The one thing that might be of some small comfort to others is the fact that at least the NSA didn't know about this bug. If they had, there wouldn't be any talk of HTTPS being a barrier in their leaked presentations. That said, all of that encrypted traffic they've got stored up can now, thanks to this bug, be decrypted.
OpenSSL Heartbleed Security Update
31–33 of 33 posts
Re: OpenSSL Heartbleed Security Update
#32Earlier quoted context omitted.
They did compartmentalize. They still do. That's why having an insider with sysadmin access and prestige for social engineering purposes is so dangerous.
Yeah. We should still take Rumsfeld's advice about what we don't know.
So was the advice about going to war with the Army you had, not the one you'd wished you had.
Re: OpenSSL Heartbleed Security Update
#33Loading an https://APPNAME.herokuapp.com page, I'm seeing a certificate (sn:"0E:3E:94:7F:C0:64:D7:4A:52:B1:38:D7:71:90:88:1F") with an "Issued Date" of "1/20/14"... which doesn't sound like it's been regenerated in the last 24 hours. Am I interpreting the certificate info wrong? [edit per official answer below: YES] (Are fresh certificates sometimes given much older start times? [edit: YES] ) This blogpost doesn't cl…
Several certificate vendors reissue certificates with the same "not valid before"/"issued" date as the original one.
http://blog.digicert.com/2014/04/heartbleed-openssl-fix/
Excerpt: "Also, Busy IT Guy is right; it's a little disheartening to be listed as Unsafe after having done all the right things, just because the issue date didn’t get updated."