Click Labs Click Labs

Navigation

  • About Us
  • Franchise
  • Who We Are
  • Products
    • JungleWorks
    • Jugnoo
  • Contact Us
  • 14 April 2014

“HeartBleed” for Apps: Secure Your Server and Data

You would have all read about the (in)famous “Heartbleed” bug. While there are a lot of articles floating around to educate you on what it is and what it can do, there’s none solving an app developer’s questions. So, here it is.

Heartbleed bug a.k.a an OpenSSL vulnerability CVE-2014-0160 was discovered on April 7 2014. This bug was introduced in OpenSSL version 1.0.1 and is out there since March 2012. OpenSSL, one of the pillars of the encryption on internet and the target victim of the bug, is widely used encryption library and is used to provide secure connections between servers and the clients. This bug has affected nearly all the major web service providers who use HTTPS to provide customers secure access to their services. It can potentially reveal the sensitive data about your customers without leaving any traces and needs to be fixed at the earliest. Amazon, Facebook, Google, Yahoo are working or have already issued the patches to this bug.

If you are a developer of the mobile and web services and managing an HTTPS server, here’s what you need to do to secure your server and your customer’s data.

1. Upgrade OpenSSL library

On Ubuntu systems:
sudo apt-get install –only-upgrade libssl1.0.0

You can recheck using the following command.
sudo openssl version -a

If the “build on” date is Apr 7 or later then your server has been patched for “Heartbleed bug”. Please reboot your server and then follow the remaining three steps.

2. Revoke all the SSL certificates on this server
3. Regenerate all SSL private keys and certificates
4. Recommend your customers to change their passwords

Very rarely it happens, that a bug can affect the core foundation of internet. This is one of the few such cases. All the major web service providers are putting together the fixes in place and it is widely feared that it will take months for nearly all the web service providers providing HTTPS services to apply these fixes and make the customer data secure.

It is also highly recommended to ask your customers to change their passwords as customers typically use same passwords across different web services and while you may have secured your service but other web services might not have done the same.

Have fun fixing the heart!!!

← Want a Custom Taxi App better than Uber for your Cab Company?
How Mobile Apps for Restaurants Help Reduce Wait Times? →
No comments yet.

Leave a Reply Click here to cancel reply.

Industry Insights

Stay updated with the latest news, trending topics and useful resources delivered to you every week.

Thanks a lot for subscribing

Guest User
View all posts by Guest User →
Join us on Social Media

About Us

We are one of the leading Franchise providers in the industry focusing on on-demand taxi franchise, food ordering platform franchise and on-demand salon services. With a complete end to end training program, we are helping the young and aspiring entrepreneurs to run their Franchise Business successfully

Products

  • JungleWorks
  • Jugnoo
  • Juggernaut
  • JCurve
  • Delta School

Download

  • Jungleworks
  • Jugnoo
  • Jcurve
  • Delta School

Contact Us

USA

Click Labs Inc, 4830 West Kennedy Blvd, Suite 600, Tampa Florida 33609, U.S.A

India

Plot No 10, 1st Floor, IT Park, Chandigarh, India

Email: contact@clicklabs.co

TwitterGoogle PlusLinkedInPinterest
Click Labs © 2024. All Rights Reserved.
Careers | Blog | Privacy Policy