Over at Vocativ, Eric Markowitz has a good piece on how a Finnish security firm discovered the Heartbleed bug that’s left vast numbers of Internet services utterly vulnerable for more than two years:
Before hanging up, Chartier instructed one of the Finnish engineers to write an exploit code to take advantage of Codenomicon‘s own site. Basically, Chartier wanted to see what, exactly, a hacker could get if they knew about the bug.
“We attacked ourselves,” Chartier says. The results freaked him out. The team realized they were able to access a user’s memory, encryption keys, usernames and passwords—”plus a lot of other stuff that we don’t want to mention,” Chartier says. “We saw how serious it was.”
An engineer at Codenomicon, the firm in question, found the bug at the same time as a Google researcher, an amazing coincidence considering that it was introduced back in March 2012.
The whole situation is chilling — not just because we don’t know who might have known about the bug and leveraged it to steal data, but also because it’s such a sobering reminder of how little we know about the software we depend on every day. There are other Heartbleeds out there; it’s just that nobody’s told us about them yet.
More Must-Reads from TIME
- Cybersecurity Experts Are Sounding the Alarm on DOGE
- Meet the 2025 Women of the Year
- The Harsh Truth About Disability Inclusion
- Why Do More Young Adults Have Cancer?
- Colman Domingo Leads With Radical Love
- How to Get Better at Doing Things Alone
- Michelle Zauner Stares Down the Darkness
Contact us at letters@time.com