DFO On-Line Licences Potential Major Security Issue

Whole in the Water

Well-Known Member
Hopefully, not too many of us will fall victim of the Heartbleed worldwide internet security crisis and got hacked when we bought our licences online. Hopefully, they can fix this ASAP. In the meantime everyone should seriously consider changing all their passwords - not much else one can do at this time.

Fishery Notice - Fisheries and Oceans Canada
Subject: FN0303-Licensing Information - The National Online Licensing System (NOLS) and the National Recreational Licensing System (NRLS) temporary outage

Fisheries and Oceans Canada is committed to protecting the confidentiality of our clients’ personal information on DFO online applications. The vulnerability known as “Heartbleed” impacts recent versions of OpenSSL, a commonly used software by websites to encrypt and secure data being transmitted across the Internet. The Department acted promptly upon learning about the security issues associated with the Heartbleed Bug. Departmental systems using the affected application have been identified and the necessary steps have been taken to ensure their security.

The National Online Licensing System and the National Recreational Licensing System were not compromised by the Heartbleed Bug and remain fully secure. However, as a precaution, both have been temporarily disabled. To further minimize the risks related to this bug, clients using DFO applications may be prompted to change their passwords in the coming days.

As part of Canada’s Cyber Security Strategy, the Government of Canada launched “Get Cyber Safe,” a national public awareness campaign created to educate Canadians about Internet security and the simple steps they can take to protect themselves online. To learn more about how to stay safe online, visit www.getcybersafe.ca

The licensing systems will be available again at 9:00am on Saturday, April 12,2014. If you are still having trouble accessing the National Recreational Licensing System at that time, please visit an Independent Access Provider for a Tidal Water Sport Fishing licence. A list of current service locations may be found at http://www.pac.dfo-mpo.gc.ca/fm-gp/rec/licence-permis/IAP-FAI-eng.pdf.Please be sure to contact the applicable Independent Access Provider prior to arriving to verify business hours and licence availability.
 
EPIC FAIL. I was getting ready to go down to the cabin fishing for the weekend. Bags packed, food purchased. Go online to get licenses, and met by this. I already paid for one licence earlier, but it would not print. So thinking I would try again when I got my wife's license was the plan...and now this.

What on earth is going to happen when 200,000 tourists come here looking to get a licence the day before their trip! What a CLUSTER.

Beyond pissed off.
 
A friend just got her license online an hour ago, all was good, no problems.

She still got a balance in her bank account???? Cause that's what heartbleed does-it is not a virus it is a hole in the security -I got a warning from mcAffee that they cannot protect from it.
 
She still got a balance in her bank account???? Cause that's what heartbleed does-it is not a virus it is a hole in the security -I got a warning from mcAffee that they cannot protect from it.

Yes, her balance is fine.

You can't blame the folks there at the Fed Gov for shutting the site down and patching their SSL software. Imagine the **** that would have flown if they didn't and peoples userID's and passwords were stolen, or worse.
 
I read it was shut down to fix the loophole last night and is supposed to be fixed as of this morning


They shut down to check things out but they do not use that brand of ssl.
here is what the ssl check software says

LastPass Heartbleed checker




Site:www-ops2.pac.dfo-mpo.gc.ca
Server software:Microsoft-IIS/7.5
Was vulnerable:No (does not use OpenSSL)
SSL Certificate:Safe (regenerated 1 year ago)
Assessment:This server was not vulnerable, no need to change your password unless you have used it on any other site!

<tbody>
</tbody>
 
Last edited by a moderator:
Yep,same here. I have a "pay as you go" Visa specifically for online purchases.When I find something online I want,I just put enough money on the card to cover the item,shipping,U.S. exchange,and that's it! You can't get blood out of stone
so they say.
 
Our bank gave us an extra credit card with a small limit on it for online purchases.
If we want to buy something bigger, they will increase the limit for 24 hours.
If the online card trips up the bank security and gets shut down, it does not affect our regular card.
 
Got a "gift card" from RBC for $3.95 charge, and used that today.
Got a 8x11 piece of paper with my salmon stamp, painful for me!
Will write my MP shortly and complain, want the old way back!
 
Yep,same here. I have a "pay as you go" Visa specifically for online purchases.When I find something online I want,I just put enough money on the card to cover the item,shipping,U.S. exchange,and that's it! You can't get blood out of stone
so they say.

That is a really good idea. Thanks for posting.
 
its just a security flaw, its not a virus or anything that is actively attacking computers. Its simply a hole that a would be hacker could exploit, its highly unlikely they're targeting DFO - just change your passwords and you'll be fine.
 
That is a really good idea. Thanks for posting.
Got mine from Money Mart.It's called a Titanium Visa.Cost $20.00.Use it all the time.In fact I just finished putting $60.00
on it for some something I found on line today.Amazing how much cheaper stuff is online sometimes,especially in the
U.S.!
 
Back
Top