#HeartBleed

Herzmut 🏳️‍🌈herzmut@23.social
2025-03-26

Warum noch mal war unsere kritische Infrastruktur im Netz, wie #letsencrypt oder #OpenVPN, von der US-Regierung abhängig?

Irgendwann braucht man nach #Heartbleed und #GnuPG-Krise auch nicht mehr Snowden zitieren, wenn die einzige Konsequenz, die man da nicht gezogen hat, die ist, dass Open Source-Entwicklung auch Geld kostet.

Und dass man das am besten auch nicht allein einer alle vier Jahre wechselnden Regierung überlässt.

#KRITIS #Privacy #Tor

2025-02-19

Now Simon Moore from the #UniversityOfCambridge (but on sabatical at Victoria University Wellington) is talking about architecture security features with #CHERI
To mitigate #MemorySafety bugs like #HeartBleed

#mw25nz

A speaker stands at a podium in front of a presentation slide titled "Making computers fundamentally more secure: the CHERI approach." The setting is a conference with banners for "Multicore World" and "OpenParallel."Slide showing the micro architecture details of the CHERI implementation in a RISC-V core
Benjamin Carr, Ph.D. 👨🏻‍💻🧬BenjaminHCCarr@hachyderm.io
2024-11-04

How to make #opensource #software more secure
The #xz attack, which followed other well-known cybersecurity incidents involving open source software like #Heartbleed, #Shellshock, and #Log4j, was another stark reminder that open source software, given how widespread it is, can pose significant #security risks.  
techcrunch.com/2024/11/01/how- #itsec

Als ich meinte, wir brauchen mal wieder richtige Bugs, meinte ich nicht dieses auf #Wish bestellte #Heartbleed

jbp.io/2024/06/27/cve-2024-553

2024-04-29

Follow up to my first #Heartbleed article, this time with a interview with OpenSSF GM Omkhar Arasaratnam to discuss the security of open source 10 years on. Looking at whether we are too reliant on the volunteered hours of maintainers, asking if the space is clouded with for-profit offerings, and who is looking after the health of those maintainers?

insight.scmagazineuk.com/open-

2024-04-15

New from me SC UK:

This month marks 10 years since #Heartbleed was disclosed, and #cybersecurity had to react fast. I talked to CISO Neil Thacker and Synopsys - who acquired Codenomicon (who discovered the OpenSSL bug) - about lessons learned over the past decade about open source code bases, patching and vulnerabilities.

insight.scmagazineuk.com/ten-y

XnetX_net
2024-04-09

Este parasitismo provoca precariedad, agotamiento y hartazgo en desarrolladores y lleva a problemas de seguridad global como

Por eso nuestras autoridades se plantean obligar a las BigTech a contribuir… ¡NO! Se plantean obligar a voluntarios a darles mantenimiento 🤯

Ottoottok
2024-04-07

Today marks the 10th anniversary of the vulnerability in OpenSSL. It had the same ultimate root cause as recent backdoor incident. This underscores the importance of public funding to protect vital open source projects that underpin our internet infrastructure. Learn more: optimizedbyotto.com/post/what-

Christina Warrenfilm_girl
2024-04-03

Thinking a lot about the backdoor this week. Almost exactly 10 years ago, I wrote this about the attack and how we should do more to support , especially for important libraries. Sadly, almost all of what I wrote then is still relevant. web.archive.org/web/2014042013

2024-03-30

À quelques jours près, la découverte du code malicieux de #xz coïncide avec la découverte de #HeartBleed avec 10 ans d'écart. 🥳

(J'ai l'impression que les choses n'ont pas tellement évoluée depuis 😓)

Chuck Darwincdarwin@c.im
2024-03-30

The important role #OpenSSL plays in securing the Internet has never been matched by the financial resources devoted to maintaining it.
The open source #cryptographic #software library secures hundreds of thousands of Web servers and many products sold by multi-billion-dollar companies,
but it operates on a shoestring budget.
OpenSSL Software Foundation President Steve Marquess wrote in a blog post last week that OpenSSL typically receives about $2,000 in donations a year
and has just one employee who works full time on the open source code.

Given that, perhaps we shouldn’t be surprised by the existence of #Heartbleed, a security flaw in OpenSSL that can expose user passwords and the private encryption keys needed to protect websites.

OpenSSL’s bare-bones operations are in stark contrast to some other open source projects that receive sponsorship from corporations relying on their code.
Chief among them is probably the #Linux operating system #kernel, which has a foundation with multiple employees and funding from HP, IBM, Red Hat, Intel, Oracle, Google, Cisco, and many other companies.
Workers at some of these firms spend large amounts of their employers’ time writing code for the Linux kernel, benefiting everyone who uses it.
That’s never been the case with OpenSSL, but the Linux Foundation wants to change that.
⭐️The foundation today is announcing a three-year initiative with at least $3.9 million to help under-funded open source projects⭐️
—with OpenSSL coming first.
Amazon Web Services, Cisco, Dell, Facebook, Fujitsu, Google, IBM, Intel, Microsoft, NetApp, Qualcomm, Rackspace, and VMware have all pledged to commit 💥at least $100,000 a year for at least three years💥 to the “#Core #Infrastructure #Initiative,” Linux Foundation Executive Director Jim Zemlin told Ars.
To be clear, the money will go to multiple open source projects
—OpenSSL will get a portion of the funding but likely nowhere close to the entire $3.9 million.
The initiative will identify important open source projects that need help in addition to OpenSSL.

arstechnica.com/information-te

2024-03-30

@Bibobu

Le pire, c'est que le débat autour des petits projets extrêmement utilisés et pourtant complètement sous-financés avait déjà eu lieu plusieurs fois ces dernières années, à la suite de failles mémorables telles que #Heartbleed.

Sauf que ça s'agite un peu sur le moment, ça créé divers fonds pour financer le libre, mais une fois la tempête passée, on en entend plus parler et rien ne change ☹️

next.ink/4883/cybersecurite-et

#Linux #logiciellibre #FOSS #cybersecurity

@lauren @djb

All in all, this seems like another wildly overblown security vulnerability #publicity tour. I'm only shocked it doesn't have its own website and professional logo like "#shellshock" or "#heartbleed".

Signed,

Long time qmail guy & #internet #mail #infrastructure consultant

5/5

#PRStunt #security #vulnerability #researcher #report #PR #stunt

Daniel Böhmerdboehmer@ieji.de
2023-10-10

I don't see any nickname for the upcoming #curl #vulnerability yet. You can make some suggestions here:

#heartbleed #poodle #breach #owasp

2023-08-19

Wait, is #heartbleed yet another bug that would've been impossible with any language with sane boundary checks like #Ada or #CommonLisp? (And also yet another malloc & equivalents considered harmful, I suppose.)

Why are we still not learning anything?

2023-08-18
2023-06-04

Etwas früh dran zum runden Jubiläum hat K2 jetzt #Heartbleed Gedächtnisturnschuhe. 😍 de.m.wikipedia.org/wiki/Heartb

Foto zeigt weiße Sketchers-Turnschuhe mit drei blutenden Herzen.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst