# What the April 7 Web Security Vulnerability Meant for Websites and Passwords

DevFeed: [What the April 7 Web Security Vulnerability Meant for Websites and Passwords](<https://devfeed.tech/articles/what-you-need-to-know-about-april-7-and-your-security-on-the-web-41167.md>)

Original publisher: [Read original article](<https://www.craigkerstiens.com/2014/04/08/What-you-need-to-know-about-April-7-and-your-security-on-the-web./>)

Author: Map

Published: 2014-04-08T20:55:56Z

Content type: opinion

Language: en

Sources: [Craig Kerstiens](<https://devfeed.tech/sources/craig-kerstiens.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [technology](<https://devfeed.tech/tags/technology.md>), [web](<https://devfeed.tech/tags/web.md>)

## AI overview

The article explains a web security vulnerability that allowed external parties to acquire data from vulnerable websites, including recently logged-in Yahoo Mail usernames and passwords. It advises website operators to update affected sites and users to change passwords after confirming that sites are safe.

## Source excerpt

Yahoo Amazon.com Netflix Various banks Many more If you're interested in more technical details you can follow along or on the Heroku blog. The short of it is you, yes you as in everyone, should rotate your passwords once all websites are safe. For further details please continue reading. What does the vulnerability mean In this case it allowed an external party to acquire a moderate amount of data from some computer running your website. Extremely clear examples (such as shown on the right) highlight an example of random third parties easily acquiring most recently logged in Yahoo mail usernames and passwords. The first step The first step in resolving this is actually not a step required by you at all, unless you're running a production website online. The first step requires the developers running the site to update their site so they are no longer vulnerable. This as available to happen as early as April 7, and many major sites were fully updated and again safe as of April 8. Still area for concern With security vulnerabilities there are two key things to consider. First is the vulnerability itself, second is whether its therotical or can be simply acted upon. Yes, there's a range here. One of the most unfortunate pieces from talking to those that know about security is this was extremely trivial to act upon. This is made even worse in that this vulnerability has existed for 2 years without many knowing about it, meaning people have had an ability to snoop and collect parts of your data for two years What to do? First things first, be extremely cautious with any major website you connect with anything important. Any account that you have a password and you care about the account you should cease logging into it until you know its safe. As of the morning of April 8 here is a list of sites that were safe and ones that were vulnerable. You can check any site today here. Once it's clear that a site you know is now updated and safe either via that list of the latter