A serious vulnerability dubbed Heartbleed was disclosed in OpenSSL, the open-source encryption library used by a large share of the world’s secure websites. The flaw was found independently by Neel Mehta of Google and the Finnish security firm Codenomicon.
What happened
- The bug (CVE-2014-0160) in OpenSSL’s heartbeat extension let attackers read chunks of a server’s memory without leaving a trace.
- Exposed memory could include passwords, session data, and the private keys used to secure websites.
- Around half a million websites were estimated to be vulnerable, and many organisations had to patch, replace certificates, and ask users to change passwords.
- Networking equipment and other devices that embedded OpenSSL were also affected.
Why it mattered
Heartbleed showed how much of the internet relied on a small, underfunded open-source project, and led to new industry funding for critical open-source software. Its catchy name and logo also changed how vulnerabilities are publicised.
Lessons for organisations
Organisations should keep an inventory of the software components they use, including open-source libraries, so they can quickly find and patch affected systems. After a key-exposure flaw, certificates and credentials should be rotated, not just patched.
Source: Slate
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.