• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
  • X
  • Facebook
  • YouTube
  • LinkedIn
Support
Screen Connect
Pay Online
SWK logo.

SWK Technologies

Software Solutions & Services

  • Accounting & ERP Software
      • Acumatica Cloud ERP
        • Overview
        • Construction
        • Distribution
        • Field Service
        • Financial Management
        • Manufacturing
        • Professional Services
        • Project Accounting
        • Retail-Commerce
      • Sage Intacct
        • Overview
        • Construction and Real Estate (CRE)
        • Distribution Operations for Sage Intacct
        • Financial Services
        • Healthcare
        • Manufacturing Operations for Sage Intacct
        • Nonprofits
        • Professional Services
        • Sage Intacct Payroll powered by ADP
      • Sage 100
        • Overview
        • Business Intelligence
        • Core Accounting & Financials
        • Distribution
        • Manufacturing
        • Payroll
        • Sage 100 Contractor
      • More Accounting Products
        • QuickBooks
        • Sage 50
        • Sage 300
        • Sage 500
        • Sage BusinessWorks
      • ERP Add-ons
        • ADP Workforce Now
        • Altec
        • Avalara
        • AvidXchange
        • BigCommerce
        • CIMCloud
        • Cloud Hosting
        • DataSelf
        • Fortis
        • FreightPOP
        • Microsoft 365
        • Netstock
        • Ottimate
        • Sage Fixed Assets
        • Sage HRMS
        • Sage Intacct Payroll powered by ADP
        • Savant WMS
        • Scanco
        • ScanForce
        • Solver
        • SPS Commerce
        • Velixo
        • Workforce Go!
      • More ERP Add-ons
        • Bizinsight
        • Concur
        • Crystal Reports
        • Fraxion
        • Fusion RMS
        • FYISoft
        • JobOps
        • KnowledgeSync
        • Lockstep Collect
        • Nectari
        • Pacejet
        • Planning Maestro
        • Sage CRM
        • Sage Intelligence
        • Scissortail HCM
        • Service Pro
        • ShipStation
        • Shopify
        • Starship
        • Sugar CRM
        • Time & Billing Pro
        • Timekeeper
        • True Sky
      • Industries
        • Construction
        • Distribution
        • Financial Services
        • Healthcare
        • Manufacturing
        • Nonprofit
        • Professional Services
        • Retail
  • Managed Cloud Services
      • Managed Services
        • IT Support
        • Cloud Hosting
        • Infrastructure-as-a-Service
        • Managed Cloud Services
        • vCIO
        • Acumatica Infrastructure
      • IT Solutions
        • Backup & Continuity
        • Cybersecurity
        • Email Hosting
        • Microsoft 365 Services
        • Virtualization
  • Consulting & Implementation
    • Business Technology Consulting
    • eCommerce
    • Financing
    • Human Capital Management
    • Managed Cloud & IT Services
    • Partner Program
    • Software Development
    • Software Implementation
  • Resources
    • Help Desk
    • Blog Posts
    • Payments Portal
    • Webinars
    • YouTube Channels
    • Acumatica Resources
    • Sage Intacct Resources
    • Sage 100 Resources
    • IT Resource Pages
  • About
    • About SWK
    • Awards & Recognition
    • Life@SWK
    • Careers
    • Success Stories
    • SWK Gives
  • Contact
    • Contact Us
    • Support
    • Our Locations

The Clearest and Simplest Explanation of the Heartbleed Bug

April 10, 2014 by Marketing

Home » IT Services » The Clearest and Simplest Explanation of the Heartbleed Bug

heartbleed SWK Tech Business Continuity Backup and Disaster Recovery
What is Heartbleed and how does it affect your business? Get all the answers in this clear and simple explanation.

Have you heard about the newly discovered Heartbleed bug that has affected millions of sites across the entire Internet? At this point, the news is pretty widespread that on April 7, the world discovered a massive security problem that many Internet security researchers are saying is the top bug that has ever hit the Internet… but what IS it? If you’re looking for the real information about what Heartbleed is and how it affects your business, SWK’s Network and Computer Security Experts have the answers.

How much of the Internet does Heartbleed affect?

At least 17.5% of the Internet is affected by the Heartbleed bug, which is approximately about half a million sites. Want to check if a specific site is affected? Filippo Valsorda created an easy site checker in which you can enter in the web address you’re curious about, and see if it’s vulnerable. Go there right now and make sure your site doesn’t have any issues.

Where did the Heartbleed bug come from?

First off, it’s important to know that that the entire Internet is written in code. Code is responsible for absolutely everything you see on the Internet. Here’s what one single paragraph looks like on your screen (left) and in code (right).

Heartbleed page and source Network Services SWK Tech

When you look at the Internet code, you realize that it’s complex, and it’s clear how oversights could happen. In essence, Heartbleed is a bug that someone introduced to the code, either intentionally or unintentionally, that no one noticed until much, much later. The bug is a “missing bounds check” in the heartbeat extension of OpenSSL. (I’ll explain that sentence clearly, don’t worry.)

