A serious security defect was found in the software that is the foundation of security for a large percentage of Internet web sites. Organizations around the world have been frantically updating the affected software.

What is the Heartbleed bug?

The software that logs you in securely to a web site (the https: that you usually see) had a bug that could expose userids and passwords to an attacker. In addition to passwords, other highly sensitive information can be leaked. The ramifications of the problem are broad and potentially grave. Vendors are rushing updates, but not all web sites and services are patched at this point in time.

Why do I care?

Your password(s) to various websites may be compromised. Think about all the sensitive web sites you use!

What is Denison doing?

Denison ITS staff have updated affected software on all of our exposed web sites and services. We are still awaiting some vendor updates. We are examining all our 3rd party services to be sure they are patched as well. At this time, the risk of having your BigRedID and password exposed is minimal.

What can I do to protect myself?

Because this affected more than 1/2 million web sites and services, you are undoubtedly affected somewhere. For an idea of the impact on popular sites, check out the Mashable article “The Heartbleed Hit List”.

Changing your password is a good response, but if you use the new password at a site that is still vulnerable, your new password could still be at risk. Because Denison sites have been patched, we advise you to change your BigRedID password. (Go to MyDenison and select My Apps -> Change My BigRedID Password.)

The best steps you can take now are the same ones you should follow as a general practice:

(1) Use different passwords for all sites, especially highly sensitive sites such as banking. You should NEVER use your BigRedID password on any other site;

(2) Monitor your accounts for unusual activity. If the site/account has a “Last Time You Logged In” message, check to be sure it seems reasonable; and,

(3) Beware of phishing emails to update your password. NEVER click on password change links embedded in an email. The only safe way is to go to the web site directly and locate their password change link on the site itself. If you are still unsure, contact your bank or other institution for more information. The bad guys will almost certainly take advantage of this event to harm unsuspecting victims.

Additional questions may be directed to Kent King, Information Security Officer (kingk@denison.edu).

Update: Maintenance was completed at 6:30 AM.

Between 6:15 and 6:45 AM, ITS will perform routine maintenance to the MyDenison servers. MyDenison should be available again by 6:45 AM.

During this time period, if you have need to check your class list/course schedule, confirm your registration, or provide emergency contact information you can access Self-Service Banner directly at http://ssb.denison.edu. If you do not know your Self-Service PIN, you can reset it. Additional services may be accessed directly via these URLs:

Network testing will occur between 5:00AM & 7:00AM on 4/8/14 for continued testing of wireless equipment. The process will only effect the 4th floor of Slayter and the 4th floor of Samson-Talbot. Temporary network outages will occur during this time frame in these locations.

Network testing will be performed in Samson Talbot, Burton Morgan and Slayter on 4/1/14 between the hours of 5:00AM and 7:00AM. This testing will result in temporary service disruptions as we will be simulating power outages for data collection purposes.

Update: 7:00am Testing has been completed.

We will be testing Internet connection failover through our backup service provider on 3/27 from 5-7AM. These tests may cause brief outages in Internet connectivity on campus, and interrupt access to all BigRedID services, such as MyDenison, from off campus.