Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Also see this explanation from Troy Hunt, which hasn't made the front page. https://news.ycombinator.com/item?id=7558597


TL, DR:

Troy Hunt: ”The Heartbleed bug itself was introduced in December 2011, in fact it appears to have been committed about an hour before New Year’s Eve (read into that what you will). The bug affects OpenSSL version 1.0.1 which was released in March 2012 through to 1.0.1f which hit on Jan 6 of this year. The unfortunate thing about this timing is that you’re only vulnerable if you’ve been doing “the right thing” and keeping your versions up to date! Then again, for those that believe you need to give new releases a little while to get the bugs out before adopting them, would they really have expected it to take more than two years? Probably not.”


Debian squeeze (oldstable) is not vulnerable, because it's still running 0.9.8o-4squeeze14.

0.9.8o was released 2010-06-01, almost 4 years ago!


http://patch-tracker.debian.org/package/openssl/0.9.8o-4sque...

It's had a lot of security fixes backported to it in the four years since the upstream release.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: