A review by a security engineer would have prevented a false sense of security Everyone involved in this, from the people who wrote the heartbeat code, the people who committed the code, the people at Akami who wrote this patch, this poster ... all would describe themselves as security engineers. Is everyone but Willem Pinckars incompetent? I think the one lesson to learn is to treat crypto just like you do cloud pro…
Apparently, he is not competent enough to understand what "this is not our actual code but merely a POC" means.
void *custom_malloc() { };
It's only a POC though so you'll have to adapt it. You can go ahead and begin praising me and flaming my critics.