AfterDawn: Tech news

Heartbleed fallout: If you signed up for Obamacare, it's time to change your password

Written by Andre Yoskowitz @ 20 Apr 2014 11:50 User comments (2)

Heartbleed fallout: If you signed up for Obamacare, it's time to change your password

Government officials have confirmed that the HealthCare.gov website is indeed vulnerable to the Heartbleed bug, and those that have signed up for Obamacare should change their passwords.
There was no indication that the site had been compromised, but officials still recommend changing the password to be safe. Other government sites may have been vulnerable, as well, but a full review is still ongoing, say the officials.

Heartbleed, which is a massive flaw in the OpenSSL website encryption technology used by a major portion of the Web, has been dominating headlines recently as major companies rush to patch their services and recommend to users that their passwords and other info be changed.

"While there's no indication that any personal information has ever been at risk, we have taken steps to address Heartbleed issues and reset consumers' passwords out of an abundance of caution," reads the website.

Phyllis Schneck, Department of Homeland Security deputy undersecretary for cybersecurity and communications also added: "We will continue to focus on this issue until government agencies have mitigated the vulnerability in their systems. And we will continue to adapt our response if we learn about additional issues created by the vulnerability."



Source:
Healthcare.gov

Previous Next  

2 user comments

123.4.2014 20:08

No OpenSSL on our network and I've changed my TurboTax password plus one other so I'm good.

I think Heartbleed is essentially used as a scare tactic. Haven't heard of any fallout with facts backing it.

224.4.2014 18:29

Originally posted by hearme0:
No OpenSSL on our network and I've changed my TurboTax password plus one other so I'm good.

Come on hearme, if the site wasn't infected and you changed your passwords then when it becomes infected they'll just use the new passwords. If it was infected, you have missed it, like shutting the gate after the horse is out...



Originally posted by hearme0:
I think Heartbleed is essentially used as a scare tactic. Haven't heard of any fallout with facts backing it.

That's called CYA (cover yo ass) if your infected and bitch at the site, they can always say you were warned... And Bad news travels very slowly. ROFL

Comments have been disabled for this article.

Latest news

GitHub Copilot to train its AI with users' prompts, code - here's how to opt out GitHub Copilot to train its AI with users' prompts, code - here's how to opt out (30 Mar 2026 3:49)
GitHub, the world's largest code repository for software development projects, owned by Microsoft, will start using user interactions to train its AI models.
Sony suspends memory card sales because memory chips are simply not available Sony suspends memory card sales because memory chips are simply not available (28 Mar 2026 6:49)
Sony has announced that it is temporarily suspending the sale of memory cards used in mobile phones and digital cameras, among other things. The company states that the reason is problems with the availability of memory chips.
Austria plans to ban social media for under 14 year olds Austria plans to ban social media for under 14 year olds (28 Mar 2026 6:17)
Austria is planning to ban social media for children under 14. The reform aims to protect children from harmful effects and addictions, but at the same time, it is problematic from a privacy perspective.
TP-Link urges users to update their routers - several vulnerabilities patched TP-Link urges users to update their routers - several vulnerabilities patched (26 Mar 2026 1:56)
Serious security vulnerabilities have been discovered in several TP-Link router models, for which patches were released at the end of March 2026. The company urges users to update their router software immediately.
Google: The feared Q-Day is now expected to happen in 2029 Google: The feared Q-Day is now expected to happen in 2029 (25 Mar 2026 4:32)
Google has advanced its estimate of when current forms of encryption will become insecure. The moment is called Q-Day, or Quantum Day, when the computational power of quantum computers will be sufficient to break currently used encryptions.

News archive