# Heartbleed Openssl Bug

**URL:** https://forums.speedlife.net/t/heartbleed-openssl-bug/268950
**Category:** NYSpeed Off Topic
**Created:** [April 7, 2014, 5:26pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950 "2014-04-07T17:26:50Z")
**Posts on this page:** 11
**Page:** 5

<div class="post-metadata">

### Author: ![boxxa](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/boxxa/32/5045_2.png) [@boxxa](https://forums.speedlife.net/u/boxxa)
#### Post date: [April 12, 2014, 5:23pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/81 "2014-04-12T17:23:05Z")

</div>

> [@LZ](#):
>
> I guess that answers that - [https://www.cloudflarechallenge.com/heartbleed](https://www.cloudflarechallenge.com/heartbleed)
> 
> However the server was rebooted during testing

Ya fits our initial thought. I would find this attack very hard on a busy server.

---

<div class="post-metadata">

### Author: ![evane](https://avatars.discourse-cdn.com/v4/letter/e/6bbea6/32.png) [@evane](https://forums.speedlife.net/u/evane)
#### Post date: [April 15, 2014, 6:25am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/82 "2014-04-15T06:25:28Z")

</div>

OpenBSD is being well OpenBSD

> **[OpenBSD has started a massive strip-down and cleanup of OpenSSL | Lobsters](https://lobste.rs/s/3utipo/openbsd_has_started_a_massive_strip-down_and_cleanup_of_openssl)**
>
> 31 comments

---

<div class="post-metadata">

### Author: ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)
#### Post date: [April 15, 2014, 9:48am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/83 "2014-04-15T09:48:47Z")

</div>

no surprise on the OpenBSD stuff

Just saw this today (released yesterday):

> **[CloudFlare Challenge writeup](https://blog.erratasec.com/2014/04/cloudflare-challenge-writeup.html)**
>
> Last week, I made an embarrassing mistake. I misread the OpenSSL code and claimed getting the private-key would be unlikely. This was wrong ...

---

<div class="post-metadata">

### Author: ![boxxa](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/boxxa/32/5045_2.png) [@boxxa](https://forums.speedlife.net/u/boxxa)
#### Post date: [April 15, 2014, 1:24pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/84 "2014-04-15T13:24:20Z")

</div>

BSD is just forking OpenSSL, not really doing anything too ground breaking.

I am shocked there hasn’t bee another Java 0day out so people can move on.

---

<div class="post-metadata">

### Author: ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)
#### Post date: [April 15, 2014, 1:26pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/85 "2014-04-15T13:26:31Z")

</div>

Did you see some of the changes? They’re making some pretty radical changes to it. It’s not out of the ordinary for something like that to happen, but it’s interesting. They’ll regret it in the long run though. It’s a knee jerk reaction.

---

<div class="post-metadata">

### Author: ![boxxa](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/boxxa/32/5045_2.png) [@boxxa](https://forums.speedlife.net/u/boxxa)
#### Post date: [April 17, 2014, 10:40pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/86 "2014-04-17T22:40:38Z")

</div>

So the BSD project has gotten full effort now that they keep uncovering really scary items in OpenSSL. A basic understanding of code may help make some be more entertaining/scary.

> **[OpenSSL Valhalla Rampage](https://opensslrampage.org/)**
>
> Tearing apart OpenSSL, one arcane VMS hack at a time. Like what OpenBSD is doing to OpenSSL? Donate...

> “ **Remove non-posix support. Why is OPENSSL\_isservice even here? Is this a crypto library or a generic platform abstraction library? “A hack to make Visual C++ 5.0 work correctly” … time to upgrade.”** — tedu

---

<div class="post-metadata">

### Author: ![evane](https://avatars.discourse-cdn.com/v4/letter/e/6bbea6/32.png) [@evane](https://forums.speedlife.net/u/evane)
#### Post date: [April 18, 2014, 8:33pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/87 "2014-04-18T20:33:14Z")

</div>

Not a fork they are doing refactoring on steroids and it will a.) usefully improve openssl or b.) break openssl and be adandonware.

I fear much of what there doing won’t be useful for mainline inclusion since they are saying fuck-it to all the ports they don’t care about, which is classic Theo and OpenBSD behaviour.

---

<div class="post-metadata">

### Author: ![boxxa](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/boxxa/32/5045_2.png) [@boxxa](https://forums.speedlife.net/u/boxxa)
#### Post date: [April 19, 2014, 2:44pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/88 "2014-04-19T14:44:35Z")

</div>

> [@evane](#):
>
> Not a fork they are doing refactoring on steroids and it will a.) usefully improve openssl or b.) break openssl and be adandonware.
> 
> I fear much of what there doing won’t be useful for mainline inclusion since they are saying fuck-it to all the ports they don’t care about, which is classic Theo and OpenBSD behaviour.

It is nice to see that a FOSS project realized they need a full time dev and project management team for something that runs such a large part of the web. Hopefully what they start is a project that continues on.

---

<div class="post-metadata">

### Author: ![evane](https://avatars.discourse-cdn.com/v4/letter/e/6bbea6/32.png) [@evane](https://forums.speedlife.net/u/evane)
#### Post date: [April 23, 2014, 11:14am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/89 "2014-04-23T11:14:21Z")

</div>

Wells it official OpenBSD forked it…

> **[OpenSSL code beyond repair, claims creator of “LibreSSL” fork](https://arstechnica.com/information-technology/2014/04/openssl-code-beyond-repair-claims-creator-of-libressl-fork/)**
>
> OpenBSD developers "removed half of the OpenSSL source tree in a week."

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 30, 2014, 5:20am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/90 "2014-04-30T05:20:14Z")

</div>

> **[Fun with IDS funtime #3: heartbleed](https://blog.erratasec.com/2014/04/fun-with-ids-funtime-3-heartbleed.html?m=1)**
>
> I don't like the EmergingThreat rules, not so much because of the rules themselves but because of the mentality of the people who use them. ...

---

<div class="post-metadata">

### Author: ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)
#### Post date: [April 30, 2014, 6:19am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/91 "2014-04-30T06:19:24Z")

</div>

Great article :tup:

[Previous page](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950.md?page=4)
