No way for average user to know which websites contain software flaw: Experts

Advertisement

Advertise with us

CALGARY - Experts say Canadians should use good "cyber hygiene" in light of the discovery of a massive software flaw that has resulted in the precautionary shutdown of thousands of websites.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 13/12/2021 (1737 days ago), so information in it may no longer be current.

CALGARY – Experts say Canadians should use good “cyber hygiene” in light of the discovery of a massive software flaw that has resulted in the precautionary shutdown of thousands of websites.

The federal government, the government of Quebec and the Canada Revenue Agency are among the organizations that temporarily suspended websites as a precaution after the Canadian Centre for Cyber Security issued an alert Dec. 10 about the recently discovered software vulnerability in a Java-based library of an Apache product known as Log4j.

Experts describe the software flaw as akin to “leaving the back door open” in that it could give cyber criminals access to the thousands of organizations that use the open-source logging library.

A woman uses her computer keyboard to type while surfing the internet in North Vancouver, B.C., on December 19, 2012. Experts say Canadians should be extra careful online in light of a massive software flaw that has resulted in the precautionary shutdown of thousands of websites. THE CANADIAN PRESS/Jonathan Hayward
A woman uses her computer keyboard to type while surfing the internet in North Vancouver, B.C., on December 19, 2012. Experts say Canadians should be extra careful online in light of a massive software flaw that has resulted in the precautionary shutdown of thousands of websites. THE CANADIAN PRESS/Jonathan Hayward

“What we’re talking about here isn’t an attack or a hack or malware. What we’re talking about is a door that’s been left open and can be exploited,” said Brent Arnold, a Toronto-based litigator and data breach coach with the law firm Gowling WLG. “We know already that people are out there trying to take advantage of this.”

Arnold said hackers are able to use the software flaw to breach an organization’s defences, meaning they could potentially take control of its web servers, introduce malware or ransomware attacks, or steal customer data.

While public and government institutions appear to be the ones making public statements about Log4j so far, cybersecurity experts say the logging library is widely used in the private sector as well.

Patrick Mathieu, the co-founder of Hackfest, a large computer security event in Quebec City, said he’s concerned about the lack of communication from companies like major banks about how they’re working on the problem.

“Yes, the (Quebec) government’s shut this down, but what about big institutions, finance, insurance, mortgage, medical companies? Are they working on the issue?” Mathieu said.

“The lack of transparency right now, it’s dangerous.”

Even small businesses could potentially be exposed to the risk, said Sumit Bhatia, a director with the Rogers Cybersecure Catalyst at Ryerson University.

“Even if small and medium businesses aren’t developing a framework like this, they might be using products and services from those people who do,” he said. “And it’s important to them to reach out to their service providers and ask about the steps that have been taken.”

With governments and other organizations scrambling right now to assess their websites and patch them if necessary, experts say there’s not a lot that the average Canadian can do at this point to address their personal Log4j vulnerability.

“You don’t have any way of knowing when you visit a website if it’s been compromised with a defect. Short of crawling under a rock and not using your computer and not using the internet, there’s not very much (the average user) can do to look out for this specific problem,” Arnold said.

However, while it’s up to companies and organizations to fix the flaws that exist within their own systems, experts say Canadians should be doubly cautious right now when doing anything online. That means not clicking on suspicious links, being wary of emails from unknown sources, and monitoring their bank balances and credit card statements for unusual activity.

“All we can really do is keep being alert and doing all the things we should already be doing, but that not nearly enough of us are doing,” Arnold said.

“Change your passwords, go in and put in two-factor authentication in your systems,” Bhatia said. “These are steps that can make folks at least feel that they’ve done their part, while they’re allowing government institutions and businesses to think about how they’re going to be preventative in their own measures.”

— With files from Jacob Serebrin in Montreal

This report by The Canadian Press was first published Dec. 13, 2021.

Report Error Submit a Tip

More Stories

Treating the disease we simply won’t insure

Rafiq Andani 5 minute read Yesterday at 2:00 AM CDT

There is a condition affecting tens of thousands of Canadians. In 2024, one national measure estimated that almost 120,000 people had the condition. The estimate captures only part of the problem.

Mayoral candidate denounced for online comments

Morgan Modjeski 3 minute read Preview

Mayoral candidate denounced for online comments

Morgan Modjeski 3 minute read Sunday, Sep. 13, 2026

A Winnipeg mayoral candidate is facing criticism after he posted derogatory comments about immigrants and used the word “gay” as an insult online.

Read
Sunday, Sep. 13, 2026

A father and son arrested last month are accused of travelling across Canada — and using courier services and Canada Post — to supply their Winnipeg drug-trafficking operation, a recent court filing shows.

Film fest showcases Africa’s best

Ben Waldman 5 minute read Preview

Film fest showcases Africa’s best

Ben Waldman 5 minute read 2:00 AM CDT

Winnipeggers are sometimes accused of living within the Perimeter, meaning a visit to Ouagadougou, the capital city of Burkina Faso, might be out of the question for your weekend travel plans.

Read
2:00 AM CDT

Seven years sought for serial harasser

Dean Pritchard 5 minute read Preview

Seven years sought for serial harasser

Dean Pritchard 5 minute read 2:01 AM CDT

Alexander Beaton finished serving a two-year jail sentence for criminally harassing six women and didn’t last two days in the community before he was back at it, sending unwanted obscene messages and videos to a dozen women.

Now prosecutors are seeking a seven-year prison sentence for the 30-year-old Winnipeg man, whose latest string of victims includes a police officer who investigated his earlier crimes.

“He essentially continued (offending) unabated,” Crown attorney Brett Rach told provincial court Judge Malcolm McDonald at a sentencing hearing Friday. “It caused more than a nuisance to these victims — it caused them to fear for their safety.”

Beaton pleaded guilty to 14 charges of criminal harassment, sending indecent communications and breaching court orders for a campaign of harassment waged between 2015 and 2025.

Read
2:01 AM CDT

Rogers, Telus deny blame for June twister alert barrage

Malak Abas 3 minute read Preview

Rogers, Telus deny blame for June twister alert barrage

Malak Abas 3 minute read Updated: 7:21 AM CDT

Telecom companies say they aren’t to blame for the barrage of tornado alerts Manitobans received during severe thunderstorms in early June.

The Canadian Radio-television and Telecommunications Commission announced in August it would investigate the unusually high number of alerts, and called on the Pelmorex Corp., which operates the national Alert Ready system, along with telecom companies Bell, Rogers and Telus to respond to a number of questions.

They were given until last Friday to describe their possible roles in the creation, receipt, processing or distribution of alerts issued from Environment and Climate Change Canada in the midst of the June 9 storm.

Telus said in its response that it received 133 alert requests targeted to Manitoba created by Environment Canada and forwarded by Pelmorex between 2:35 p.m. June 9 and 3:29 a.m. the following day. While the majority of those messages contained identical information and were automatically suppressed, 17 were ultimately sent out as alerts in Winnipeg.

Read
Updated: 7:21 AM CDT