Rush to fight Heartbleed leads to errors with certificates and patches
Some reissued SSL certificates use the same vulnerable key as the ones they replace, and some sites moved to a vulnerable version of OpenSSL
IDG News Service - Despite taking prompt action to defend against the Heartbleed attack, some sites are no better off than before -- and in some cases, they are much worse off.
Many of the sites that patched vulnerable OpenSSL installations after the Heartbleed attack was revealed on April 7 then went on to revoke compromised SSL certificates and order new ones. But 30,000 sites are now using replacements based on the same compromised private key as the old certificate, according to a study by Internet services company Netcraft released Friday.
That means that anyone who managed to steal the private key of such a server before it was patched could still use the key to impersonate the server in a man-in-the-middle attack, even with the new certificate in place.
The error is a dangerous one, because the operators of vulnerable servers are likely to believe they have taken all the steps necessary to protect their users, Netcraft warned.
Around 57 percent of sites vulnerable to the Heartbleed attack have so far neither revoked nor reissued their SSL certificates, Netcraft said. A further 21 percent have reissued certificates but not revoked the compromised ones.
The 30,000 sites that revoked their certificates and reissued new ones with the same private key represent around 5 percent of vulnerable sites, according to Netcraft. An additional 2 percent are reusing the same private key and have yet to revoke their old certificates.
Those sites at least are no worse off than the day the Heartbleed attack was revealed.
That's not the case, though, for the roughly 20 percent of servers vulnerable today that were not vulnerable when the attack was revealed: Their operators appear to have replaced safe versions of OpenSSL with flawed ones, according to a study by software developer Yngve NysA|ter Pettersen.
"One possibility is that all the media attention led concerned system administrators into believing their system was unsecure. This, perhaps combined with administrative pressure and a need to 'do something', led them to upgrade an unaffected server to a newer, but still buggy version of the system, perhaps because the system variant had not yet been officially patched," he suggested.
NysA|ter Pettersen began scanning on April 11, and in the following two weeks around half the vulnerable servers he found were patched, bringing the proportion running vulnerable OpenSSL installations down from 5.36 percent to 2.77 percent. Since then, though, "Patching of vulnerable servers has almost completely stopped," with 2.33 percent still unpatched on Wednesday, he said.
Peter Sayer covers open source software, European intellectual property legislation and general technology breaking news for IDG News Service. Send comments and news tips to Peter at firstname.lastname@example.org.
- Why Open Source Software Isn't as Secure as You Think
- Heartbleed still matters, and we're all partly to blame
- The Next Heartbleed: 5 Security Vulnerabilities to Watch
- Security Manager's Journal: Dealing with the heartburn of Heartbleed
- Rush to fight Heartbleed leads to errors with certificates and patches
- Security Manager's Journal: With Heartbleed, suddenly the world is paying attention to security
- Kenneth van Wyk: Looking beyond Heartbleed
- Tip of the Hat: Heartbleed prompts chastened tech giants to fund OpenSSL
- Most but not all sites have fixed Heartbleed flaw
- 3 privacy violations you shouldn't worry about
- Deep Security +VMware vSphere with Operations Management Most midsize organizations are highly virtualized on VMware, and while this has produced significant savings, it also has created new challenges when it...
- 3 Questions to Ask Your DNS Host about Lowering DDoS Risks Neustar has had wide-ranging conversations with clients wanting to know how they can optimize protection as DDoS attacks increase in frequency and size.
- The Danger Deepens: 2014 Neustar Annual DDoS Attacks and Impact Report This report compares DDoS findings from 2013 to 2012, based on a survey of 440 North American companies, including 139 businesses delivering technology...
- DDoS Infographic: How Are Attacks Evolving? For the third consecutive year, Neustar surveyed businesses across major industries to track the evolution of DDoS attacks. Are they more frequent? Larger?...
- How to Use Crowd-Sourced Threat Intelligence to Stop Malware in its Tracks Threat sharing networks have been around for a long time, however they have typically been "invitation-only", available to only large companies, or those...
- An Incident Response Playbook: From Monitoring to Operations As cyber-attacks grow more sophisticated, many organizations are investing more into incident detection and response capabilities. In this webcast, learn how to develop... All Malware and Vulnerabilities White Papers | Webcasts