Welcome to the Treehouse Community
Want to collaborate on code errors? Have bugs you need feedback on? Looking for an extra set of eyes on your latest project? Get support with fellow developers, designers, and programmers of all backgrounds and skill levels here with the Treehouse Community! While you're at it, check out some resources Treehouse students have shared here.
Looking to learn something new?
Treehouse offers a seven day free trial for new students. Get access to thousands of hours of content and join thousands of Treehouse students and alumni in the community today.
Start your free trial
Boon Kiat Seah
66,664 PointsHeartbleed Bug - What can a developer do about it
Hi moderators,
I was notified of a technical vulnerability in openssl that exists in ubuntu and apache that will allow backdoor access to all user ids and password without any back trace. This information was gotten from ifttt.com newsletter sent today.
The vulnerability was code named heartbleed bug.
More information can be found here regarding heart bleed bug:
As a starting and new php developer, i am using mamp and working on the mac. I believe my web application will also have this vulnerability.
Unfortunately, i find that it is too technical for me to understand what's this vulnerability is about. But i learnt from the website that as apache powered 66% of website online, we will be affected in someway.
As a php developer, what can i do about it to protect my web application and users?
Regards,
Boon Kiat
2 Answers
Howard Slatter
8,049 PointsI'm no expert, but the problem was patched before the story broke, maybe forcing users to change passwords regularly would be prudent as you can't predict these things.
I don't think you could have done anything about in your php, though I could be wrong.
James Barnett
39,199 PointsWhat can you do about it?
Whose job is it to install the OS, update the packages, setup webserver (and HTTPS certs), email (and IMAPS & SMTPS certs)?
If it's your responsibility, you probably need to call in some outside help in this case.
If not, talk to the people whose job that is.