bk99.de entertain the web since 1997

Heartbleed and its aftermath

Summary

Zakir Durumeric examines Heartbleed with internet-wide measurements and shows its spread, key risks, speed of response and the vulnerable systems that remained. Small memory bugs can trigger global infrastructure crises through widely used libraries. An effective response needs inventory, patching, key changes and transparent communication together.

Ideas

  • A missing length check let remote clients read other processes’ memory.
  • Memory contents could include credentials, sessions and possibly private keys.
  • An update alone was not enough if keys and certificates had already been exposed.
  • Internet-wide scans made the progress of remediation measurable.

Recommendations

  • Record centrally which services use cryptographic libraries.
  • Plan key and certificate changes as a normal part of incident response.

References

Watch the talk

Search the Web Archive