StarTekh
Max Output Level: -55 dBFS
- Total Posts : 2007
- Joined: 2004/03/09 12:02:20
- Location: Montreal
- Status: offline
Heartbleed Bug !
Is there a issue with my Cakewalk account password
|
Kalle Rantaaho
Max Output Level: -5 dBFS
- Total Posts : 7005
- Joined: 2006/01/09 13:07:59
- Location: Finland
- Status: offline
Re: Heartbleed Bug !
2014/04/09 13:05:37
(permalink)
Hmmmm...how could we know?
SONAR PE 8.5.3, Asus P5B, 2,4 Ghz Dual Core, 4 Gb RAM, GF 7300, EMU 1820, Bluetube Pre - Kontakt4, Ozone, Addictive Drums, PSP Mixpack2, Melda Creative Pack, Melodyne Plugin etc. The benefit of being a middle aged amateur is the low number of years of frustration ahead of you.
|
KPerry
Max Output Level: -44 dBFS
- Total Posts : 3120
- Joined: 2011/04/26 15:13:15
- Location: London, UK
- Status: offline
Re: Heartbleed Bug !
2014/04/09 13:20:17
(permalink)
Unlikely as the CW site uses .NET, which is almost certainly hosted on a Windows IIS server, which is not affected by the OpenSSL bug.
|
Splat
Max Output Level: 0 dBFS
- Total Posts : 8672
- Joined: 2010/12/29 15:28:29
- Location: Mars.
- Status: offline
Re: Heartbleed Bug !
2014/04/09 14:46:34
(permalink)
Well as we don't exactly know what your issue is... Who knows...
Sell by date at 9000 posts. Do not feed. @48/24 & 128 buffers latency is 367 with offset of 38. Sonar Platinum(64 bit),Win 8.1(64 bit),Saffire Pro 40(Firewire),Mix Control = 3.4,Firewire=VIA,Dell Studio XPS 8100(Intel Core i7 CPU 2.93 Ghz/16 Gb),4 x Seagate ST31500341AS (mirrored),GeForce GTX 460,Yamaha DGX-505 keyboard,Roland A-300PRO,Roland SPD-30 V2,FD-8,Triggera Krigg,Shure SM7B,Yamaha HS5.Maschine Studio+Komplete 9 Ultimate+Kontrol Z1.Addictive Keys,Izotope Nectar elements,Overloud Bundle,Geist.Acronis True Image 2014.
|
StarTekh
Max Output Level: -55 dBFS
- Total Posts : 2007
- Joined: 2004/03/09 12:02:20
- Location: Montreal
- Status: offline
Re: Heartbleed Bug !
2014/04/09 15:20:15
(permalink)
KPerry : thanks ! Kalle manualy update your os , reseting email pass words is suggested , Alex start reading ! :)
|
wetdentist
Max Output Level: -68 dBFS
- Total Posts : 1129
- Joined: 2007/04/12 19:06:25
- Location: Bethlehem, PA USA
- Status: offline
Re: Heartbleed Bug !
2014/04/09 15:38:21
(permalink)
i'm changing all my passwords everywhere
3.5 Ghz AMD 6-Core/16 gigs RAM, Roland Quad-Capture, Win 10, Cakewalk by Bandlab, Komplete 10, z3ta+, Z3TA+ 2, Rapture, Maschine 2.7 (MKI & Jam), Melodyne 4 Studio, Ozone 4, Jam Origin MIDI Guitar 2, Schecter Damien Elite, Fender Sonoran w/TronicalTune Plus installed, etc go here to hear Wet Dentist (2000-2016 RIP) my new sounds: The Das Kaput
|
Kalle Rantaaho
Max Output Level: -5 dBFS
- Total Posts : 7005
- Joined: 2006/01/09 13:07:59
- Location: Finland
- Status: offline
Re: Heartbleed Bug !
2014/04/09 15:45:01
(permalink)
Does this thread have a point?
