Heartbleed bug still a threat after flawed patches
Rush to patch Heartbleed bug causes sites to make dangerous errors The majority of sites that attempted to protect themselves against Heartbleed have ended up no better for it, while some are actually more vulnerable than before. Following Heartbleed’s reveal on 7 April, sites scrambled to patch their OpenSSL installations and revoke their old certificates. Now, data from a study conducted by Netcraft shows that many sites haven’t done enough to fully protect themselves from the bug. Some 30,000 sites revoked their old certificates but did not replace their private keys, according…
Read More