Heartbleed Update v3
blogs.akamai.com
Heartbleed Update v3
1–10 of 55 posts
Re: Heartbleed Update v3
#2I don't know akamai's relationship with open source projects, but it sounds like they had local changes and tried to karma whore them as, "trust us, our customers were protected, and we contribute to open source." I hope I'm wrong, or they deserve the public shaming they are receiving. Ultimately, we need more engagement from commercial organizations benefiting from open source projects.
Re: Heartbleed Update v3
#3Good politics: they had custom code for parts of OpenSSL, they published it when it seemed needed, open-source community told them what was wrong, they fixed it and apologized. No bullshit.
Re: Heartbleed Update v3
#4I'm so grateful we have people like Willem Pinckaers uncovering these things.
Re: Heartbleed Update v3
#5Good response from Akamai. No beating around the bush there.
Re: Heartbleed Update v3
#6Good politics: they had custom code for parts of OpenSSL, they published it when it seemed needed, open-source community told them what was wrong, they fixed it and apologized. No bullshit.
Also: the way this played out makes an awesome story for the next time Akamai experiences internal pushback against participating in open source. "Remember that one time it saved our bacon" is a political goldmine.
Re: Heartbleed Update v3
#7I would like to know how many security related patches they are keeping for themselves? And I think not only Akamai did this. I hope that this situation will prove that security needs a bit more patch reviews and a bit less of secret sauce.
Re: Heartbleed Update v3
#8Right before this all came out our Akamai rep came on site and swore up and down they were not vulnerable. They need to quickly communicate internally as well that a vulnerability existed and send account managers back out to work on high priority cert rollovers.
Re: Heartbleed Update v3
#9Good response from Akamai. No beating around the bush there.
Yes, they've been clear and honest in their communication.
Re: Heartbleed Update v3
#10Good politics: they had custom code for parts of OpenSSL, they published it when it seemed needed, open-source community told them what was wrong, they fixed it and apologized. No bullshit.
Also: the way this played out makes an awesome story for the next time Akamai experiences internal pushback against participating in open source. "Remember that one time it saved our bacon" is a political goldmine.
Them and everybody else. "Remember that time akamai ran vulnerable code in production for 13 years and the bug got patched two days after they open-sourced it" should be able to drive open source contributions at all kinds of companies.