Live data from Hacker News

Mint won't give a clear answer about Heartbleed

satisfaction.mint.com

11–20 of 33 posts

Re: Mint won't give a clear answer about Heartbleed

#11
post #3

What is unclear about the response: "As indicated, our engineers have verified Mint is not affected by "Heartbleed." Password resets and re-issuing of SSL certificates are not required at this time." It seems that they are saying either (a) they are not using OpenSSL, or (b) they were using a version of OpenSSL without the vulnerability. Is there anything wrong with assuming that given their statements?

True, but people tend to take security in a very strict manner. (With just cause.) The mod could have said, "was not affected", but instead and using improper word use, said "is not affected[sic]". Someone can correct me if I'm wrong, but I believe the proper use is either, was not affected or is not effected, not some combination of the two. The true point is, the statement is inherently unclear as to when, much more so when you introduce faulty word use.

Re: Mint won't give a clear answer about Heartbleed

#12
post #5

Earlier quoted context omitted.

"is not affected" being the operative wording. users want to know if their data has ever been at risk. still, surely everyone can just assume it was affected, act accordingly, and move on?

Except in this case, seeing as it seems that Mint hasn't got new ssl certs or private keys, the only way to 'act accordingly' is to never use the service again.

ah, right. i didn't consider that their private key could have been leaked if they were once vulnerable (i was only considering passwords and the like). good point, thanks!

Re: Mint won't give a clear answer about Heartbleed

#13
post #3

What is unclear about the response: "As indicated, our engineers have verified Mint is not affected by "Heartbleed." Password resets and re-issuing of SSL certificates are not required at this time." It seems that they are saying either (a) they are not using OpenSSL, or (b) they were using a version of OpenSSL without the vulnerability. Is there anything wrong with assuming that given their statements?

True, but people tend to take security in a very strict manner. (With just cause.) The mod could have said, "was not affected", but instead and using improper word use, said "is not affected[sic]". Someone can correct me if I'm wrong, but I believe the proper use is either, was not affected or is not effected, not some combination of the two. The true point is, the statement is inherently unclear as to when, much mor…

Proper use is to communicate abundant details to remove any ambiguity in phrasing.

Re: Mint won't give a clear answer about Heartbleed

#15
post #4

They should at least give us some more info, like which openssl version their running (if they use openssl)

That's probably not a great idea - it just instantly confirms them as a viable future target if a bug in that particular version comes up with a hole in it later. I'm personally okay with "We were not affected by the bug" - random internet people shouldn't have details on the software your company runs internally. One more thing for a potential bad guy to exploit. Besides, if they'd be willing to lie about being affe…

If they make a lie that can be proven, they invite liability ($$). If they make an unclear statement and people foolishly trust then to mean more than they say, they skate by. That's why users should always assume the vendor is being intentionally deceptive.

This is mint, for heavens sake, who do all kinds of contortions to downplay the fact that the whole service relies on the having all your passwords and banking details, instead of using their clout to push for sane Oauth-style access tokens for limited access to bank accounts.

Re: Mint won't give a clear answer about Heartbleed

#16
post #4

They should at least give us some more info, like which openssl version their running (if they use openssl)

That's probably not a great idea - it just instantly confirms them as a viable future target if a bug in that particular version comes up with a hole in it later. I'm personally okay with "We were not affected by the bug" - random internet people shouldn't have details on the software your company runs internally. One more thing for a potential bad guy to exploit. Besides, if they'd be willing to lie about being affe…

I agree that they shouldn't publicize which specific other versions of openssl they use/used, but they should be much more forthcoming about what systems (and potentially keys) in their architecture were affected and what data such systems had.

For instance, at my work, we very explicitly said that only two internal systems, our wiki and our issue tracking system, used that version of openssl. Those systems had no user data and had a different set of certs. It is essential to give details. http://blog.taximagic.com/heartbleed/

Post reply on HN