- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Security Catastrophe: have you changed your passwords?
Collapse
X
-
-
The thing is, at the moment you can't be sure all servers have been patched, which means that if you change your password now you could just be giving away the new one, whereas your existing password might never have been compromised.
It can make more sense to wait a few days for everything to be updated, and only then change your password.
Though that may be too late, of course
Security expert Bruce Schneier has a good view on it: "On the scale of 1 to 10, this is an 11." https://www.schneier.com/blog/archiv...eartbleed.html -
There ought to be a standard drill for a vulnerability like this, in that as soon as it is patched the site should direct users to a password replacement page where they are validated by their answers to a decent set of contextual questions (stored on a separate server solely for this purpose) and prompted to enter a new password.Originally posted by NickFitz View PostThe thing is, at the moment you can't be sure all servers have been patched, which means that if you change your password now you could just be giving away the new one, whereas your existing password might never have been compromised. ...Work in the public sector? Read the IR35 FAQ hereComment
-
To avoid this kind of issue I don't use passwords. Much more secure.Comment
-
So how do you log into CUK?Originally posted by MyUserName View PostTo avoid this kind of issue I don't use passwords. Much more secure.Comment
-
Let us not forget EU open doors immigration benefits IT contractors more than anyoneComment
-
Just don't use anything that's open source. Problem solved.
Good write up of the problem:
http://www.theregister.co.uk/2014/04...eed_explained/
Not quite as stupid as the recent Apple bug.Will work inside IR35. Or for food.Comment
-
An arrogant and stubborn refusal to accept the fact I can'tOriginally posted by vwdan View PostSo how do you log into CUK?Comment
-
To be honest, I think I totally misinterpreted your first post - I thought you were making some point about alternate authentication methods.Originally posted by MyUserName View PostAn arrogant and stubborn refusal to accept the fact I can'tComment
-
AbCdEf - Sh1rLeY?Originally posted by zeitghostThere we are, I've changed all mine from 123456 to ABCDEF.
Fixed.Comment
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- Business expenses: What IT contractors can and cannot claim from HMRC Jan 30 08:44
- April’s umbrella PAYE risk: how contractors’ end-clients are prepping Jan 29 05:45
- How EV tax changes of 2025-2028 add up for contractor limited company directors Jan 28 08:11
- Under the terms he was shackled by, Ray McCann’s Loan Charge Review probably is a fair resolution Jan 27 08:41
- Contractors, a £25million crackdown on rogue company directors is coming Jan 26 05:02
- How to run a contractor limited company — efficiently. Part one: software Jan 22 23:31
- Forget February as an MSC contractor seeking clarity, and maybe forget fairness altogether Jan 22 19:57
- What contractors should take from Honest Payroll Ltd’s failure Jan 21 07:05
- HMRC tax avoidance list ‘proves promoters’ nothing-to-lose mentality’ Jan 20 09:17
- Digital ID won’t be required for Right To Work, but more compulsion looms Jan 19 07:41

Comment