← Blog

The Heartbleed Weakness

An exchange about a security assumption that seemed too obvious to question.

X: the heartbleed weakness

X: you know, its pretty well known in openssl community

X: but nobody gave a try to seek the memory registers using handshake signals

X: because everybody (just like me) would have thought that its obviously blocked

Y: obviously not