It keeps happening. A newly discovered software bug–this one going by the ominous name Heartbleed–allows hackers to bypass the encryption technology used on many websites to access passwords, credit-card numbers and other sensitive data. By one estimate, as much as 66% of the web is affected, including Yahoo and the popular dating site OkCupid.
Companies are scrambling to close off the security flaw in the widely used encryption technology, called OpenSSL, but since the coding error went unnoticed for two years, there’s no telling how much information hackers have stolen. Users are advised to change their passwords–but only after confirming that an affected website is no longer susceptible.
Heartbleed is the latest and farthest-reaching cybersecurity scare in a spate of them affecting everything from cell phones to brick-and-mortar stores like Target. Experts say data will get only more difficult to secure. “There are no secrets on the Internet,” says Ari Takanen, founder of Codenomicon, the security firm that discovered Heartbleed. “Something bad can always happen.”
–VICTOR LUCKERSON
More Must-Reads from TIME
- Why Trump’s Message Worked on Latino Men
- What Trump’s Win Could Mean for Housing
- The 100 Must-Read Books of 2024
- Sleep Doctors Share the 1 Tip That’s Changed Their Lives
- Column: Let’s Bring Back Romance
- What It’s Like to Have Long COVID As a Kid
- FX’s Say Nothing Is the Must-Watch Political Thriller of 2024
- Merle Bombardieri Is Helping People Make the Baby Decision
Contact us at letters@time.com