Heartbleed Update
blogs.akamai.com
Heartbleed Update
1–10 of 14 posts
Re: Heartbleed Update
#2Re: Heartbleed Update
#3> No. And unfortunately, this isn't "No, we have evidence that there was no breach of data;" rather, "we have no evidence at all." We doubt many people do - and this leaves data holders in the uncomfortable position of not knowing what, if any, data breaches might have happened
I like their honesty - many organizations simply stated "our evidence suggests there was no breach"
Re: Heartbleed Update
#4Maybe Akamai should create a challenge just like Cloudflare did...
You ever try rotating 400 EV certs in a weekend? Neither have most Certificate Authorities. They say security is people, processes, technology. Our tech worked well---but not so well I can't wish it was better. Our people did awesome, stalwart work. But the PKI industry processes are due for some serious reconsideration.
I can't tell you how badly I want TACK or DANE or CT live and working right now.
Re: Heartbleed Update
#5Maybe Akamai should create a challenge just like Cloudflare did...
Re: Heartbleed Update
#6This whole thing has been one giant clusterfuck, I myself seen one rather larger alexa top 1000 site being exploited by sessions being hijacked.
Re: Heartbleed Update
#7Maybe Akamai and other large internet companies (Google, Facebook, Cloudflare etc) contribute now financially and/or with engineers towards openssl development or create an alternative. This whole thing has been one giant clusterfuck, I myself seen one rather larger alexa top 1000 site being exploited by sessions being hijacked.
I'm finalizing a tool to scan and visualize the top 1M alexa site URLs to see which are vulnerable - and ~3% (30 000) still are. In the last few days I've observed about ~5% of those getting patched daily (~1500).
Re: Heartbleed Update
#8Maybe Akamai and other large internet companies (Google, Facebook, Cloudflare etc) contribute now financially and/or with engineers towards openssl development or create an alternative. This whole thing has been one giant clusterfuck, I myself seen one rather larger alexa top 1000 site being exploited by sessions being hijacked.
The OpenSSL Foundation is trying to help people with those needs and needs varying on every imaginable dimension communicate with secrecy and strong authentication. We should expect them to need several times as many developers full time on that problem as any of the planetary-scale computing companies.
Re: Heartbleed Update
#9Re: Heartbleed Update
#10It seems interesting that Akamai protected itself from heartbleed by implementing a custom allocator, which was in some respects at least part of what caused heartbleed.