YNOT
  • Home
  • Industry News
    • Adult Business News
    • Adult Novelty News
    • YNOT Magazine
    • EU News
    • Opinions
    • Picture Galleries
  • PR Wire
    • Adult Company News
    • Adult Retail News
    • Adult Talent News
    • Adult Videos News
  • Podcasts
  • Industry Guides
    • Adult Affiliate Guide
    • Affiliate Marketing for Beginners
    • Top Adult Traffic Networks
    • Top Adult PR Agents
    • Funding an Adult Business
  • Business Directory
    • View Categories
    • View Listings
    • Submit Listing
  • Newsletters
  • Industry Events
    • Events Calendar
    • YNOT Cam Awards | Hollywood
    • YNOT Awards | Prague
    • YNOT Cammunity
    • YNOT Summit
    • YNOT Reunion
  • Login with YNOT ID

Who Caused the Heartbleed SSL Bug?

Posted On 15 Apr 2014
By : admin

CYBERSPACE — The “Heartbleed” security bug has been widely patched across the internet, and the panic that accompanied the public disclosure of the flaw is now winding down. Efforts to discover the individual or individuals responsible for the mess, however, are just getting started.

The Heartbleed security flaw exploited a weakness in OpenSSL system’s “Heartbeat Request” function, where the link between a server and a computer sharing a secure connection is tested by the transmission of a request packet. The packet contains a tiny amount of information from the computer that is supposed to be answered by the server by sending that same information back to the source of the query.

The Heartbleed bug was exploited by hackers sending a malformed heartbeat request with a small data payload and an inappropriately large length field to the server. The server randomly filled in the blank field with random data from its recently discarded SSL memory.

While attackers would have no control over what data was sent back, they could fish for sensitive data, including server’s private master key and well as user’s passwords, cookies and other compromising data.

Conspiracy theories implicating the NSA in the Heartbleed fiasco continue to be batted about. Some say that the flaw was introduced into OpenSSL at their direction, while others allege the NSA was aware of this vulnerability for some time and withheld the information lest it curtail their intelligence-gathering activities.

The US government denies involvement in the Heartbleed flaw and also denies that it used the bug as a tool to obtain sensitive data. Documents released via the Edward Snowden leaks show that the agency was working on cracking SSL via a program they had dubbed BULLRUN.

A German software developer, Dr. Robin Seggalmann, who as it turns out was the individual who introduced the errant code, has stepped forward to take responsibility for the mistake, which was added to OpenSSL over two years ago as part of a project to fix bugs and add features to the existing software code. The small error missed validation of message length, an error also missed by another OpenSSL programmer named Dr. Steven Henson.

  • google-share
Previous Story

Jasmin.com Launches Adult Live Chat for HDTV

Next Story

China Starts a New Assault on Porn

Leave a Reply Cancel reply

You must be logged in to post a comment.

Sponsor

YNOT Shoot Me

YNOTShootMe.com has exclusive pics from adult industry business events. Check it out!

YNOT Directory

  • Bcams
    News & Resources
  • SmuttyFy
    Other Professional Services
  • Global Access
    Online Billing Services
  • Premiere Listing

    PayOut Magazine

    More Details

RECENT

POPULAR

COMMENTS

Maya Farrell appears on the Misfit Effect

Posted On 27 Aug 2025
Maria May Schools Football Star for Naughty America

Maria May Schools Football Star for Naughty America

Posted On 27 Aug 2025

Onahole.com Is Giving Head with Brain Hacker DX

Posted On 27 Aug 2025

Vanessa, Meet Vivid

Posted On 29 Sep 2014
Laila Mickelwaite and Exodus Cry

Laila Mickelwaite, Exodus Cry and their Crusade Against Porn

Posted On 03 May 2021

Someone puts Gal Gadot in one of your vids? Take it down!

Posted On 13 Dec 2017

Hoping viewers can also enjoy a spooky...

Posted On 24 Oct 2023

now a days these type of games will get...

Posted On 17 Jul 2023

good move from adent. these type of...

Posted On 06 Jul 2023

Sponsor

Sitemap
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.OkPrivacy Policy