump Declares Victory as He Addresses Jubilant Supporters in Florida

Donald Trump declares victory in the US election as he addresses jubilant supporters in Florida.…

2 weeks ago

Stocks Soaring as Donald Trump Closes in on US Victory

Stocks around the world are rising as Donald Trump appears to be on the cusp…

2 weeks ago

Who Won? Kamala Harris Cancels Election Night Party as Path to Victory Narrows

Donald Trump has won Pennsylvania, North Carolina and Georgia and taken a lead over Kamala…

2 weeks ago

Quincy Jones Dead at 91

Quincy Jones, the celebrated musician and producer who worked with Michael Jackson, Frank Sinatra, Ray…

2 weeks ago