<node id="290131">
  <nid>290131</nid>
  <type>news</type>
  <uid>
    <user id="27299"><![CDATA[27299]]></user>
  </uid>
  <created>1397226266</created>
  <changed>1475896571</changed>
  <title><![CDATA[Tech’s Main Systems Not Compromised by Heartbleed]]></title>
  <body><![CDATA[<p>This week’s Heartbleed web security vulnerability had users of numerous popular websites scrambling to change passwords. Thankfully, none of Georgia Tech’s significant systems were affected.</p><p>“As soon as we became aware Monday, we did a scan of all our campus systems,” said Jimmy Lummis, cybersecurity policy and compliance manager in the <a href="http://www.oit.gatech.edu">Office of Information Technology</a>. The scan reported 120 unique IP addresses as being vulnerable. After five days of patching by OIT employees across campus, that number is now fewer than 30.</p><p>Because Tech’s main systems were not affected, most users do not need to worry about changing their Georgia Tech login passwords — with a few exceptions.</p><p>“Where I would be concerned is if users are using the same password for Georgia Tech as they are with other websites or systems,” Lummis said. He advised those users to change both passwords as a security measure.</p><p>“The other important thing to remember is that just because a site was vulnerable to Heartbleed, it doesn’t mean people got ahold of your information,” Lummis said. “All someone would get from exploiting Heartbleed would be a segment of memory stream for a particular process, which may or may not have any authentication information.” This differs from other types of security breaches in which large volumes of names, personal information, and credit card information are compromised.</p><p>OIT continues to run periodic scans to monitor systems as they are patched. Firewalls will block anything attempting to launch the Heartbleed vulnerability against any of Tech’s systems. For external sites, Lummis advised users to find out if the site has been patched before changing their passwords, or else they’ll have to be changed a second time.</p><p>Faculty and staff can also consider using <a href="http://lastpass.com">LastPass</a>, a password management tool for which <a href="http://oit.gatech.edu/lastpass-faq">they can get a license from OIT</a>. This tool was not vulnerable to Heartbleed, and in security breach situations it can notify users on which accounts passwords should changed.</p>]]></body>
  <field_subtitle>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_subtitle>
  <field_dateline>
    <item>
      <value>2014-04-11T00:00:00-04:00</value>
      <timezone><![CDATA[America/New_York]]></timezone>
    </item>
  </field_dateline>
  <field_summary_sentence>
    <item>
      <value><![CDATA[Most users do not need to worry about changing their GT login passwords — with a few exceptions]]></value>
    </item>
  </field_summary_sentence>
  <field_summary>
    <item>
      <value><![CDATA[<p>This week’s Heartbleed web security vulnerability had users of numerous popular websites scrambling to change passwords. Thankfully, none of Georgia Tech’s significant systems were affected.</p>&nbsp;]]></value>
    </item>
  </field_summary>
  <field_media>
          <item>
        <nid>
          <node id="290141">
            <nid>290141</nid>
            <type>image</type>
            <title><![CDATA[Heartbleed Bug]]></title>
            <body><![CDATA[]]></body>
                          <field_image>
                <item>
                  <fid>199210</fid>
                  <filename><![CDATA[p.txt_.png]]></filename>
                  <filepath><![CDATA[/sites/default/files/images/p.txt__0.png]]></filepath>
                  <file_full_path><![CDATA[http://hg.gatech.edu//sites/default/files/images/p.txt__0.png]]></file_full_path>
                  <filemime>image/png</filemime>
                  <image_740><![CDATA[]]></image_740>
                  <image_alt><![CDATA[Heartbleed Bug]]></image_alt>
                </item>
              </field_image>
            
                      </node>
        </nid>
      </item>
      </field_media>
  <field_contact_email>
    <item>
      <email><![CDATA[]]></email>
    </item>
  </field_contact_email>
  <field_location>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_location>
  <field_contact>
    <item>
      <value><![CDATA[<p><a href="mailto:kristen.bailey@comm.gatech.edu">Kristen Bailey</a><br />Institute Communications</p>]]></value>
    </item>
  </field_contact>
  <field_sidebar>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_sidebar>
  <field_boilerplate>
    <item>
      <nid><![CDATA[]]></nid>
    </item>
  </field_boilerplate>
  <!--  TO DO: correct to not conflate categories and news room topics  -->
  <!--  Disquisition: it's funny how I write these TODOs and then never
         revisit them. It's as though the act of writing the thing down frees me
         from the responsibility to actually solve the problem. But what can I
         say? There are more problems than there's time to solve.  -->
  <links_related> </links_related>
  <files> </files>
  <og_groups>
          <item>1214</item>
      </og_groups>
  <og_groups_both>
          <item>
        <![CDATA[Institute and Campus]]>
      </item>
      </og_groups_both>
  <field_categories>
          <item>
        <tid>129</tid>
        <value><![CDATA[Institute and Campus]]></value>
      </item>
      </field_categories>
  <core_research_areas>
      </core_research_areas>
  <field_news_room_topics>
          <item>
        <tid>71871</tid>
        <value><![CDATA[Campus and Community]]></value>
      </item>
      </field_news_room_topics>
  <links_related>
          <link>
      <url>http://heartbleed.com/</url>
      <title></title>
      </link>
          <link>
      <url>http://blog.lastpass.com/2014/04/lastpass-and-heartbleed-bug.html</url>
      <title></title>
      </link>
          <link>
      <url>http://oit.gatech.edu/directorate/information-security</url>
      <title></title>
      </link>
      </links_related>
  <files>
      </files>
  <og_groups>
          <item>1214</item>
      </og_groups>
  <og_groups_both>
          <item><![CDATA[News Room]]></item>
      </og_groups_both>
  <field_keywords>
          <item>
        <tid>91421</tid>
        <value><![CDATA[heartbleed]]></value>
      </item>
          <item>
        <tid>2678</tid>
        <value><![CDATA[information security]]></value>
      </item>
          <item>
        <tid>4112</tid>
        <value><![CDATA[oit]]></value>
      </item>
          <item>
        <tid>91431</tid>
        <value><![CDATA[password]]></value>
      </item>
      </field_keywords>
  <field_userdata><![CDATA[]]></field_userdata>
</node>
