Mint won't give a clear answer about Heartbleed
21–30 of 33 posts
Re: Mint won't give a clear answer about Heartbleed
#22> You say there's no evidence that customer data was affected, but the heartbleed bug leaves no logs, so that is not re-assuring at all
Well, if they're looking for people making use of the data received by the exploit that is re-assuring..
> You've said before that Mint servers are being updated, which suggests that it was exposed. If this is the case, have you gotten new SSL certificatess? (this is extremely important see next point)
Almost everyone was exposed. I'd like to know they have a new ssl cert too but not because of why you want them to.
> Even if I take a personal precaution and change my Mint and bank account passwords, if a hacker stole your cert at any time and you haven't gotten a new one, all my accounts are STILL vulnerable no matter how many times I change the password. This is because they basically have a permanent back door into Mint until you get a new SSL cert.
No, no they don't I don't think you understand ssl at all.
> Basically, if you don't answer the following questions, we have no choice but to STOP USING MINT FOREVER in order to secure ourselves. 1. Was Mint EVER vulnerable to the heartbleed bug (which has existed for 2 years) 2. If so, has the SSL cert been revoked and a new one acquired?
Good, stop using it, you're taking up security analyst resources to answer your stupid questions instead of letting them make sure everything is solid.
Re: Mint won't give a clear answer about Heartbleed
#23What is unclear about the response: "As indicated, our engineers have verified Mint is not affected by "Heartbleed." Password resets and re-issuing of SSL certificates are not required at this time." It seems that they are saying either (a) they are not using OpenSSL, or (b) they were using a version of OpenSSL without the vulnerability. Is there anything wrong with assuming that given their statements?
I think there is something wrong with it. As a site that has access to financial records, I would expect them to explain in detail why they aren't affected and if they were ever vulnerable. For instance, if they are using IIS (I know, I know) it would be an easy answer. The fact they are not explaining clearly and in detail leads me to believe that there is/was something amiss. The transparency expectation of them is…
Re: Mint won't give a clear answer about Heartbleed
#24Just deleted my Mint account; if they're not going to be transparent around this, I flat out can't trust them with my financial information.
Re: Mint won't give a clear answer about Heartbleed
#25Just deleted my Mint account; if they're not going to be transparent around this, I flat out can't trust them with my financial information.
If you can't trust them with your financial information, how can you trust that they actually deleted your account?
Re: Mint won't give a clear answer about Heartbleed
#26What is unclear about the response: "As indicated, our engineers have verified Mint is not affected by "Heartbleed." Password resets and re-issuing of SSL certificates are not required at this time." It seems that they are saying either (a) they are not using OpenSSL, or (b) they were using a version of OpenSSL without the vulnerability. Is there anything wrong with assuming that given their statements?
"is not affected" being the operative wording. users want to know if their data has ever been at risk. still, surely everyone can just assume it was affected, act accordingly, and move on?
After a small amount of research, it looks like they run Java webservers, along with (or on?) F5 Big-IP platforms, with the later likely providing hardware SSL decryption that isn't vulnerable to Heartbleed (mostly, apparently there were some vulnerabilities in certain configurations where it would fall back to Open-SSL.) The way Java webserver allocates memory is also different that the typical Apache/Linux server, so it is unlikely that even if the server was vulnerable that a hacker would actually be able to pull any data of any value from the chunks they could get.
I don't profess to be an expert on server security or the F5 Big-IP platform, but my point is, it would appear that there is no reason to not believe Mint when they say they investigated and have no reason for concern.
Re: Mint won't give a clear answer about Heartbleed
#27What is unclear about the response: "As indicated, our engineers have verified Mint is not affected by "Heartbleed." Password resets and re-issuing of SSL certificates are not required at this time." It seems that they are saying either (a) they are not using OpenSSL, or (b) they were using a version of OpenSSL without the vulnerability. Is there anything wrong with assuming that given their statements?
I think there is something wrong with it. As a site that has access to financial records, I would expect them to explain in detail why they aren't affected and if they were ever vulnerable. For instance, if they are using IIS (I know, I know) it would be an easy answer. The fact they are not explaining clearly and in detail leads me to believe that there is/was something amiss. The transparency expectation of them is…
Re: Mint won't give a clear answer about Heartbleed
#28netcraft shows mint.com is using f5 BigIP, if they terminate SSL using BigIP and should not be affected: https://devcentral.f5.com/articles/openssl-heartbleed-cve-20...
Re: Mint won't give a clear answer about Heartbleed
#29Earlier quoted context omitted.
True, but people tend to take security in a very strict manner. (With just cause.) The mod could have said, "was not affected", but instead and using improper word use, said "is not affected[sic]". Someone can correct me if I'm wrong, but I believe the proper use is either, was not affected or is not effected, not some combination of the two. The true point is, the statement is inherently unclear as to when, much mor…
Proper use is to communicate abundant details to remove any ambiguity in phrasing.
Re: Mint won't give a clear answer about Heartbleed
#30Earlier quoted context omitted.
"is not affected" being the operative wording. users want to know if their data has ever been at risk. still, surely everyone can just assume it was affected, act accordingly, and move on?
Except in this case, seeing as it seems that Mint hasn't got new ssl certs or private keys, the only way to 'act accordingly' is to never use the service again.