YNOT
  • Home
  • Industry News
    • Adult Business News
    • Adult Novelty News
    • YNOT Magazine
    • EU News
    • Opinions
    • Picture Galleries
  • PR Wire
    • Adult Company News
    • Adult Retail News
    • Adult Talent News
    • Adult Videos News
  • Podcasts
  • Industry Guides
    • Adult Affiliate Guide
    • Affiliate Marketing for Beginners
    • Top Adult Traffic Networks
    • Top Adult PR Agents
    • Funding an Adult Business
  • Business Directory
    • View Categories
    • View Listings
    • Submit Listing
  • Newsletters
  • Industry Events
    • Events Calendar
    • YNOT Cam Awards | Hollywood
    • YNOT Awards | Prague
    • YNOT Cammunity
    • YNOT Summit
    • YNOT Reunion
  • Login with YNOT ID

Who Caused the Heartbleed SSL Bug?

Posted On 15 Apr 2014
By : admin

CYBERSPACE — The “Heartbleed” security bug has been widely patched across the internet, and the panic that accompanied the public disclosure of the flaw is now winding down. Efforts to discover the individual or individuals responsible for the mess, however, are just getting started.

The Heartbleed security flaw exploited a weakness in OpenSSL system’s “Heartbeat Request” function, where the link between a server and a computer sharing a secure connection is tested by the transmission of a request packet. The packet contains a tiny amount of information from the computer that is supposed to be answered by the server by sending that same information back to the source of the query.

The Heartbleed bug was exploited by hackers sending a malformed heartbeat request with a small data payload and an inappropriately large length field to the server. The server randomly filled in the blank field with random data from its recently discarded SSL memory.

While attackers would have no control over what data was sent back, they could fish for sensitive data, including server’s private master key and well as user’s passwords, cookies and other compromising data.

Conspiracy theories implicating the NSA in the Heartbleed fiasco continue to be batted about. Some say that the flaw was introduced into OpenSSL at their direction, while others allege the NSA was aware of this vulnerability for some time and withheld the information lest it curtail their intelligence-gathering activities.

The US government denies involvement in the Heartbleed flaw and also denies that it used the bug as a tool to obtain sensitive data. Documents released via the Edward Snowden leaks show that the agency was working on cracking SSL via a program they had dubbed BULLRUN.

A German software developer, Dr. Robin Seggalmann, who as it turns out was the individual who introduced the errant code, has stepped forward to take responsibility for the mistake, which was added to OpenSSL over two years ago as part of a project to fix bugs and add features to the existing software code. The small error missed validation of message length, an error also missed by another OpenSSL programmer named Dr. Steven Henson.

  • google-share
Previous Story

Jasmin.com Launches Adult Live Chat for HDTV

Next Story

China Starts a New Assault on Porn

Leave a Reply Cancel reply

You must be logged in to post a comment.

Sponsor

YNOT Shoot Me

YNOTShootMe.com has exclusive pics from adult industry business events. Check it out!

YNOT Directory

  • FUBAR Webmasters
    Photographers and Videographers
  • MVG Video
    Online Content Providers
  • Traffic Holder
    Marketing & Traffic Services
  • Premiere Listing

    Erotic Sky Magazine

    More Details

RECENT

POPULAR

COMMENTS

Addis Fouche & Richelle Ryan Spill Oral Sex Secrets on EBaum's World

Posted On 04 Jul 2025

Emma Rose Guests on "In The Tub" Podcast

Posted On 04 Jul 2025

Cubam Star Eva Maxim Enjoys a Hot, New Scene with White Rhino

Posted On 04 Jul 2025

Vanessa, Meet Vivid

Posted On 29 Sep 2014
Laila Mickelwaite and Exodus Cry

Laila Mickelwaite, Exodus Cry and their Crusade Against Porn

Posted On 03 May 2021

Sex Toy Collective Dildo Sculptor

Posted On 19 Mar 2019

Find a good sex toy is now a problem,...

Posted On 18 Mar 2024

Thanks to the variety of sex toys, I can...

Posted On 02 Feb 2024

I understand the concerns about...

Posted On 05 Jan 2024

Sponsor

Sitemap
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.OkPrivacy Policy