Jump to content

Heartbleed... Is this the end?


Recommended Posts

It has been patched. It was patched when it first came to the public domain.

You can patch it all you like, but until *everyone* who has OpenSSL on their server updates, then it's still a problem.

Also, what about the bad guys who have managed to steal private SSL keys via the exploit? Reissuing SSL certs surely isn't on someones favorite thing to do, especially as it's costly.


Or is the whole internet going up have to find a new encryption for secure data?

Nothing was wrong with the encryption, it was just bad logic. The logic allowed an offset to be allocated in the data, thus allowing memory access to be exploited.


As everyone is aware heartbleed has killed off SSL

Only for servers running outdated (pre-patch) OpenSSL versions


Edited by sniko
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Create New...