Rush to fight Heartbleed leads to errors with certificates and patches
Some reissued SSL certificates use the same vulnerable key as the ones they replace, and some sites moved to a vulnerable version of OpenSSL
IDG News Service - Despite taking prompt action to defend against the Heartbleed attack, some sites are no better off than before -- and in some cases, they are much worse off.
Many of the sites that patched vulnerable OpenSSL installations after the Heartbleed attack was revealed on April 7 then went on to revoke compromised SSL certificates and order new ones. But 30,000 sites are now using replacements based on the same compromised private key as the old certificate, according to a study by Internet services company Netcraft released Friday.
That means that anyone who managed to steal the private key of such a server before it was patched could still use the key to impersonate the server in a man-in-the-middle attack, even with the new certificate in place.
The error is a dangerous one, because the operators of vulnerable servers are likely to believe they have taken all the steps necessary to protect their users, Netcraft warned.
Around 57 percent of sites vulnerable to the Heartbleed attack have so far neither revoked nor reissued their SSL certificates, Netcraft said. A further 21 percent have reissued certificates but not revoked the compromised ones.
The 30,000 sites that revoked their certificates and reissued new ones with the same private key represent around 5 percent of vulnerable sites, according to Netcraft. An additional 2 percent are reusing the same private key and have yet to revoke their old certificates.
Those sites at least are no worse off than the day the Heartbleed attack was revealed.
That's not the case, though, for the roughly 20 percent of servers vulnerable today that were not vulnerable when the attack was revealed: Their operators appear to have replaced safe versions of OpenSSL with flawed ones, according to a study by software developer Yngve NysA|ter Pettersen.
"One possibility is that all the media attention led concerned system administrators into believing their system was unsecure. This, perhaps combined with administrative pressure and a need to 'do something', led them to upgrade an unaffected server to a newer, but still buggy version of the system, perhaps because the system variant had not yet been officially patched," he suggested.
NysA|ter Pettersen began scanning on April 11, and in the following two weeks around half the vulnerable servers he found were patched, bringing the proportion running vulnerable OpenSSL installations down from 5.36 percent to 2.77 percent. Since then, though, "Patching of vulnerable servers has almost completely stopped," with 2.33 percent still unpatched on Wednesday, he said.
Peter Sayer covers open source software, European intellectual property legislation and general technology breaking news for IDG News Service. Send comments and news tips to Peter at firstname.lastname@example.org.
- Why Open Source Software Isn't as Secure as You Think
- Heartbleed still matters, and we're all partly to blame
- The Next Heartbleed: 5 Security Vulnerabilities to Watch
- Security Manager's Journal: Dealing with the heartburn of Heartbleed
- Rush to fight Heartbleed leads to errors with certificates and patches
- Security Manager's Journal: With Heartbleed, suddenly the world is paying attention to security
- Kenneth van Wyk: Looking beyond Heartbleed
- Tip of the Hat: Heartbleed prompts chastened tech giants to fund OpenSSL
- Most but not all sites have fixed Heartbleed flaw
- 3 privacy violations you shouldn't worry about
- Who's Spying on You? You're aware of the threats of malware to your business but what about the ever-changing ground rules? Cybercriminals today are launching attacks against...
- The Business Value of Continuous Delivery Download this whitepaper to learn more about the business value of Continuous Delivery and see why it could be a game changer for...
- Ten Factors Shaping the Future of Application Delivery Download this research report conducted by Enterprise Management Associates (EMA) to learn how those that are seeking to accelerate application delivery are leveraging...
- Software Asset Management: Ensuring Today's Assets Today's trends like BYOD and SaaS are new and exciting in terms of how they will help make our jobs more productive but...
- On-demand webinar - 7 Keys to Service Catalog Implementation Success Watch this webinar to learn 7 crucial keys to make your service catalog a success!
- Transform Your IT Service Management Watch this webinar, to learn how EasyVista can increase IT productivity & efficiency and deliver streamlined & integrated IT Service & Asset Mgmt. All Malware and Vulnerabilities White Papers | Webcasts