The Bug: Heartbleed and OpenSSL
On Wednesday, the internet is patching a wound that has been open for two years, and the wound was in the very fabric of the web's security. Security researchers disclosed a critical flaw in OpenSSL, the encryption library that protects a large share of the world's secure websites, and the flaw allowed anyone to read the memory of a server, including the passwords, the session keys, and the private keys. The bug is the April 2014 story, and the story is the lesson: the security of the internet rests on software maintained by a handful of volunteers.
The Bug is the subject of this article: what Heartbleed is, how it works, why it went unnoticed for two years, and what it reveals about the invisible foundation of the digital world. The flaw was made public on Monday, April 7, and the patching has been running ever since. This is the story of the bug, and the story is about the moment the internet discovered that its immune system had a hole in it.
1. The Name
The name was chosen to make the flaw impossible to ignore, and the name worked. The researchers who found the bug called it Heartbleed, after the heartbeat extension in the OpenSSL protocol, the feature that keeps a connection alive by sending small pulses of data. The name was the brand, and the brand was the warning: the flaw was not an obscure edge case, and it was a hole in the heart of the web's encryption.
The name came with a logo, a red heart with a crack in it, and the logo was the packaging of the message. The security community had learned that a scary name and a memorable image made the world pay attention, and the world needed to pay attention to this one. The name was the hook, and the hook was the beginning of the story.
2. The Flaw
The flaw was a missing check, and the missing check was the whole bug. OpenSSL's heartbeat feature worked by sending a small message with a length field, and the receiving computer was supposed to check that the message actually contained that many bytes. The bug was that the check was missing: a cleverly crafted request could ask for more data than the message contained, and the server would respond with whatever was sitting in its memory next to the message, up to sixty four kilobytes at a time.
The sixty four kilobytes were the treasure. The memory of a server contained the secrets of the web: the passwords typed by users, the session cookies that kept people logged in, the private keys that proved a website was what it claimed to be. An attacker could read the memory again and again, and each read was a sip from the well. The flaw was the hole, and the hole was the access.
3. The Silence
The silence was the most frightening part of the story, and the silence was the two years. The bug had been introduced in December 2011, in a version of OpenSSL that had spread to a large share of the internet's secure servers. For two years, the flaw had been there, waiting, and no one had noticed, and the notices that came later showed that the flaw had been used in attacks before the disclosure.
The silence was also the lesson in the difficulty of seeing what is invisible. The code looked normal, the tests passed, the certificates were valid, and the encryption worked, right up until the moment it did not. The security of the system depended on a single line of code, and the line of code was wrong, and the wrongness had been invisible for two years. The silence was the patience of the bug, and the patience was the horror.
4. The Discovery
The discovery came from two directions at once, and the directions were the two worlds of security research. A researcher at Google, Neel Mehta, found the bug and reported it privately to the OpenSSL team, and researchers at the Finnish company Codenomicon found it independently, confirmed it, and built the proof of concept. The two teams coordinated the disclosure with the OpenSSL developers, and the fix was prepared before the world was told.
The discovery was the happy part of the story, and the happy part was the coordination. The researchers could have sold the bug, and they could have used it, and they chose the responsible path: tell the developers, prepare the fix, and disclose the flaw to the world with the fix ready. The discovery was the proof that the security community, for all its flaws, still worked for the good of the web.
5. The Panic
The panic was the reaction, and the reaction was the scale of the bug. The news hit the front pages, the security experts called it catastrophic, and the word was not exaggeration: the bug affected a large share of the world's secure servers, and every affected server had to be patched, and every affected server's certificates had to be reconsidered, and every user's passwords had to be reconsidered. The advice was to change the passwords, and the advice was the beginning of the work.
The panic was also the silence of the affected companies, and the silence was the problem. The websites could not tell the users exactly which servers were affected, and the uncertainty was the fear. The companies that had been running the vulnerable software for years had to check their systems, patch their servers, and decide whether to revoke their certificates. The panic was the price of the two years, and the price was paid in the days after the disclosure.
6. The Volunteers
The volunteers were the heart of the story, and the heart was the problem. OpenSSL was one of the most important pieces of software in the world, the encryption library that protected a large share of the web, and it was maintained by a tiny team of volunteers, funded by a trickle of donations. The researchers who found the bug noted that the project had received around two thousand dollars a year in donations, and the number became the symbol of the neglect.
The neglect was the structural weakness of the internet. The web was built on open source software, and the open source software was built by volunteers, and the volunteers were the unsung heroes who could not be everywhere at once. The bug was not the fault of the volunteers; the bug was the fault of a system that expected the most important software in the world to be maintained for free. The volunteers were the lesson, and the lesson was the funding.
7. The Lesson
The lesson of Heartbleed was about the invisible foundation of the digital world, and the foundation was the open source. The websites, the banks, the governments, the companies that the world trusted were all built on software that no one saw, and the software was maintained by a handful of people. The bug showed what happened when the foundation cracked, and the crack was in the most important software of all.
The lesson was also about the responsibility of the users of the foundation. The companies that ran the vulnerable servers had used the software for free, had never funded the project, had never audited the code, and had never noticed the flaw. The companies that depended on the foundation had a duty to the foundation, and the duty had been ignored for years. The lesson was the funding, and the funding was the future.
8. The Future
The future of the story would be the response, and the response would take years. The servers would be patched, the certificates would be reissued, the passwords would be changed, and the companies would move on, and the memory of the bug would fade. The future would also be the question that the bug raised: who pays for the software that the world runs on? The question would not be answered quickly, and the answer would shape the internet.
The future was also the lesson in the making. The bug had been open for two years, and the two years were the reminder that the security of the internet was a constant vigil, and the vigil was the work of the volunteers and the researchers. The Heartbleed logo would fade, and the lesson would remain. The bug is the April 2014 story, and the story is the lesson: the security of the internet rests on software maintained by a handful of volunteers, and the handful deserves more than a trickle. The heart bled, and the bleeding was the beginning of the healing. The companies that run the internet have a choice in the months ahead: keep taking the foundation for granted, or start paying for the work that holds the whole thing up. The bug was the invoice, and the invoice was the lesson. The volunteers will keep the watch, and the users of the foundation will decide whether the watch is funded. The engineers who maintain the open source are the invisible foundation of everything, and the foundation is the story. The bug was the invoice, and the invoice was the lesson: the software that the world runs on is the software that the world must fund. The volunteers will keep the watch, and the users of the foundation will decide whether the watch is funded, and the deciding is the future.
Tags
#engineering #technology
Comments
No comments yet. Be the first!
Leave a comment