/plushcap/analysis/cloudflare/certificate-revocation-and-heartbleed

Certificate Revocation and Heartbleed

What's this blog post about?

The CloudFlare Heartbleed Challenge has been solved, and the private key for cloudflarechallenge.com was obtained by several authorized attackers using the Heartbleed exploit. Private key holders can impersonate the site, as demonstrated by Fedor Indutny. Although the certificate has been revoked, the site remains active to test browser behavior when encountering expired certificates. Internet Explorer and Safari give warnings but allow users to proceed; Firefox denies access, while Chrome allows loading without warning due to disabled online verification. Certificate revocation rates have increased since Heartbleed's discovery, with more websites evaluating the risk of stolen private keys.

Company
Cloudflare

Date published
April 12, 2014

Author(s)
Nick Sullivan

Word count
294

Hacker News points
None found.

Language
English


By Matt Makai. 2021-2024.