Live data from Hacker News

The Heartbleed Challenge

cloudflarechallenge.com

111–120 of 125 posts

Re: The Heartbleed Challenge

#111
I find this to be disingenous on CloudFlares part. First of all their configuration is almost irrelevant. The heartbleed.com guys did in fact recover key material without much effort.

I really dont care what cloudflare thinks they know about heap allocation in THEIR one trick pony configuration.

its irrelevant to the problem at hand. Sadly another example of CF grandstanding to appear smarter than everyone else with little to back it up.

Re: The Heartbleed Challenge

#113
hmm, all I'm getting is a bunch of dicks...

  0600: 20 38 3D 3D 3D 3D 3D 3D 3D 3D 3D 3D 3D 44 20 20   8===========D
  0610: 20 38 3D 3D 3D 3D 3D 3D 3D 3D 3D 3D 3D 44 20 20   8===========D
  0620: 20 38 3D 3D 3D 3D 3D 3D 3D 3D 3D 3D 3D 44 20 20   8===========D
  0630: 20 38 3D 3D 3D 3D 3D 3D 3D 3D 3D 3D 3D 44 20 20   8===========D

Re: The Heartbleed Challenge

#114
post #82

Earlier quoted context omitted.

> maybe this is not leaked or it requires a read at the correct time because these buffers might be trashed by another computation. As far as I can tell, it's certainly possible for intermediate data to be leaked, but it'd require pretty spectacular timing. That said, I'm having a bit of a hard time understanding why this challenge exists. If the possibility (even remote) exists that key material was leaked in any fo…

i've locally tested the BN_div function and the sdiv buffer is intact at the end of the function with a p or q value. however, the BN values seem to be allocated in some kind of pool and they are reused so the private keys get clobbered by another BN function soon after. also, at the end of the RSA_eay_private_encrypt function the BN values are zeroed (or written over with crap data) so unless there is another implem…

So it looks like you might be right. Debian uses Apache mpm_worker by default, and after getting a test install running and using ab to provide load I managed to get the private key in under a minute on the first run: http://t.co/nYvIw7q4M8 (I was lucky the first time, usually it seems to take a little longer.)

Re: The Heartbleed Challenge

#115
post #83

Earlier quoted context omitted.

It doesn't matter if they show "responsibly disclosed" all their repos are publicly available to see, it takes one person looking through commits then going wtf is this followed by a quick look at the code and a blog post to make this a wildfire.

Every major linux distro has a procedure in place for discreetly preparing updates for pre-disclosure security flaws.

It only takes one person on any of these teams to leak the details and the cat is out of the bag, and then the scramble is on.

Considering the circumstances, it appears that the process that was followed with regards to the release was as flawless as it could have been.

Re: The Heartbleed Challenge

#116
post #81

Earlier quoted context omitted.

You would think that they could easily work on in advance of incidents who they can trust to with early information. I'd be amazed if Canonical (Ubuntu), Redhat (RHEL) and The Attachmate Group (SUSE) wouldn't show discreet discretion. I don't know about Debian and similar projects, but you would think they could determine this in advance.

I haven't been involved in distro security for a few years, but all this coordination used to happen via a mailing list. Organizations (distro maintainers, OS vendors, security people representing some of the larger/more security sensitive open source projects, etc) would need to apply to be on the list. They'd need to document who would have access to the sensitive materials posted, what their procedure would be for…

There is just no easy way to handle this and someone had to make the decision on who got what.

The reality is that the open source community isn't vetted like an intelligence agency when it comes to holding secrets to their vest. It only takes one person in all those OSS communities to leak to the press about something of this magnitude and then the result could be even worse. The fact that this was kept under wraps for 12 days (that we know) is a testament to the folks who made the decision whom to inform.

Re: The Heartbleed Challenge

#117

So out of curiosity, I ran the python heartbleed tester against their server. Surprisingly, the first (and every response thereafter) returned a memory dump which contained at least part of what looked like a private key. I immediately became skeptical when each of these apparent private keys ended in LOLJK. 0690: 79 37 70 71 31 76 63 2F 74 70 49 67 68 4C 4F 4C y7pq1vc/tpIghLOL 06a0: 4A 4B 3D 3D 2D 2D 2D 2D 2D 45 4E…

I got a private key without the LOLJK, but I'm 99% certain this is someone trolling me.

Still going to double-check though.

Re: The Heartbleed Challenge

#118
post #76

We will add a $10,000 bounty for the first published and confirmed successful completion of this challenge. Conditions: 1) CloudFlare confirms success. 2) The winner publishes their solution, including source, publicly. 3) Promptly send the link to the publication to [adam | ionicsecurity | com] (for tracking the order of submissions) Good luck!

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1

Hello Adam!

My email is public: fedor@indutny.com , and here is my proof of identity: https://keybase.io/indutny .

If you wish - you could contact me via it. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1

iQIcBAEBAgAGBQJTSJ7IAAoJEPsOEJWxeXmZYnkP/1r9qVARb89x2bAteh9RPcRI VGUmRZVz/1wLqy/LmvB+XwgkEGRyjQBCa2vHPi8PpwenLEl8IXMMYyzQSqx94tkV y54ZTwABtXXcPIaFOu4O8sG8RM6rDVsF9FpJICVxuYzrkyQPVDMEFa3faBNEgTHo zpgOf5keNq3nCnhTwhkMryBzYVVMLUdQy6JUzhzOXTarmgNH5CtRW0CzFN+9sxM9 6/EH1W4VcJt0lpcvCQK75Kv9syrbavB6qXP85b0gSvKcMHvkX0z5dPphUJcyL/9Q QyXE2vloNj6qwjLQRPoCymSjePeQsodhec47iQxVgil72U5X4YFYJpDHurE5KVOb VIGjmiXhAcL7M8MgywNNtP9iIsi45WiOBmNQVYrBr3/37TSL6FFMfpFVuOxxVrNV fRKRx7VFihTyYxqacwBLAkNPQ6V4QiEdEt74DQFZsokgk1dcchP4GrSypNbrM4SX SJW0RwqF1t44mvuAHmt0U6otgzKy4XyjmDGvki6FNE8ww+OIEQX6tgRPSTD0bURn PyNtZ1EKYZguQt3b4pveVK8JMgWxuCcO9LgKFbPTZJ8YBYOTCU6WtTm4OfCdnTG7 1EtOv6c2k5nlOiK11K8M9ZPEkjq//6C0MZFn1CB7/43+tkWDTr/vSayW/6Yi8pF5 /C1vMZXz3MmpY/gj9z+W =mH1/ -----END PGP SIGNATURE-----

Re: The Heartbleed Challenge

#119
post #76

We will add a $10,000 bounty for the first published and confirmed successful completion of this challenge. Conditions: 1) CloudFlare confirms success. 2) The winner publishes their solution, including source, publicly. 3) Promptly send the link to the publication to [adam | ionicsecurity | com] (for tracking the order of submissions) Good luck!

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hello Adam! My email is public: fedor@indutny.com , and here is my proof of identity: https://keybase.io/indutny . If you wish - you could contact me via it. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJTSJ7IAAoJEPsOEJWxeXmZYnkP/1r9qVARb89x2bAteh9RPcRI VGUmRZVz/1wLqy/LmvB+XwgkEGRyjQBCa2vHPi8PpwenLEl8IXMMYyzQSqx94tkV y54ZTwABtXXcPIaFOu4O8sG8RM6rDVsF9FpJIC…

Nice work!

https://twitter.com/indutny/status/454773820822679552

Re: The Heartbleed Challenge

#120
post #119

Earlier quoted context omitted.

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hello Adam! My email is public: fedor@indutny.com , and here is my proof of identity: https://keybase.io/indutny . If you wish - you could contact me via it. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJTSJ7IAAoJEPsOEJWxeXmZYnkP/1r9qVARb89x2bAteh9RPcRI VGUmRZVz/1wLqy/LmvB+XwgkEGRyjQBCa2vHPi8PpwenLEl8IXMMYyzQSqx94tkV y54ZTwABtXXcPIaFOu4O8sG8RM6rDVsF9FpJIC…

Nice work! https://twitter.com/indutny/status/454773820822679552

Thank you!
Post reply on HN