Behind 'Heartbleed,' a terrifying new internet security problem
Thinkstock


Internet security experts are seriously concerned about an implementation problem with some versions of OpenSSL (a cryptographic library that powers Secure Sockets Layer or Transport Security Layer encryption). So what's OpenSSL? It's basically that little padlock symbol you see in your browser when visiting a secure website. And the problem with these secure sites is called "Heartbleed:"
Even if you've never heard of OpenSSL, it's probably a part of your life in one way or another — or, more likely, in many ways. The apps you use, the sites you visit; if they encrypt the data they send back and forth, there's a good chance they use OpenSSL to do it. The Apache web server that powers something like 50 percent of the internet's web sites, for example, utilizes OpenSSL.
Through a bug that security researchers have dubbed "Heartbleed," it seems that it's possible to trick almost any system running any version of OpenSSL from the past 2 years into revealing chunks of data sitting in its system memory.
Why that's bad: very, very sensitive data often sits in a server's system memory, including the keys it uses to encrypt and decrypt communication (read: usernames, passwords, credit cards, etc.) This means an attacker could quite feasibly get a server to spit out its secret keys, allowing them to read to any communication that they intercept like it wasn't encrypted it all. Armed with those keys, an attacker could also impersonate an otherwise secure site/server in a way that would fool many of your browser's built-in security checks. [TechCrunch]
This is a programming mistake, not a problem with the cryptography itself. Luckily, there are patches out already, and web companies are scrambling to bring their systems up to date. Here is more information, and here is a tool to test whether a server is vulnerable.
A free daily email with the biggest news stories of the day – and the best features from TheWeek.com
Subscribe to The Week
Escape your echo chamber. Get the facts behind the news, plus analysis from multiple perspectives.

Sign up for The Week's Free Newsletters
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
Ryan Cooper is a national correspondent at TheWeek.com. His work has appeared in the Washington Monthly, The New Republic, and the Washington Post.
-
Florida erases rainbow crosswalk at Pulse nightclub
Speed Read The colorful crosswalk was outside the former LGBTQ nightclub where 49 people were killed in a 2016 shooting
-
Trump says Smithsonian too focused on slavery's ills
Speed Read The president would prefer the museum to highlight 'success,' 'brightness' and 'the future'
-
Trump to host Kennedy Honors for Kiss, Stallone
Speed Read Actor Sylvester Stallone and the glam-rock band Kiss were among those named as this year's inductees
-
White House seeks to bend Smithsonian to Trump's view
Speed Read The Smithsonian Institution's 21 museums are under review to ensure their content aligns with the president's interpretation of American history
-
Charlamagne Tha God irks Trump with Epstein talk
Speed Read The radio host said the Jeffrey Epstein scandal could help 'traditional conservatives' take back the Republican Party
-
CBS cancels Colbert's 'Late Show'
Speed Read 'The Late Show with Stephen Colbert' is ending next year
-
Shakespeare not an absent spouse, study proposes
speed read A letter fragment suggests that the Shakespeares lived together all along, says scholar Matthew Steggle
-
New Mexico to investigate death of Gene Hackman, wife
speed read The Oscar-winning actor and his wife Betsy Arakawa were found dead in their home with no signs of foul play