Heartbleed 101

Marco Carvalho, Jared D. DeMott, Richard Ford, David A. Wheeler · IEEE Security & Privacy · 2014

Described by some as the worst vulnerability since e-commerce began on the Internet, one word sums up what this Basic Training column is all about: Heartbleed. Although we don't necessarily agree with such hyperbole (although it really was pretty bad!), the media furor around the Heartbleed vulnerability was incredible and crossed over from security mailing lists to the national press with remarkable speed. Here, the authors take a look at this vulnerability in OpenSSL and outline how it was fixed. Perhaps more important, they also step back and look at the issue more broadly. Why was the Heartbleed vulnerability missed for so long?

Read the paper · More papers on PaperTik