It keeps happening. A newly discovered software bug–this one going by the ominous name Heartbleed–allows hackers to bypass the encryption technology used on many websites to access passwords, credit-card numbers and other sensitive data. By one estimate, as much as 66% of the web is affected, including Yahoo and the popular dating site OkCupid.
Companies are scrambling to close off the security flaw in the widely used encryption technology, called OpenSSL, but since the coding error went unnoticed for two years, there’s no telling how much information hackers have stolen. Users are advised to change their passwords–but only after confirming that an affected website is no longer susceptible.
Heartbleed is the latest and farthest-reaching cybersecurity scare in a spate of them affecting everything from cell phones to brick-and-mortar stores like Target. Experts say data will get only more difficult to secure. “There are no secrets on the Internet,” says Ari Takanen, founder of Codenomicon, the security firm that discovered Heartbleed. “Something bad can always happen.”
–VICTOR LUCKERSON
More Must-Reads from TIME
- Why Biden Dropped Out
- Ukraine’s Plan to Survive Trump
- The Rise of a New Kind of Parenting Guru
- The Chaos and Commotion of the RNC in Photos
- Why We All Have a Stake in Twisters’ Success
- 8 Eating Habits That Actually Improve Your Sleep
- Welcome to the Noah Lyles Olympics
- Get Our Paris Olympics Newsletter in Your Inbox
Contact us at letters@time.com