/plushcap/analysis/cloudflare/the-heartbleed-aftermath-all-cloudflare-certificates-revoked-and-reissued

The Heartbleed Aftermath: all CloudFlare certificates revoked and reissued

What's this blog post about?

On April 17, 2014, Nick Sullivan discussed the Heartbleed vulnerability and its impact on CloudFlare. The company issued a challenge to find out if their private keys were at risk due to this bug. After revoking and reissuing all SSL certificates they manage, they concluded that within two hours a dedicated attacker could retrieve a private key from a vulnerable server. They recommend administrators running servers using vulnerable versions of OpenSSL to patch the software and reissue and revoke all their private keys.

Company
Cloudflare

Date published
April 17, 2014

Author(s)
Nick Sullivan

Word count
1478

Hacker News points
None found.

Language
English


By Matt Makai. 2021-2024.