Website Security & Threat Management
Answering the Critical Question: Can You Get Private SSL Keys Using Heartbleed?

Answering the Critical Question: Can You Get Private SSL Keys Using Heartbleed?

4/11/2014 · Nick Sullivan

What this post added

This post details the discovery and impact of the Heartbleed vulnerability, a critical bug in OpenSSL that could potentially expose server memory, including private SSL keys. Cloudflare's engineers investigated the exploit's ability to extract private keys, initially believing it to be impossible due to their specific NGINX and OpenSSL configurations. They launched a public challenge to test this hypothesis and, upon confirmation that private keys could indeed be extracted, initiated a mass reissue and revocation of customer SSL keys. The post also provides a technical explanation of the Heartbleed bug and how memory allocation on the heap can influence the exploit's effectiveness.

Read the original post ↗