Live data from Hacker News

Heartbleed Update v3

blogs.akamai.com

51–55 of 55 posts

Re: Heartbleed Update v3

#51
post #8

Right before this all came out our Akamai rep came on site and swore up and down they were not vulnerable. They need to quickly communicate internally as well that a vulnerability existed and send account managers back out to work on high priority cert rollovers.

Our rep said the same thing even when we insisted they rotate our certs on day 1.

Of course we're still waiting. I don't know who's decision it was to not reissue all certs on day 1, but this is an epically bad decision bordering on gross negligence.

Heads should roll.

Re: Heartbleed Update v3

#52
post #6

Earlier quoted context omitted.

Also: the way this played out makes an awesome story for the next time Akamai experiences internal pushback against participating in open source. "Remember that one time it saved our bacon" is a political goldmine.

Them and everybody else. "Remember that time akamai ran vulnerable code in production for 13 years and the bug got patched two days after they open-sourced it" should be able to drive open source contributions at all kinds of companies.

It won't matter. The response will be, "Without releasing the source no one would've ever found the bug. Now think of how many bugs were found that haven't been responsibly disclosed!"

Re: Heartbleed Update v3

#53
post #40
post #39

Earlier quoted context omitted.

There I agree with you. Thanks.

For what it's worth, I think that the patch you guys threw out there (and have been using for a while) is a great idea, and I really hope it ends up in mainline OpenSSL. I think you guys have acted 100% properly from a tech perspective in this whole thing, even if a bug did pop up (when do they not?). I disagree strongly with the business decision made w.r.t. keys, but I hope people don't take that as me ragging on t…

How do you know the business team didn't ask the tech team:

"Should we rotate all the keys?"

And someone said: "Nope, we wrote this awesome custom allocator in 2001, all good!".

FWIW, we're still waiting for our cert to be reissued by Akamai. It's only been 6 days since everyone else reissued their certs. Great job team!

Re: Heartbleed Update v3

#54
post #37

Earlier quoted context omitted.

As Andy tweeted, we built that particular patch to keep unencrypted secrets off disk -- it actually was intended to provide tangible security benefit, it wasn't just paranoia: https://twitter.com/csoandy/status/455307255895060480

If you folks have used this technique for years as I believe it has been stated, any particular reason why it wasn't contributed back to OpenSSL earlier?

Licensing issues, primarily. See https://news.ycombinator.com/item?id=7581509

Re: Heartbleed Update v3

#55
post #54

Earlier quoted context omitted.

If you folks have used this technique for years as I believe it has been stated, any particular reason why it wasn't contributed back to OpenSSL earlier?

Licensing issues, primarily. See https://news.ycombinator.com/item?id=7581509

Thanks for the info! Sorry that I didn't reply back earlier, I missed seeing that you had replied :)
Post reply on HN