Live data from Hacker News

Mint won't give a clear answer about Heartbleed

satisfaction.mint.com

1–10 of 33 posts

Re: Mint won't give a clear answer about Heartbleed

#3
What is unclear about the response: "As indicated, our engineers have verified Mint is not affected by "Heartbleed." Password resets and re-issuing of SSL certificates are not required at this time."

It seems that they are saying either (a) they are not using OpenSSL, or (b) they were using a version of OpenSSL without the vulnerability. Is there anything wrong with assuming that given their statements?

Re: Mint won't give a clear answer about Heartbleed

#5
post #3

What is unclear about the response: "As indicated, our engineers have verified Mint is not affected by "Heartbleed." Password resets and re-issuing of SSL certificates are not required at this time." It seems that they are saying either (a) they are not using OpenSSL, or (b) they were using a version of OpenSSL without the vulnerability. Is there anything wrong with assuming that given their statements?

"is not affected" being the operative wording. users want to know if their data has ever been at risk. still, surely everyone can just assume it was affected, act accordingly, and move on?

Re: Mint won't give a clear answer about Heartbleed

#6
post #4

They should at least give us some more info, like which openssl version their running (if they use openssl)

That's probably not a great idea - it just instantly confirms them as a viable future target if a bug in that particular version comes up with a hole in it later.

I'm personally okay with "We were not affected by the bug" - random internet people shouldn't have details on the software your company runs internally. One more thing for a potential bad guy to exploit.

Besides, if they'd be willing to lie about being affected, they'd be willing to lie about using a particular version of software, so nothing gained anyways.

Re: Mint won't give a clear answer about Heartbleed

#7
post #3

What is unclear about the response: "As indicated, our engineers have verified Mint is not affected by "Heartbleed." Password resets and re-issuing of SSL certificates are not required at this time." It seems that they are saying either (a) they are not using OpenSSL, or (b) they were using a version of OpenSSL without the vulnerability. Is there anything wrong with assuming that given their statements?

I think their issue is that "is not affected" implies the present moment, and makes no claims about possible exposure in the past.

Re: Mint won't give a clear answer about Heartbleed

#8
post #3

What is unclear about the response: "As indicated, our engineers have verified Mint is not affected by "Heartbleed." Password resets and re-issuing of SSL certificates are not required at this time." It seems that they are saying either (a) they are not using OpenSSL, or (b) they were using a version of OpenSSL without the vulnerability. Is there anything wrong with assuming that given their statements?

I think there is something wrong with it.

As a site that has access to financial records, I would expect them to explain in detail why they aren't affected and if they were ever vulnerable.

For instance, if they are using IIS (I know, I know) it would be an easy answer.

The fact they are not explaining clearly and in detail leads me to believe that there is/was something amiss.

The transparency expectation of them is greater.

Re: Mint won't give a clear answer about Heartbleed

#9
post #5
post #3

What is unclear about the response: "As indicated, our engineers have verified Mint is not affected by "Heartbleed." Password resets and re-issuing of SSL certificates are not required at this time." It seems that they are saying either (a) they are not using OpenSSL, or (b) they were using a version of OpenSSL without the vulnerability. Is there anything wrong with assuming that given their statements?

"is not affected" being the operative wording. users want to know if their data has ever been at risk. still, surely everyone can just assume it was affected, act accordingly, and move on?

Except in this case, seeing as it seems that Mint hasn't got new ssl certs or private keys, the only way to 'act accordingly' is to never use the service again.

Re: Mint won't give a clear answer about Heartbleed

#10
The absence of a clear response indicates to me that the brass is currently weighing the pros and cons of admitting there was a problem. This is the sort of thing where those who really weren't affected get way out ahead of this sort of thing with vivid detail. I deleted my account.
Post reply on HN