Website Security & Threat Management
Heartbleed Revisited

Heartbleed Revisited

3/27/2021 · Nick Sullivan

What this post added

This post revisits the Heartbleed vulnerability from 2014, highlighting how Cloudflare has incorporated its lessons into its security posture. It details advancements in TLS/SSL key protection and management, including Keyless SSL, Geo Key Manager, Keyless Everywhere, and Delegated Credentials, which provide defense-in-depth against key compromise. It also discusses improvements in certificate revocation mechanisms, such as OCSP stapling and OCSP Must-staple, to mitigate the impact of future key compromises. The post contrasts the security landscape of 2014 with the present, showcasing Cloudflare's continuous innovation in TLS/SSL security.

Read the original post ↗