Live data from Hacker News

OpenSSL Heartbleed Security Update

blog.heroku.com

31–33 of 33 posts

Re: OpenSSL Heartbleed Security Update

#31

The one thing that might be of some small comfort to others is the fact that at least the NSA didn't know about this bug. If they had, there wouldn't be any talk of HTTPS being a barrier in their leaked presentations. That said, all of that encrypted traffic they've got stored up can now, thanks to this bug, be decrypted.

The bug was introduced in version 1.0.1, released 14 Mar 2012. Aren't most of Snowden's documents older than that? And we certainly don't know what the NSA has been doing since Snowden collected his files late 2012 / beginning 2013.

Re: OpenSSL Heartbleed Security Update

#32
post #29

Earlier quoted context omitted.

They did compartmentalize. They still do. That's why having an insider with sysadmin access and prestige for social engineering purposes is so dangerous.

Yeah. We should still take Rumsfeld's advice about what we don't know.

Sure, the advice is still as sound as it ever was.

So was the advice about going to war with the Army you had, not the one you'd wished you had.

Re: OpenSSL Heartbleed Security Update

#33
post #2

Loading an https://APPNAME.herokuapp.com page, I'm seeing a certificate (sn:"0E:3E:94:7F:C0:64:D7:4A:52:B1:38:D7:71:90:88:1F") with an "Issued Date" of "1/20/14"... which doesn't sound like it's been regenerated in the last 24 hours. Am I interpreting the certificate info wrong? [edit per official answer below: YES] (Are fresh certificates sometimes given much older start times? [edit: YES] ) This blogpost doesn't cl…

Several certificate vendors reissue certificates with the same "not valid before"/"issued" date as the original one.

Yep, I was just hassling our billing SaaS provider about this, but then I looked into their SSL vendor heartbleed post, and their customers mention this in the comments:

http://blog.digicert.com/2014/04/heartbleed-openssl-fix/

Excerpt: "Also, Busy IT Guy is right; it's a little disheartening to be listed as Unsafe after having done all the right things, just because the issue date didn’t get updated."

Post reply on HN