The Heartbleed Challenge
31–40 of 125 posts
Re: The Heartbleed Challenge
#32Don't be surprised when the winner has an @nsa.gov email address.
I would be shocked if Neel was wrong about private key exposure AND it is a nation state that highlights his misunderstanding.
Re: The Heartbleed Challenge
#33Re: The Heartbleed Challenge
#34A different CloudFlare post on HN https://news.ycombinator.com/item?id=7572666 claimed that they had a fix for the HeartBleed bug 12 days ago. At CloudFlare, we received early warning of the Heartbleed vulnerability and patched our systems 12 days ago. I commented on that post that the date of discovery was 7 days ago http://www.vocativ.com/tech/hacking/behind-scenes-crazy-72-h... For whatever reason that HN post was…
Re: The Heartbleed Challenge
#35A different CloudFlare post on HN https://news.ycombinator.com/item?id=7572666 claimed that they had a fix for the HeartBleed bug 12 days ago. At CloudFlare, we received early warning of the Heartbleed vulnerability and patched our systems 12 days ago. I commented on that post that the date of discovery was 7 days ago http://www.vocativ.com/tech/hacking/behind-scenes-crazy-72-h... For whatever reason that HN post was…
I'm sure this bug was discovered at least 1 month ago. I would not trust my keys are safe even if using cloudflare.
"While we believe it is unlikely that private key data was exposed, we are proceeding with an abundance of caution. We’ve begun the process of reissuing and revoking the keys CloudFlare manages on behalf of our customers. In order to ensure that we don’t overburden the certificate authority resources, we are staging this process. We expect that it will be complete by early next week."
Re: The Heartbleed Challenge
#36A different CloudFlare post on HN https://news.ycombinator.com/item?id=7572666 claimed that they had a fix for the HeartBleed bug 12 days ago. At CloudFlare, we received early warning of the Heartbleed vulnerability and patched our systems 12 days ago. I commented on that post that the date of discovery was 7 days ago http://www.vocativ.com/tech/hacking/behind-scenes-crazy-72-h... For whatever reason that HN post was…
I'm sure this bug was discovered at least 1 month ago. I would not trust my keys are safe even if using cloudflare.
Re: The Heartbleed Challenge
#37ssl_certificate /home/nick/ssl-bundle.crt ssl_certificate_key /home/nick/server.key
Got that one too. Also got this [1] but it looks like public keys maybe ? I'dont have time to check right now. [1] http://pastebin.com/KiVNV0c6
Edit: It seems that these are only trusted CA certs, there is no server cert in there.
Re: The Heartbleed Challenge
#38It's cool seeing other people's attempts to extract the key in my return buffer. It's like multiplayer microcorruption.com
Re: The Heartbleed Challenge
#39Re: The Heartbleed Challenge
#40A different CloudFlare post on HN https://news.ycombinator.com/item?id=7572666 claimed that they had a fix for the HeartBleed bug 12 days ago. At CloudFlare, we received early warning of the Heartbleed vulnerability and patched our systems 12 days ago. I commented on that post that the date of discovery was 7 days ago http://www.vocativ.com/tech/hacking/behind-scenes-crazy-72-h... For whatever reason that HN post was…
The bug was discovered by whitehat researchers approximately 12 days ago. It was publicly announced 5 days ago. We got early word of it from the researchers who initially discovered it, allowing us to patch our systems and ensure all sites behind CloudFlare were not vulnerable. However, we have no way of knowing how long blackhats may have had it. It had been present in the OpenSSL software for the last 2+ years. The…