What is unclear about the response: "As indicated, our engineers have verified Mint is not affected by "Heartbleed." Password resets and re-issuing of SSL certificates are not required at this time." It seems that they are saying either (a) they are not using OpenSSL, or (b) they were using a version of OpenSSL without the vulnerability. Is there anything wrong with assuming that given their statements?
Mint won't give a clear answer about Heartbleed
11–20 of 33 posts
Re: Mint won't give a clear answer about Heartbleed
#12Earlier quoted context omitted.
"is not affected" being the operative wording. users want to know if their data has ever been at risk. still, surely everyone can just assume it was affected, act accordingly, and move on?
Except in this case, seeing as it seems that Mint hasn't got new ssl certs or private keys, the only way to 'act accordingly' is to never use the service again.
Re: Mint won't give a clear answer about Heartbleed
#13What is unclear about the response: "As indicated, our engineers have verified Mint is not affected by "Heartbleed." Password resets and re-issuing of SSL certificates are not required at this time." It seems that they are saying either (a) they are not using OpenSSL, or (b) they were using a version of OpenSSL without the vulnerability. Is there anything wrong with assuming that given their statements?
True, but people tend to take security in a very strict manner. (With just cause.) The mod could have said, "was not affected", but instead and using improper word use, said "is not affected[sic]". Someone can correct me if I'm wrong, but I believe the proper use is either, was not affected or is not effected, not some combination of the two. The true point is, the statement is inherently unclear as to when, much mor…
Re: Mint won't give a clear answer about Heartbleed
#14Go try to read some some of their dev docs.... I do not believe anyone in the company can give clear and concise responses to anything.
Re: Mint won't give a clear answer about Heartbleed
#15They should at least give us some more info, like which openssl version their running (if they use openssl)
That's probably not a great idea - it just instantly confirms them as a viable future target if a bug in that particular version comes up with a hole in it later. I'm personally okay with "We were not affected by the bug" - random internet people shouldn't have details on the software your company runs internally. One more thing for a potential bad guy to exploit. Besides, if they'd be willing to lie about being affe…
This is mint, for heavens sake, who do all kinds of contortions to downplay the fact that the whole service relies on the having all your passwords and banking details, instead of using their clout to push for sane Oauth-style access tokens for limited access to bank accounts.
Re: Mint won't give a clear answer about Heartbleed
#16They should at least give us some more info, like which openssl version their running (if they use openssl)
That's probably not a great idea - it just instantly confirms them as a viable future target if a bug in that particular version comes up with a hole in it later. I'm personally okay with "We were not affected by the bug" - random internet people shouldn't have details on the software your company runs internally. One more thing for a potential bad guy to exploit. Besides, if they'd be willing to lie about being affe…
For instance, at my work, we very explicitly said that only two internal systems, our wiki and our issue tracking system, used that version of openssl. Those systems had no user data and had a different set of certs. It is essential to give details. http://blog.taximagic.com/heartbleed/