Sluggishness saves government websites from Heartbleed

ICERT had issued an advisory warning internet user about the bug and its solution

pragya

Praggya Guptaa | April 18, 2014



Believe it or not, government websites in India are less vulnerable to 'Heartbleed' bug. No, not because these websites have world’s best internet security protocols but because of the sluggish approach of government departments in the country. Yes, you read it right: sluggishness.

The Heartbleed bug exploits a flaw in the OpenSSL cryptographic software library. The vulnerability exposes sensitive information such as passwords, credit card numbers and other information to hackers by attacking the security certificates (SSL) of websites designed to protect online accounts for email, instant messaging and e-commerce.

According to experts, the bug has majorly attacked the sites that have updated their certificates. However, most of the Indian government sites are sluggish in updating their certificates, and therefore, the risk of getting affected is comparatively low. The two-year old bug has entered the system while updating these SSL certificates. “Generally government gives contract to vendors and they are less bothered about updating them,” said a security testing expert on the condition of anonymity.

It may be recalled that the Canadian revenue department had recently suspended its e-services for few days after being affected by the bug. The agency had reported that private information of about 900 people had been compromised as hackers exploited the Heartbleed bug. However, according to Indian Computer Emergency Response Team of India (ICERT) no such case has been reported so far in India.

ICERT had also issued an advisory warning internet user about the bug and its solution. “We have also written to large users and other organisations about the steps to be followed to mitigate the risk," said Gulshan Rai, director deneral, ICERT, to Governance Now.

According to some security experts, majority of the agencies and service providers might have already replaced the security certificates after the panic situation. Many experts and agencies are also advising internet users to change their passwords. ICERT’s advisory has also advised service provider to replace the certificate after moving to a fixed version of OpenSSL. It also advises users to change all sensitive credentials like usernames and passwords.

According to eScan MD and CEO Govind Rammurthy, “Since majority of websites are vulnerable to the Heartbleed bug mere changing a password will not help. Website would have to replace their OpenSSL software first in order to mitigate the threat.”

Commenting on the risks, Ajay Dubey, manager-south India, Websense, said, “Due to the nature of this bug data theft is of larger concern. We don’t know which all sites are compromised and what all data are with the hackers. Therefore, it is advisable that after replacing SSL certificate of sites, username and password must be changed.”

Comments

 

Other News

Doctors, experts call for ban on junk food ads, mandate warning labels

More than 30 doctors, medical scientists and public health professionals have urged the government to take decisive action against the aggressive advertising and marketing of junk food, calling for a watershed ban on advertisements for foods high in fat, sugar and salt (HFSS) and ultra-processed foods (UPF

Asiatic Lion population rises from 523 in 2015 to 891 in 2025

On World Lion Day 2026, environment, forest and climate change Minister  Bhupender Yadav celebrated India’s remarkable journey in lion conservation and reaffirmed the country’s unwavering commitment to protecting wildlife and biodiversity.   In a post on soc

Railways imposed ₹5.13 crore fine for food quality and hygiene violations

Indian Railways serve about 58 crore meals every year on an average. About only 0.0008% food quality related complaints are received on average. Based on complaints during the last three years, appropriate penal actions have been taken by IRCTC. Such actions include imposition of fines amounting to ₹5.13

STHAVAR: Why every Indian built asset needs a permanent digital identity

India has built digital systems for identity, payments, taxation, documents, logistics and public services. State governments, ministries, infrastructure agencies and urban local bodies have also created portals for land records, building permissions, project monitoring, property taxation and municipal s

Saksham Skill census identifies 22,000 job-ready candidates in one Mumbai ward

A first-of-its-kind AI-enabled skill census conducted in Mumbai`s H-West Ward has identified a potential livelihood pipeline of nearly 22,000 candidates, generated over 32,000 provisional job matches while revealing that 71.2 per cent of surveyed homemakers are willing to join the workforce, according to

GI tags: Scaling traditional wealth into global brands

Geographical Indication (GI) tags have emerged as a powerful tool for protecting India`s cultural heritage, while creating economic opportunities for local communities. By linking products to their place of origin, GI tags preserve traditional knowledge, prevent misuse, and enhance consumer trust. They h

Upcoming Conferences



-->

Archives

Current Issue

Opinion

Facebook Twitter Google Plus Linkedin Subscribe Newsletter

Twitter