Behind 'Heartbleed,' a terrifying new internet security problem
Thinkstock


Internet security experts are seriously concerned about an implementation problem with some versions of OpenSSL (a cryptographic library that powers Secure Sockets Layer or Transport Security Layer encryption). So what's OpenSSL? It's basically that little padlock symbol you see in your browser when visiting a secure website. And the problem with these secure sites is called "Heartbleed:"
Even if you've never heard of OpenSSL, it's probably a part of your life in one way or another — or, more likely, in many ways. The apps you use, the sites you visit; if they encrypt the data they send back and forth, there's a good chance they use OpenSSL to do it. The Apache web server that powers something like 50 percent of the internet's web sites, for example, utilizes OpenSSL.
Through a bug that security researchers have dubbed "Heartbleed," it seems that it's possible to trick almost any system running any version of OpenSSL from the past 2 years into revealing chunks of data sitting in its system memory.
Why that's bad: very, very sensitive data often sits in a server's system memory, including the keys it uses to encrypt and decrypt communication (read: usernames, passwords, credit cards, etc.) This means an attacker could quite feasibly get a server to spit out its secret keys, allowing them to read to any communication that they intercept like it wasn't encrypted it all. Armed with those keys, an attacker could also impersonate an otherwise secure site/server in a way that would fool many of your browser's built-in security checks. [TechCrunch]
This is a programming mistake, not a problem with the cryptography itself. Luckily, there are patches out already, and web companies are scrambling to bring their systems up to date. Here is more information, and here is a tool to test whether a server is vulnerable.
Subscribe to The Week
Escape your echo chamber. Get the facts behind the news, plus analysis from multiple perspectives.

Sign up for The Week's Free Newsletters
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
Sign up for Today's Best Articles in your inbox
A free daily email with the biggest news stories of the day – and the best features from TheWeek.com
Ryan Cooper is a national correspondent at TheWeek.com. His work has appeared in the Washington Monthly, The New Republic, and the Washington Post.
-
5 low approval cartoons about poll numbers
Cartoons Artists take on fake pollsters, shared disapproval, and more
-
Deepfakes and impostors: the brave new world of AI jobseeking
In The Spotlight More than 80% of large companies use AI in their hiring process, but increasingly job candidates are getting in on the act
-
Codeword: May 4, 2025
The Week's daily codeword puzzle
-
Shakespeare not an absent spouse, study proposes
speed read A letter fragment suggests that the Shakespeares lived together all along, says scholar Matthew Steggle
-
New Mexico to investigate death of Gene Hackman, wife
speed read The Oscar-winning actor and his wife Betsy Arakawa were found dead in their home with no signs of foul play
-
Giant schnauzer wins top prize at Westminster show
Speed Read Monty won best in show at the 149th Westminster Kennel Club dog show
-
Beyoncé, Kendrick Lamar take top Grammys
Speed Read Beyoncé took home album of the year for 'Cowboy Carter' and Kendrick Lamar's diss track 'Not Like Us' won five awards
-
The Louvre is giving 'Mona Lisa' her own room
Speed Read The world's most-visited art museum is getting a major renovation
-
Honda and Nissan in merger talks
Speed Read The companies are currently Japan's second and third-biggest automakers, respectively
-
Taylor Swift wraps up record-shattering Eras tour
Speed Read The pop star finally ended her long-running tour in Vancouver, Canada
-
Drake claims illegal boosting, defamation
Speed Read The rapper accused Universal Music of boosting Kendrick Lamar's diss track and said UMG allowed him to be falsely accused of pedophilia