Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This would be a more compelling rebuttal to Willem's post if Akamai hadn't confirmed his central thesis:

https://blogs.akamai.com/2014/04/heartbleed-update-v3.html



> As a result, we have begin the process of rotating all customer SSL keys/certificates.

AGHHHHHHH! Even if their code was likely to have worked perfectly, this is a huge mistake. And I mean huge. They should've operated under the assumption that their defense didn't work and immediately rotated all keys. Period.


They used their patch for some length of time, release it to the community and a few hours later a bug is spotted and fixed. Peer review is a good thing.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: