Heartbleed... Is this the end?


It has been patched. It was patched when it first came to the public domain.

You can patch it all you like, but until *everyone* who has OpenSSL on their server updates, then it's still a problem.

Also, what about the bad guys who have managed to steal private SSL keys via the exploit? Reissuing SSL certs surely isn't on someones favorite thing to do, especially as it's costly.


Or is the whole internet going up have to find a new encryption for secure data?

Nothing was wrong with the encryption, it was just bad logic. The logic allowed an offset to be allocated in the data, thus allowing memory access to be exploited.


As everyone is aware heartbleed has killed off SSL

Only for servers running outdated (pre-patch) OpenSSL versions


