Presentation: The Most Secure Program Is One That Doesn’t Exist

Transcript On April 7th, 2014, OpenSSL released version 1.0.1.g which fixed a buffer overread vulnerability that had been introduced accidentally two years earlier. This was a result of a missing bounds check in the TLS heartbeat extension, which allowed attackers to read arbitrary memory, memory that could contain passwords, it could contain private keys, maybe some social security numbers.

Read full news article on InfoQ