Heartbleed: The OpenSSL Bug That Exposed the Internet’s Unpaid Guards

For two years, a single missing bounds check sat inside OpenSSL, the open source cryptography library that put the padlock icon on most of the web. The Heartbeat extension, submitted by PhD student Robin Seggelmann and reviewed by core developer Stephen Henson, went live in March 2012. It let a computer ask a server to echo back a short message, but the server never verified the claimed length. An attacker could send four letters, claim five hundred, and receive whatever sat next to them in active memory: plain text passwords, session cookies, even the server’s private keys, up to 64 kilobytes per request.

This episode follows the bug from its near simultaneous discovery in April 2014 by Google’s Neel Mehta and the Finnish firm Codenomicon to the panic that followed, when roughly 17 percent of secure web servers, about half a million machines, were found vulnerable. It then turns to the harder lesson. The code guarding trillions of dollars in commerce was maintained by one or two people living on about $2,000 a year in donations, and the industry had to decide whether to finally pay for the foundations it was built on.

  • Codenomicon bought a domain, drew the bleeding heart logo, and explained the flaw in plain English, a branding move that changed how vulnerabilities are disclosed.
  • The Canada Revenue Agency shut down its tax filing site and extended the deadline after someone stole the social insurance numbers of 900 taxpayers in a six hour window. The RCMP later arrested a computer science student.
  • Bloomberg reported that the NSA had known about the flaw for years, which the agency and the White House flatly denied. Suspicious server logs from six months earlier turned out to be the harmless scanner Masscan.
  • Patching was not enough: administrators had to generate new keys and revoke old certificates, and Cloudflare estimated the revocation list alone could cost one issuer $400,000 a month in bandwidth.
  • OpenBSD developers forked the code into LibreSSL and cut 90,000 lines in the first week, while the Linux Foundation’s Core Infrastructure Initiative, funded by Amazon, Google, Microsoft, and IBM, made OpenSSL its first major recipient.

Leave a Reply

Discover more from pplpod

Subscribe now to keep reading and get access to the full archive.

Continue reading