SONAR PE 8.5.3, Asus P5B, 2,4 Ghz Dual Core, 4 Gb RAM, GF 7300, EMU 1820, Bluetube Pre - Kontakt4, Ozone, Addictive Drums, PSP Mixpack2, Melda Creative Pack, Melodyne Plugin etc. The benefit of being a middle aged amateur is the low number of years of frustration ahead of you.
|
Kalle Rantaaho
Max Output Level: -5 dBFS
- Total Posts : 7005
- Joined: 2006/01/09 13:07:59
- Location: Finland
- Status: offline
Re: Heartbleed Bug !
2014/04/09 15:45:02
(permalink)
Does this thread have a point?
SONAR PE 8.5.3, Asus P5B, 2,4 Ghz Dual Core, 4 Gb RAM, GF 7300, EMU 1820, Bluetube Pre - Kontakt4, Ozone, Addictive Drums, PSP Mixpack2, Melda Creative Pack, Melodyne Plugin etc. The benefit of being a middle aged amateur is the low number of years of frustration ahead of you.
|
DumbKidFromHell
Max Output Level: -79 dBFS
- Total Posts : 598
- Joined: 2005/06/09 22:22:51
- Status: offline
Re: Heartbleed Bug !
2014/04/09 16:02:23
(permalink)
Now that I've posted, this thread has even less than a point...
|
Cactus Music
Max Output Level: 0 dBFS
- Total Posts : 8424
- Joined: 2004/02/09 21:34:04
- Status: offline
Re: Heartbleed Bug !
2014/04/09 16:34:08
(permalink)
Government E mail address book hi-jacked? Well I get at least 1 scam a day in my telus inbox, most likely because my address is public on my web site. I was about to mark this one as spam but out of curiosity I right clicked the sender and saw that it actually came from Revenue Canada? I double checked and this was accurate. It told me I have a extra refund coming and to click the link to claim my " 733,17$. " - notice the comma and the dollar sign placement. The provided link is obviously a phishing site, Google Chrome confirmed this when I clicked the link. So it would seem that someone has managed to hijack the Revenue Canada's e mail address book, I'm on file and this is the e mail address I used for E file. So I figured I should report this as it might even be a national security issue, right? I Googled "reporting fraud" and the top of the list was RCMP. But their web site claimed they don't want to hear from me unless I'm an actual victim. I guess I'm not. So there is a link to the Government "Anti Fraud Agency" , looking good. They have a list of currant fraud scams but I didn't see this one. I clicked the report fraud link thinking this was the way to pass on what might be important info. I have to log on? ! I had to fill in a page and a half of personal info? OK I'm game. I finally get to a page to report the fraud and it looks amazingly like the unEmployment Insurance claim reporting site! Cool. But it was page after page of stupid questions and none of the choices matched my issue. I gave up after 12 minutes. But when I returned to my in box I had a email from an IT friend warning about the Heartbleed bug. So I guess they already were aware they have been hacked big time. This will be an interesting development. I think the OP was just joking.. if you read the link you'll see how not all secure site software is compromised, only 2/3 of the sites. http://news.ca.msn.com/top-stories/heartbleed-web-security-bug-what-you-need-to-know
|
Cactus Music
Max Output Level: 0 dBFS
- Total Posts : 8424
- Joined: 2004/02/09 21:34:04
- Status: offline
Re: Heartbleed Bug !
2014/04/09 16:38:40
(permalink)
For those to lazy to follow my link this is the important part: " Takanen, chief technology officer for Codenomicon, advises you to wait for an official statement from the internet services you use (indicating that they have fixed the bug) and follow their guidelines. Typically, that will involve things like changing your password. That is something you may have to do across many —services you use. However, steps like that are useless until the security hole has been fixed for the affected services. "Changing before the service is patched could expose the new password," said a spokesperson for Google, who also noted that passwords do not need to be changed for Google services because of its early implementation of a bug fix. In the meantime, a number of sites have have been set up where you can check if the web services you're using are vulnerable, including this one, set up by Italian security researcher FilippoValsorda. You might want to stay away from sites identified as "vulnerable" for now. Security experts also recommend as a general rule that you use strong passwords that are different for different internet services and that you change them regularly.
|
Splat
Max Output Level: 0 dBFS
- Total Posts : 8672
- Joined: 2010/12/29 15:28:29
- Location: Mars.
- Status: offline
Re: Heartbleed Bug !
2014/04/09 18:35:18
(permalink)
StarTekh KPerry : thanks ! Kalle manualy update your os , reseting email pass words is suggested , Alex start reading ! :)
I was fully aware of an openSSL vunerabilty that does not effect IIS, however I didn't understand why the global media (which I have since found out why) has reffered this as a 'heartbeat bug'. I couldn't be bothered to look into the details until now (another day another vulnerability so what's new). BTW the media is wrong, this is not a bug it is a flaw. So KPerry is right, this is an IIS platform here (MS implementation) so should not be effected (at least for now). So I agree, I should read more. But there is no actual issue here (apart from the CIA) as Cake use MS products. So move on nothing to see.
post edited by CakeAlexS - 2014/04/09 18:48:42
Sell by date at 9000 posts. Do not feed. @48/24 & 128 buffers latency is 367 with offset of 38. Sonar Platinum(64 bit),Win 8.1(64 bit),Saffire Pro 40(Firewire),Mix Control = 3.4,Firewire=VIA,Dell Studio XPS 8100(Intel Core i7 CPU 2.93 Ghz/16 Gb),4 x Seagate ST31500341AS (mirrored),GeForce GTX 460,Yamaha DGX-505 keyboard,Roland A-300PRO,Roland SPD-30 V2,FD-8,Triggera Krigg,Shure SM7B,Yamaha HS5.Maschine Studio+Komplete 9 Ultimate+Kontrol Z1.Addictive Keys,Izotope Nectar elements,Overloud Bundle,Geist.Acronis True Image 2014.
|
StarTekh
Max Output Level: -55 dBFS
- Total Posts : 2007
- Joined: 2004/03/09 12:02:20
- Location: Montreal
- Status: offline
Re: Heartbleed Bug !
2014/04/09 18:57:32
(permalink)
|
Splat
Max Output Level: 0 dBFS
- Total Posts : 8672
- Joined: 2010/12/29 15:28:29
- Location: Mars.
- Status: offline
Re: Heartbleed Bug !
2014/04/09 19:02:53
(permalink)
Shorter version... The post is about OpenSSL. Cake does not use OpenSSL (they use IIS SSL) as far as I can see. So no problem here.
Sell by date at 9000 posts. Do not feed. @48/24 & 128 buffers latency is 367 with offset of 38. Sonar Platinum(64 bit),Win 8.1(64 bit),Saffire Pro 40(Firewire),Mix Control = 3.4,Firewire=VIA,Dell Studio XPS 8100(Intel Core i7 CPU 2.93 Ghz/16 Gb),4 x Seagate ST31500341AS (mirrored),GeForce GTX 460,Yamaha DGX-505 keyboard,Roland A-300PRO,Roland SPD-30 V2,FD-8,Triggera Krigg,Shure SM7B,Yamaha HS5.Maschine Studio+Komplete 9 Ultimate+Kontrol Z1.Addictive Keys,Izotope Nectar elements,Overloud Bundle,Geist.Acronis True Image 2014.
|
Re: Heartbleed Bug !
2014/04/09 20:35:15
(permalink)
Hi Everyone, None of our public facing sites are affected - however for your own security don't make the blanket assumption that because a site uses .NET or a Microsoft stack that they're not vulnerable. Lots of load balancers in front of windows servers use openSSL.
|
Kalle Rantaaho
Max Output Level: -5 dBFS
- Total Posts : 7005
- Joined: 2006/01/09 13:07:59
- Location: Finland
- Status: offline
Re: Heartbleed Bug !
