Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

Searching for The Prime Suspect: How Heartbleed Leaked Private Keys

Blog post from Cloudflare

Post Details
Company
Date Published
Author
John Graham-Cumming
Word Count
1,790
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

In April 2014, John Graham-Cumming revealed that Heartbleed could leak private SSL keys through its messages. The Heartbleed Challenge demonstrated this vulnerability within hours of launching. Most people who obtained the challenge server's private SSL key did so by searching for prime numbers in Heartbleed message results. OpenSSL was initially believed to cleanse memory of primes, but further investigation showed that it left copies of these numbers throughout its memory space. This made them vulnerable to Heartbleed attacks. To address this issue, patches were developed and submitted to the OpenSSL team, including one that cleanses memory before freeing it and another that prevents caching of Montgomery parameters. A more radical solution is not storing private keys within OpenSSL at all, which CloudFlare has been testing.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.