What is Open SSL?

Open SSL is a type of software that allows your computer to securely communicate with password-protected sites on the Internet, like Yahoo!, Amazon, or Google (all of which are now safe from the Heartbleed bug).

What is the heartbeat extension?

The heartbeat extension is a part of OpenSSL that allows you to go to different webpages on a secure, password-protected site without having to re-enter your password every time you click on a new page. Without the heartbeat extension, you’d have to re-enter your password every time you looked at a product page on Amazon…which would be greatly annoying.

What does “missing bounds check” mean?

It means that the person who wrote the buggy code for the heartbeat extension told the extension what it could do (allow you to click new pages without re-entering your password), but forgot to tell the extension what it couldn’t do (um, everything else).

Oops.

What does a “missing bounds check” do?

An imaginative hacker realized that if the heartbeat extension had no set limits, it could be exploited to steal tiny amounts of information out of protected websites. The information was stolen 64 kilobytes of information at a time, which really is a tiny amount. (For example, I’m currently writing this post in Word. At this exact point, my document is 284 kilobytes, including the screenshot of the code. That’s almost 4.5 times the amount of information the hacker could steal off a protected site at one time…and my document is exactly one page of text right now.)

Why is such a tiny amount of data such a big deal?

Because even though the hacker can only steal a 64 kilobytes at once, they can then go back and steal another 64 kilobytes, then another one, then another one. If someone were to come to your house every single minute and steal something small, it wouldn’t be too long before everything you owned was gone.

How long did the hacker have to steal this information?

Over two years. The bug was introduced on December 31, 2011, at exactly one hour before New Year’s.

What does Heartbleed mean for my business?

It means that you have to check your site to ensure that it’s safe, and you should probably reset all of your passwords on the Internet as well. The reason why you have to reset all of your passwords is because Heartbleed is completely untraceable; no one can tell you which of your usernames and passwords (if any) have been stolen.

To make sure that you’re safe:

Reset your login information and passwords on every site you go to

Enable Two-factor authentication where you can (That means that to get into a protected site, you’d have to enter your username and password, and then enter a randomly generated code that the system sends to your phone.) 

The most important thing you need to do right now is to make sure your site and business data are protected. If you’re worried, you can always contact the security experts at SWK Technologies, who will answer any questions you have honestly and clearly.

Contact Us Heartbleed

Category: IT ServicesTag: Backup and disaster recovery, Business Continuity, SWK Tech

Sidebar

Recent Posts

  • How a Recreational Play Structure Builder Laid the Groundwork for Their Lasting Growth
  • Why Financial Services Firms Need Phishing Defense
  • Acumatica General Ledger Training – Key Tips & Tricks
  • Sage Intacct vs. Sage 500: Best ERP for CFOs and Financial Leaders
  • What is the Relationship Between Cybersecurity and Cyber Insurance? 
  • Guide for Sage Intacct Credit Card Management
  • Minimize Tariff Impacts on Your Technology Costs in the Cloud

Categories

Ready to take the next step?

Contact SWK today to get in touch with one of our experts. We’ll go over your business challenges and unique needs, and see where you can unlock new value from your technology and make your operations run easier.

Get in touch!

Our Latest Posts

Recreational Play Structure

How a Recreational Play Structure Builder Laid the Groundwork for Their Lasting Growth

Read moreHow a Recreational Play Structure Builder Laid the Groundwork for Their Lasting Growth
Hands holding an open silver padlock over a laptop keyboard, symbolizing cybersecurity vulnerabilities that phishing attacks exploit in financial services firms

Why Financial Services Firms Need Phishing Defense

Read moreWhy Financial Services Firms Need Phishing Defense
Black laptop displaying Acumatica General Ledger journal transactions screen on a desk with coffee mug and notepad, showcasing the financial management interface on a computer in an office setting.

Acumatica General Ledger Training – Key Tips & Tricks

Read moreAcumatica General Ledger Training – Key Tips & Tricks

Awards and Accreditations

Top work places in NJ 2020.
Acumatica the Cloud ERP gold certified partner.
The Gold Microsoft partner logo on a black background.
Sage business partner diamond logo.
Dell Technologies Gold Partner
Sage tech partner logo.

Stay in the know!

Subscribe for exclusive ERP, process automation, IT and cybersecurity news.

Twitter
  • Facebook
  • YouTube
  • LinkedIn

Home
About
Contact

Support
Screen Connect
Pay Online
Downloads

SWK logo.

Headquarters:
120 Eagle Rock Ave, Suite 330
East Hanover, NJ 07936

Contact:
info@swktech.com
(877) 979-5462

Copyright © 2025 · SWK Technologies, Inc. · All Rights Reserved · Terms of Use · Privacy Policy

This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. By continuing to browse this site you agree to the use of cookies. Visit our privacy policy to learn more.I understand