# Heartbleed bug - security flaw in SSL/TLS

**URL:** <https://boards.straightdope.com/t/heartbleed-bug-security-flaw-in-ssl-tls/685831>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [April 10, 2014, 11:54pm UTC](https://boards.straightdope.com/t/heartbleed-bug-security-flaw-in-ssl-tls/685831 "2014-04-10T23:54:57Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![aceplace57](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/aceplace57/32/3500_2.png) [@aceplace57](https://boards.straightdope.com/u/aceplace57)\
**Post date:** [April 10, 2014, 11:54pm UTC](https://boards.straightdope.com/t/heartbleed-bug-security-flaw-in-ssl-tls/685831/1 "2014-04-10T23:54:57Z")

</div>

This potential could be a big one. That padlock symbol that tells you the connection i secure? You’ll often see it logging in or checking out on a shopping web site. I realize these acronyms mean little to most people. The article explains the problem in more detail.

They found a major security flaw. Oh, crap.

They’ve already got a patch for OpenSSL. It has to be applied to all the web sites that use it. Yahoo is fixing their sites now.

That means password changes are coming.

I wonder if SSH is also effected?

> **[What is the ‘Heartbleed’ bug? Understanding the major Internet security...](https://www.nydailynews.com/2014/04/10/what-is-the-heartbleed-bug-understanding-the-major-internet-security-breakdown/)**
>
> NEW YORK — Millions of passwords, credit card numbers and other personal information may be at risk as a result of a major breakdown in Internet security revealed earlier this week. The damag…

> [@](#):
>
> Q: How does it work?
> 
> A: Heartbleed creates an opening in SSL/TLS, an encryption technology marked by the small, closed padlock and “https:” on Web browsers to show that traffic is secure. The flaw makes it possible to snoop on Internet traffic even if the padlock is closed. Interlopers can also grab the keys for deciphering encrypted data without the website owners knowing the theft occurred.
> 
> The problem affects only the variant of SSL/TLS known as OpenSSL, but that happens to be one of the most common on the Internet.

---

<div class="post-metadata">

**Author:** ![jimbuff314](https://avatars.discourse-cdn.com/v4/letter/j/c57346/32.png) [@jimbuff314](https://boards.straightdope.com/u/jimbuff314)\
**Post date:** [April 11, 2014, 12:11am UTC](https://boards.straightdope.com/t/heartbleed-bug-security-flaw-in-ssl-tls/685831/2 "2014-04-11T00:11:21Z")

</div>

Thread already going on: [Heartbleed](http://boards.straightdope.com/sdmb/showthread.php?t=720444)

---

<div class="post-metadata">

**Author:** ![aceplace57](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/aceplace57/32/3500_2.png) [@aceplace57](https://boards.straightdope.com/u/aceplace57)\
**Post date:** [April 11, 2014, 12:14am UTC](https://boards.straightdope.com/t/heartbleed-bug-security-flaw-in-ssl-tls/685831/3 "2014-04-11T00:14:08Z")

</div>

I never thought to look for it in IMHO.

I was just reporting the security flaw. Not soliciting opinions about it.

---

<div class="post-metadata">

**Author:** ![Quimby](https://avatars.discourse-cdn.com/v4/letter/q/22d042/32.png) [@Quimby](https://boards.straightdope.com/u/Quimby)\
**Post date:** [April 11, 2014, 12:43am UTC](https://boards.straightdope.com/t/heartbleed-bug-security-flaw-in-ssl-tls/685831/4 "2014-04-11T00:43:49Z")

</div>

FWIW I did the exact same thing earlier today.

---

<div class="post-metadata">

**Author:** ![aceplace57](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/aceplace57/32/3500_2.png) [@aceplace57](https://boards.straightdope.com/u/aceplace57)\
**Post date:** [April 11, 2014, 12:51am UTC](https://boards.straightdope.com/t/heartbleed-bug-security-flaw-in-ssl-tls/685831/5 "2014-04-11T00:51:06Z")

</div>

Well, I really screwed this up then. So sorry.

The thread should be in Mundane. That’s where Windows security flaws are normally reported. Thats where I look for them.

---

<div class="post-metadata">

**Author:** ![blindboyard](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/blindboyard/32/2833_2.png) [@blindboyard](https://boards.straightdope.com/u/blindboyard)\
**Post date:** [April 11, 2014, 11:10am UTC](https://boards.straightdope.com/t/heartbleed-bug-security-flaw-in-ssl-tls/685831/6 "2014-04-11T11:10:41Z")

</div>

SSH isn’t effected.

---

<div class="post-metadata">

**Author:** ![aceplace57](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/aceplace57/32/3500_2.png) [@aceplace57](https://boards.straightdope.com/u/aceplace57)\
**Post date:** [April 11, 2014, 5:33pm UTC](https://boards.straightdope.com/t/heartbleed-bug-security-flaw-in-ssl-tls/685831/7 "2014-04-11T17:33:41Z")

</div>

It’s rare to here directly from the programmer that caused the problem. Contributors like Seggelmann are an important part of the Open Source projects. Usually the review process catches any errors. Once in awhile one still gets through.

> **[Developer confesses to accidentally writing the Heartbleed code](https://www.dailymail.co.uk/sciencetech/article-2602277/Heartbleed-accident-Developer-confesses-coding-error-admits-effect-clearly-severe.html)**
>
> German developer Robin Seggelmann told the Sydney Morning Herald he wrote the code, which was reviewed by other members and added to the OpenSSL software.

> [@](#):
>
> German programmer Dr Robin Seggelmann told the Sydney Morning Herald he wrote the code, which was then reviewed by other members and eventually added to the OpenSSL software.
> 
> He admitted the mistake itself was ‘trivial’, but added that its effect is ‘clearly severe’.
> 
> The code was added on New Year’s Eve in 2011 and no-one spotted the mistake until earlier this month.
> 
> ‘It was a simple programming error in a new feature, which unfortunately occurred in a security relevant area,’ Dr Seggelmann said.
> 
> ‘It was not intended at all, especially since I have previously fixed OpenSSL bugs myself, and was trying to contribute to the project.’
> 
> Dr Seggelmann said the flaw was missed by him and a reviewer, who appears to have been  
> Dr Stephen Henson, according to the logs.
> 
> OpenSSL is an open-source program which anyone can contribute to and improve.
> 
> Changes are submitted and reviewed before being added to the final release.
> 
> Websites are then sent this release to update their systems.

---

<div class="post-metadata">

**Author:** ![KneadToKnow](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/kneadtoknow/32/3999_2.png) [@KneadToKnow](https://boards.straightdope.com/u/KneadToKnow)\
**Post date:** [April 11, 2014, 5:38pm UTC](https://boards.straightdope.com/t/heartbleed-bug-security-flaw-in-ssl-tls/685831/8 "2014-04-11T17:38:14Z")

</div>

Obligatory [XKCD link](http://xkcd.com/1354/).
