Attend XDA's Second Annual Developer Conference, XDA:DevCon 2014!
5,734,299 Members 48,771 Now Online
XDA Developers Android and Mobile Development Forum

Heartbleed an issue for our GS3?

Tip us?
 
DurhamHusker
Old
(Last edited by DurhamHusker; 10th April 2014 at 03:29 AM.)
#1  
DurhamHusker's Avatar
Senior Member - OP
Thanks Meter 112
Posts: 242
Join Date: Nov 2010
Location: Kansas City
Default Heartbleed an issue for our GS3?

;So ... at the behest of some of the "security experts" I downloaded the Bluebox Heartbleed Scanner from the Play Store and got the following interesting results.

I'm running a TW ROM based on Samsung's Android 4.3 release. I was under the impression that only Android 4.1 was affected. So should we be worried?

 
DurhamHusker
Old
#2  
DurhamHusker's Avatar
Senior Member - OP
Thanks Meter 112
Posts: 242
Join Date: Nov 2010
Location: Kansas City
I emailed the developers of the scanner app and here is their response concerning our GS3 on Android 4.3:

--

The version of OpenSSL is within the affected range but the heartbeats feature has been disabled, leaving you safe. *It turned out the version number isn't enough to confirm vulnerability.

We are working on a scanner update that will test whether the OpenSSL library has the heartbeat feature enabled/disabled rather than relying on the version number alone. That should fix the confusion you are seeing. *Stay tuned.

Thanks for the feedback!

- Jeff
 
rudolfm
Old
(Last edited by rudolfm; 11th April 2014 at 08:44 PM.)
#3  
Junior Member
Thanks Meter 0
Posts: 3
Join Date: Apr 2014
It would have said "this version ... is vulnerable, but heartbeats are disabled so you're safe" if things were OK.
It says so on my phone.
Maybe you should giveit another try with the curren version, I have 1.2.1 from playstore.
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes