Heartbleed Disclosure Timeline Revealed
bennyboy64 (1437419) writes "Ever since the Heartbleed flaw in OpenSSL was made public there have been various questions about who knew what and when. The Sydney Morning Herald has done some analysis of public mailing lists and talked to those involved with disclosing the bug to get the bottom of it. The newspaper finds that Google discovered Heartbleed on or before March 21 and notified OpenSSL on April 1. Other key dates include Finnish security testing firm Codenomicon discovering the flaw independently of Google at 23:30 PDT, April 3. SuSE, Debian, FreeBSD and AltLinux all got a heads up from Red Hat about the flaw in the early hours of April 7 — a few hours before it was made public. Ubuntu, Gentoo and Chromium attempted to get a heads up by responding to an email with few details about it but didn't, as the guy at Red Hat sending the disclosure messages out in India went to bed. By the time he woke up, Codenomicon had reported the bug to OpenSSL."
> Google discovered Heartbleed on or before March 21 and notified OpenSSL on April 1. Other key dates include Finnish security testing firm Codenomicon discovering the flaw independently of Google at 23:30 PDT, April 2.
Doesn't it seem strange that the flaw has existed for a long, long time (years?) but Codenomicon happens to find it less than a day after Google notified OpenSSL, and, per the article, "some infrastructure providers under embargo"? That just seems... unlikely. Not impossible, but it kind of makes you wonder who is leaking information...
#include "standard_disclaimer.h"
Why did Google wait ten days before notifying OpenSSL? (even if they didn't trust OpenSSL to handle it responsibly, it couldn't have taken ten days for Google to patch their systems)
Disclaimer: I work for a company, but I don't speak for them.
Ubuntu, Gentoo and Chromium attempted to get a heads up by responding to an email with few details about it but didn't, as the guy at Red Hat sending the disclosure messages out in India went to bed.
I don't know why, but this reminded me of Cyril Evans. Never go to bed.
They exist; it's just that the vast majority of the people who belong to those eyes are really not qualified to be working on software that will be used in such important roles, and now we're paying the price. You don't use your Fisher Price tool set when you are building a real house. You just don't.
And you also see this same type of thing in proprietary software, where tons of losers are hired to work on the code, with predictably terrible results. The thing about open source is that anyone can see the source code, and people not part of the group that wrote the code can check it, so you at least have some chance of understanding what's going on.
Anyone who claims that open source advocates claim that open source is 100% immune from all flaws is just spewing forth straw men.
There are out there honeypot machines, which log all inbound and outbound packets.
They can run retrospective analysis of these packets to work out if undetected exploit probes have occurred.
Is anyone aware of this being done for heartbleed?
It would be interesting if - for example - it went from no exploits to most honeypots probed 3 months ago.
It's almost as though the GP knows this and is deliberately setting out to harm the company. Could this be some kind of troll?
OpenSSL is in use on Linux as well as on Windows. Chrome is in use on Windows, the Linux version is Chromium, which may or may not have the same issue.
He knows we are going to talk about how Microsoftie Howard Schmidt is chairman of the board of codenomicon.
Help stamp out iliturcy.
There's the trouble. Google's disclosure came on a day when nobody believes what they read on the Internet.
OpenSSL did not come from OpenBSD. So right from the start your theory is broken.
US Citizen living abroad? Register to vote!
Assuming he's referring to the speech to text exploit, the proof of concept works in Chromium as well. (http://guya.net/security/speech/)
I haven't tested the earlier mic keeps listening after enabled bug.