Heartbleed OpenSSL Vulnerability
The cluster discusses the Heartbleed bug in OpenSSL, its discovery after years in the codebase, catastrophic impact, patching, and use as an example of open-source security failures and auditing challenges.
Activity Over Time
Top Contributors
Keywords
Sample Comments
We had access to openssl code, and yet heartbleed happened.
Heartbleed has been patched, so unless you know a serious attack vector, I'm not sure where this is going.
But given Heartbleed, OpenSSL CCS, etc...
Don't forget heartbleed, a vulnerability in OpenSSL, the software that secures pretty much everything.
Remember OpenSSL / Heartbleed etc?
Like heartbleed, gotofail, or the debian ssl entropy bug? :)
OpenSSL (before HeartBleed) springs to mind.https://news.ycombinator.com/item?id=7640378
What practically exploitable attacks have shown up in OpenSSL over the years, with the exception of Heartbleed?
Heartbleed was a decade ago? JFC Iām getting old
Heartbleed was in OpenSSL for years before it was discovered. It was readily auditable with plenty of docs and specs and yet nobody noticed.