image: marsmettnn tallahassee heartbleed & staying secure online · 2019. 8. 31. · what about...

Post on 19-Aug-2020

3 Views

Category:

Documents

0 Downloads

Preview:

Click to see full reader

TRANSCRIPT

What is the heartbleed bug?

• A bug in OpenSSL (server security software) heartbeat system

• Allows hackers to decrypt encrypted pages

• Affected SW in use for 2 years

• nobody knew, but maybe some hackers did?

• Left many major sites vulnerable for a few days

• hackers have exploited this

• As of 17th April 2014

• Top 1,000 sites: 0 sites vulnerable

• Top 10,000 sites: 53 sites vulnerable (only 0.53% vulnerable)

• Top 100,000 sites: 1595 sites vulnerable (1.5% still vulnerable)

• Top 1,000,000 sites: 20320 sites vulnerable (2% still vulnerable)

source: xkcd

source: xkcd

top related