flawopen.com/インシデント/Heartbleed
オフィスの同僚に「『ネコ』とオウム返しして。長さは2文字」と頼むと、同僚は「ネコ」と返します。次に「『ネコ』とオウム返しして。長さは6万文字」と頼むと、同僚は長さの矛盾を確かめず、「ネコ」に続けて机の上にある他人のパスワードや秘密メモをそのまま読み上げます。
The fix is two comparisons. That ratio — a two-line check against a two-year, internet-wide exposure — is the reason Heartbleed became the standard illustration of how little code stands between working software and catastrophic failure.
Patching OpenSSL was the easy part. The hard part followed from a property of the bug: because it was silent and untraceable, no operator could prove they had not been exploited. With no logs to examine, the only defensible assumption was that every secret resident in the process memory during the exposure window had leaked.
That meant regenerating private keys, reissuing and revoking certificates at a scale the certificate authority ecosystem had never handled at once, invalidating every session, and prompting global password resets. Deployments without forward secrecy were worse off again: an attacker who had recorded encrypted traffic earlier could decrypt it retroactively once they held the key.
memcpy is a valid program. This is the argument for memory-safe languages in parsing code specifically, where untrusted input meets manual buffer handling.An overflow writes past a boundary, corrupting adjacent memory and often enabling code execution. An over-read only reads past it. Heartbleed never corrupted anything — it simply handed the attacker memory contents, which in this case was more than sufficient.
Yes. It was not guaranteed on any given request, but private key material can reside in the same heap. Repeated requests sampling different memory made recovery practical, and it was demonstrated publicly.