2014/04/10 13:05:51
(permalink)
Ok. Now I'm embarrassed. A Finnish company had a major role in finding one of the biggest flaws in the history of internet and I did not know about it:o)
SONAR PE 8.5.3, Asus P5B, 2,4 Ghz Dual Core, 4 Gb RAM, GF 7300, EMU 1820, Bluetube Pre - Kontakt4, Ozone, Addictive Drums, PSP Mixpack2, Melda Creative Pack, Melodyne Plugin etc. The benefit of being a middle aged amateur is the low number of years of frustration ahead of you.
|
joden
Max Output Level: -65 dBFS
- Total Posts : 1263
- Joined: 2007/09/22 17:03:46
- Status: offline
Re: Heartbleed Bug !
2014/04/10 13:59:38
(permalink)
However if any cake users also use a Casio, and use the Casio forums - THEY have a heartbleed vulnerability!
|
Splat
Max Output Level: 0 dBFS
- Total Posts : 8672
- Joined: 2010/12/29 15:28:29
- Location: Mars.
- Status: offline
Re: Heartbleed Bug !
2014/04/10 14:13:24
(permalink)
Kalle Rantaaho Ok. Now I'm embarrassed. A Finnish company had a major role in finding one of the biggest flaws in the history of internet and I did not know about it:o)
I wouldn't be .... It just has received a lot of publicity this time, good advice mostly about changing passwords (the CIA will need to update their password database as well  )... Check the number of issues found here: http://www.openssl.org/news/vulnerabilities.html
Sell by date at 9000 posts. Do not feed. @48/24 & 128 buffers latency is 367 with offset of 38. Sonar Platinum(64 bit),Win 8.1(64 bit),Saffire Pro 40(Firewire),Mix Control = 3.4,Firewire=VIA,Dell Studio XPS 8100(Intel Core i7 CPU 2.93 Ghz/16 Gb),4 x Seagate ST31500341AS (mirrored),GeForce GTX 460,Yamaha DGX-505 keyboard,Roland A-300PRO,Roland SPD-30 V2,FD-8,Triggera Krigg,Shure SM7B,Yamaha HS5.Maschine Studio+Komplete 9 Ultimate+Kontrol Z1.Addictive Keys,Izotope Nectar elements,Overloud Bundle,Geist.Acronis True Image 2014.
|
StarTekh
Max Output Level: -55 dBFS
- Total Posts : 2007
- Joined: 2004/03/09 12:02:20
- Location: Montreal
- Status: offline
Re: Heartbleed Bug !
2014/04/10 14:56:37
(permalink)
Willy Jones : Thank You .. This is what I wanted to hear from Cakewalk !
|
slartabartfast
Max Output Level: -22.5 dBFS
- Total Posts : 5289
- Joined: 2005/10/30 01:38:34
- Status: offline
Re: Heartbleed Bug !
2014/04/12 18:20:16
(permalink)
You can check some sites to see if the exploit has been fixed by using online tools: Heartbleed test, LastPass Heartbleed checker, or the Qualys SSL Labs I would not hold my breath to hear from sites that might have been vulnerable announcing that they have a fix or advising you to change your password. These commercial sites and the server farms that house them depend on users believing that they can protect your data and assets, even though history has proven on many occasions that they cannot. In order to tell you that the problem has been fixed, they have to acknowledge that the vulnerability existed on their servers for some time. And advising you to change your password on the on the improbable chance that it has been compromised will cost them dearly in customer confidence. Many sites will no doubt listen to marketing and ignore engineering advice and just hope no one notices. That is the kind of decision that we expect when applying the oxymoron that is business ethics. Cakewalk has at least been forthcoming in stating that their user directed sites are not affected. Let us hope that other companies who were affected will be so honest.
|