Stealing Private SSL Keys Using Heartbleed Difficult, Not Impossible

General News

Summary

Stealing private server SSL keys are a real pot at the end of a rainbow for criminal hackers and intelligence agencies alike. In the meantime, companies running the vulnerable version of OpenSSL in their infrastructure need to assess the risks involved, and then decide whether it’s worth their time and resources to revoke existing certs and reissue new ones. Incapsula, an application delivery company that offers a range of web security services, patched its infrastructure and is in the process of replace every certificate on behalf of its customers. “Different scenarios cause memory to shape the way it does; that’s why there’s the potential for the private key to be there.” If the heartbeat feature is enabled in OpenSSL, attacks against the Heartbleed vulnerability are undetectable, experts say. )” Adam Crain, a security researcher and founder of Automatak, cautioned that TLS is used in industrial control systems to wrap insecure protocols such as DNP3.

Classifications

industries
No industries detected
applications
No applications detected

AskAI Classifications

Labels
Software Development Protocol Libraries Embedded Systems

Linked Companies

Step Function I/O
up to $1M