<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Please change your passwords for ruckuswireless.com websites in ZoneDirector</title>
    <link>https://community.ruckuswireless.com/t5/ZoneDirector/Please-change-your-passwords-for-ruckuswireless-com-websites/m-p/30898#M5871</link>
    <description>A major vulnerability, known as “Heartbleed,” has been disclosed for the technology that powers secure web (HTTPS/SSL) across the majority of the internet. That includes any of our servers which require a login, such as &lt;STRONG&gt;&lt;A href="https://support.ruckuswireless.com" rel="nofollow"&gt;https://support.ruckuswireless.com&lt;/A&gt; and &lt;A href="https://partners.ruckuswireless.com" rel="nofollow"&gt;https://partners.ruckuswireless.com&lt;/A&gt;&lt;/STRONG&gt;.
&lt;BR /&gt;&lt;BR /&gt;
We have patched all of our public web servers for the so-called "Heartbleed" SSL vulnerability (best explained here.. &lt;A href="http://xkcd.com/1354/" rel="nofollow"&gt;http://xkcd.com/1354/&lt;/A&gt; ) and we have also re-issued the certificates for those servers and so it is time to change your password.
&lt;BR /&gt;&lt;BR /&gt;
We have no knowledge of any compromise to our servers, and like most sites, took immediate steps to protect our servers and your information. However, this vulnerability is very difficult to detect. 
&lt;BR /&gt;&lt;BR /&gt;
[If you have an account created after midnight PDT 4/15/2014 or changed your password since then you do not need to change your password. &lt;STRONG&gt;Only &lt;A href="https://support.ruckuswireless.com" rel="nofollow"&gt;https://support.ruckuswireless.com&lt;/A&gt; and &lt;A href="https://partners.ruckuswireless.com" rel="nofollow"&gt;https://partners.ruckuswireless.com&lt;/A&gt; websites need their password changed&lt;/STRONG&gt;]
&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="https://support.ruckuswireless.com/forgot_password" rel="nofollow"&gt;Our Password Reset Tool&lt;/A&gt; requires that you have access to the email account which is associated to your account. If you no longer have that access, please email &lt;A href="mailto:cservice@ruckuswireless.com" rel="nofollow"&gt;cservice@ruckuswireless.com&lt;/A&gt; with details. Also check to make sure that email sourced from our domain is not blocked or spam-filtered.
&lt;BR /&gt;&lt;BR /&gt;
We apologize for the inconvenience! As you probably know, you will need to do this across all your &lt;STRONG&gt;affected&lt;/STRONG&gt; internet accounts &lt;STRONG&gt;after they are announced as patched and secured &lt;/STRONG&gt; so Ruckus strongly recommends you adopt the use of a password manager tool (including free/open source apps such as KeyPass) which can help you not only keep track of all the changes, but also help to generate strong passwords without the inconvenience of having to memorize them all).
&lt;BR /&gt;&lt;BR /&gt;
[amended; not all sites are impacted]</description>
    <pubDate>Tue, 15 Apr 2014 17:43:18 GMT</pubDate>
    <dc:creator>keith_redfield</dc:creator>
    <dc:date>2014-04-15T17:43:18Z</dc:date>
    <item>
      <title>Please change your passwords for ruckuswireless.com websites</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/Please-change-your-passwords-for-ruckuswireless-com-websites/m-p/30898#M5871</link>
      <description>A major vulnerability, known as “Heartbleed,” has been disclosed for the technology that powers secure web (HTTPS/SSL) across the majority of the internet. That includes any of our servers which require a login, such as &lt;STRONG&gt;&lt;A href="https://support.ruckuswireless.com" rel="nofollow"&gt;https://support.ruckuswireless.com&lt;/A&gt; and &lt;A href="https://partners.ruckuswireless.com" rel="nofollow"&gt;https://partners.ruckuswireless.com&lt;/A&gt;&lt;/STRONG&gt;.
&lt;BR /&gt;&lt;BR /&gt;
We have patched all of our public web servers for the so-called "Heartbleed" SSL vulnerability (best explained here.. &lt;A href="http://xkcd.com/1354/" rel="nofollow"&gt;http://xkcd.com/1354/&lt;/A&gt; ) and we have also re-issued the certificates for those servers and so it is time to change your password.
&lt;BR /&gt;&lt;BR /&gt;
We have no knowledge of any compromise to our servers, and like most sites, took immediate steps to protect our servers and your information. However, this vulnerability is very difficult to detect. 
&lt;BR /&gt;&lt;BR /&gt;
[If you have an account created after midnight PDT 4/15/2014 or changed your password since then you do not need to change your password. &lt;STRONG&gt;Only &lt;A href="https://support.ruckuswireless.com" rel="nofollow"&gt;https://support.ruckuswireless.com&lt;/A&gt; and &lt;A href="https://partners.ruckuswireless.com" rel="nofollow"&gt;https://partners.ruckuswireless.com&lt;/A&gt; websites need their password changed&lt;/STRONG&gt;]
&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="https://support.ruckuswireless.com/forgot_password" rel="nofollow"&gt;Our Password Reset Tool&lt;/A&gt; requires that you have access to the email account which is associated to your account. If you no longer have that access, please email &lt;A href="mailto:cservice@ruckuswireless.com" rel="nofollow"&gt;cservice@ruckuswireless.com&lt;/A&gt; with details. Also check to make sure that email sourced from our domain is not blocked or spam-filtered.
&lt;BR /&gt;&lt;BR /&gt;
We apologize for the inconvenience! As you probably know, you will need to do this across all your &lt;STRONG&gt;affected&lt;/STRONG&gt; internet accounts &lt;STRONG&gt;after they are announced as patched and secured &lt;/STRONG&gt; so Ruckus strongly recommends you adopt the use of a password manager tool (including free/open source apps such as KeyPass) which can help you not only keep track of all the changes, but also help to generate strong passwords without the inconvenience of having to memorize them all).
&lt;BR /&gt;&lt;BR /&gt;
[amended; not all sites are impacted]</description>
      <pubDate>Tue, 15 Apr 2014 17:43:18 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/Please-change-your-passwords-for-ruckuswireless-com-websites/m-p/30898#M5871</guid>
      <dc:creator>keith_redfield</dc:creator>
      <dc:date>2014-04-15T17:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: Please change your passwords for ruckuswireless.com websites</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/Please-change-your-passwords-for-ruckuswireless-com-websites/m-p/30899#M5872</link>
      <description>So your saying change password is "best practice" but no need to worry. Precautionary.
&lt;BR /&gt;
Done.
&lt;BR /&gt;
Thanks for info.
&lt;BR /&gt;&lt;BR /&gt;
Only site so far that has directly told me to do this so I take that as a positive (for Ruckus).</description>
      <pubDate>Wed, 16 Apr 2014 12:25:30 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/Please-change-your-passwords-for-ruckuswireless-com-websites/m-p/30899#M5872</guid>
      <dc:creator>max_o_driscoll</dc:creator>
      <dc:date>2014-04-16T12:25:30Z</dc:date>
    </item>
  </channel>
</rss>

