Don’t do SECURITY. Do business SECURELY.

Heartbleed bug exposes flaw in widely used OpenSSL encryption

A critical flaw in OpenSSL let attackers read server memory, exposing passwords and encryption keys on a large share of secure websites.

A serious vulnerability dubbed Heartbleed was disclosed in OpenSSL, the open-source encryption library used by a large share of the world’s secure websites. The flaw was found independently by Neel Mehta of Google and the Finnish security firm Codenomicon.

What happened

  • The bug (CVE-2014-0160) in OpenSSL’s heartbeat extension let attackers read chunks of a server’s memory without leaving a trace.
  • Exposed memory could include passwords, session data, and the private keys used to secure websites.
  • Around half a million websites were estimated to be vulnerable, and many organisations had to patch, replace certificates, and ask users to change passwords.
  • Networking equipment and other devices that embedded OpenSSL were also affected.

Why it mattered

Heartbleed showed how much of the internet relied on a small, underfunded open-source project, and led to new industry funding for critical open-source software. Its catchy name and logo also changed how vulnerabilities are publicised.

Lessons for organisations

Organisations should keep an inventory of the software components they use, including open-source libraries, so they can quickly find and patch affected systems. After a key-exposure flaw, certificates and credentials should be rotated, not just patched.

Source: Slate

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights