Upgrade to PRO for Only $50/Year—Limited-Time Offer! 🔥
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Heartbleed: why you should care
Search
C J Silverio
April 15, 2014
Technology
0
110
Heartbleed: why you should care
A discussion of the Heartbleed bug for a non-programming but computer-using audience.
C J Silverio
April 15, 2014
Tweet
Share
More Decks by C J Silverio
See All by C J Silverio
The economics of package management
ceejbot
4
1.6k
The future of (javascript) modules (in node)
ceejbot
1
300
Keeping JavaScript safe
ceejbot
3
460
ceej's how to solve it
ceejbot
6
770
work-life balance at npm
ceejbot
5
790
hash functions and you!
ceejbot
2
360
The accidental noder
ceejbot
2
160
Design Patterns & Modularity in the npm Registry
ceejbot
3
190
Monitoring on a budget
ceejbot
2
290
Other Decks in Technology
See All in Technology
2025-12-27 Claude CodeでPRレビュー対応を効率化する@機械学習社会実装勉強会第54回
nakamasato
4
1.1k
テストセンター受験、オンライン受験、どっちなんだい?
yama3133
0
170
Knowledge Work の AI Backend
kworkdev
PRO
0
270
SQLだけでマイグレーションしたい!
makki_d
0
1.2k
20251203_AIxIoTビジネス共創ラボ_第4回勉強会_BP山崎.pdf
iotcomjpadmin
0
140
会社紹介資料 / Sansan Company Profile
sansan33
PRO
11
390k
『君の名は』と聞く君の名は。 / Your name, you who asks for mine.
nttcom
1
120
Agent Skillsがハーネスの垣根を超える日
gotalab555
6
4.4k
Microsoft Agent Frameworkの可観測性
tomokusaba
1
110
子育てで想像してなかった「見えないダメージ」 / Unforeseen "hidden burdens" of raising children.
pauli
2
330
AI with TiDD
shiraji
1
300
特別捜査官等研修会
nomizone
0
580
Featured
See All Featured
sira's awesome portfolio website redesign presentation
elsirapls
0
91
RailsConf 2023
tenderlove
30
1.3k
Agile Leadership in an Agile Organization
kimpetersen
PRO
0
58
JavaScript: Past, Present, and Future - NDC Porto 2020
reverentgeek
52
5.8k
Visualization
eitanlees
150
16k
Technical Leadership for Architectural Decision Making
baasie
0
190
Practical Orchestrator
shlominoach
190
11k
ラッコキーワード サービス紹介資料
rakko
0
1.8M
[SF Ruby Conf 2025] Rails X
palkan
0
640
State of Search Keynote: SEO is Dead Long Live SEO
ryanjones
0
71
Raft: Consensus for Rubyists
vanstee
141
7.3k
SEO Brein meetup: CTRL+C is not how to scale international SEO
lindahogenes
0
2.2k
Transcript
Heartbleed why you should care
C J Silverio devops at npm @ceejbot
what's heartbleed?
security vulnerability disclosed April 7 2/3rds of all secure servers
OpenSSL the secure 's' in https://
heartbeat a pulse from a client to a server &
back
Alice ⇢ ping ⇢ Bob Alice ⇠ pong ⇠ Bob
Alice lies: “pong is 64K letters.”
Bob trusts her. He sends Alice too much data.
that data is the bleed in heartbleed
what leaked?
Everything. » your passwords » your cookies » server's passwords
» server's identifying certificates
Everything leaked. From 2/3rds of the servers on the internet.
How long did this leak exist?
Two years.
Everything leaked from 2/3rds of the servers on the internet
for two years.
None
How did this happen?
Rogue agency: the NSA? incompetence?
now what?
change your passwords
change your passwords for everything
yes, everything
Use a password manager 1Password https://getvau.lt
Toss your cookies
Turn on 2-factor auth
Recap
Heartbleed is as bad as it gets.
change passwords delete cookies 2-factor auth
donate to important open-source projects
Buy your operations staff a drink
change your passwords