mark: A photo of Mark kneeling on top of the Taal Volcano in the Philippines. It was a long hike. (Default)
Mark Smith ([staff profile] mark) wrote in [site community profile] dw_maintenance2014-10-14 05:38 pm

Upgrading against the POODLE vulnerability

Hi all,

Today another SSL vulnerability was announced. This one is named POODLE and is, while serious, much less serious than the Heartbleed event from some months ago.

Unfortunately, the only real way to fix the problem is to disable something called "SSLv3" entirely. Basically, this means that we instruct our servers that they are no longer allowed to speak version 3 of the SSL protocol (you can think of it as a language -- we ban this language from our servers). It turns out this is generally OK since most browsers don't actually speak using SSLv3 these days -- you actually use what's called TLS, which is a more modern, better way of protecting the stuff you send across the Internet.

The SSLv3 protocol is actually around 15 years old at this point, and TLS has been out so long that nearly every browser out there supports it. However, shutting off SSLv3 does mean that very old browsers -- IE6, for one -- can no longer talk to Dreamwidth using encryption. In this case, since the encryption wouldn't actually mean anything, we think it's better to not even pretend that it works.

I will be making this change sometime in the next hour or three. This really should impact almost none of you, but there might be one or two and, in that case, I'm sorry. We think it's better to do this so you know you're not actually secure than to let Dreamwidth pretend to be secure.

Edit: This has been deployed. SSLv3 is disabled on Dreamwidth.

Comments and questions welcome, as always!

cmcmck: (Wile E Coyote)

[personal profile] cmcmck 2014-10-15 06:42 am (UTC)(link)
It's all Greek to me as I am but an humble historian, but thanks for letting us know! :o)
denise: Image: Me, facing away from camera, on top of the Castel Sant'Angelo in Rome (Default)

[staff profile] denise 2014-10-15 07:23 am (UTC)(link)

I love you, Mark.

sharpiefan: Sailor firing a cannon (Cannon firing)

[personal profile] sharpiefan 2014-10-15 09:39 am (UTC)(link)
Love your medieval DDoS attacks. I mean, your modern city-building. Er. Explanation.

Seriously, though, DW staff have a sense of humour and can and do explain things to the lay-person without them having to go hunting for it. That, right there, is why I love DW so very much. :D
archangelbeth: An egyptian-inspired eye, centered between feathered wings. (Default)

[personal profile] archangelbeth 2014-10-15 10:40 am (UTC)(link)
<3

[personal profile] swaldman 2014-10-15 12:09 pm (UTC)(link)
Hee. Love this explanation.
princessofgeeks: (Default)

[personal profile] princessofgeeks 2014-10-15 12:21 pm (UTC)(link)
CROSSBOWS!

Thanks so much for the explanation and everything else.
genarti: Knees-down view of woman on tiptoe next to bookshelves (Default)

[personal profile] genarti 2014-10-15 12:57 pm (UTC)(link)
This is such a great explanation, at least from my non-tech-expert perspective. I love it!

[personal profile] decepticon_mistress 2014-10-15 01:51 pm (UTC)(link)
LOL, best explanation ever!
the_shoshanna: "I believe in Dreamwidth" colored pencils (Dreamwidth pencils)

[personal profile] the_shoshanna 2014-10-15 02:17 pm (UTC)(link)
very, very large armies and starve them out -- medieval DDoS attacks

Drawn-out Denial Of Sustenance!
azurelunatic: Vivid pink Alaskan wild rose. (Default)

[personal profile] azurelunatic 2014-10-15 04:05 pm (UTC)(link)

(busts up giggling)

archangelbeth: An egyptian-inspired eye, centered between feathered wings. (Default)

[personal profile] archangelbeth 2014-10-16 12:54 am (UTC)(link)
Oh, nicely done!
ashkitty: (medieval milkshake)

[personal profile] ashkitty 2014-10-15 02:26 pm (UTC)(link)
...that was awesome, thank you. :)
wenchpixie: (Default)

[personal profile] wenchpixie 2014-10-15 05:01 pm (UTC)(link)
As someone who is both technical and ever so slightly obsessed with medieval siege weapons, I find this explanation to be utterly BRILLIANT and very entertaining. Thank you!
phoenixfire12: (Default)

[personal profile] phoenixfire12 2014-10-15 05:47 pm (UTC)(link)
Very entertaining, and to think I actually understood it. Thank you. BTW, I like crossbows. Have you progressed to or exceeded GATLING Crossbows?
Edited 2014-10-15 17:47 (UTC)
turlough: snickering white cat, Duchess from Disney's 'Aristocats' ((disney) fun)

[personal profile] turlough 2014-10-15 06:37 pm (UTC)(link)
Awesome and hilarious!

[personal profile] firstsuperman 2014-10-15 07:29 pm (UTC)(link)
That's actually a pretty good analogy to use so the laymen can grasp it.

Thanks for the hard work, and keeping Dreamwidth alive and kicking.

[personal profile] okami_no_mure 2014-10-15 08:13 pm (UTC)(link)
*Shriek of absolute joy!*

Mark has best analogy fu!
cmcmck: (Default)

[personal profile] cmcmck 2014-10-16 07:01 am (UTC)(link)
I was brought up in the shadow of a socking great Norman castle in the city of Rochester (probably to blame for my ending up doing history) which stood siege several times through all those developments, so this makes pretty good sense to me! :o)
Edited 2014-10-16 07:02 (UTC)