Over at Vocativ, Eric Markowitz has a good piece on how a Finnish security firm discovered the Heartbleed bug that’s left vast numbers of Internet services utterly vulnerable for more than two years:
Before hanging up, Chartier instructed one of the Finnish engineers to write an exploit code to take advantage of Codenomicon‘s own site. Basically, Chartier wanted to see what, exactly, a hacker could get if they knew about the bug.
“We attacked ourselves,” Chartier says. The results freaked him out. The team realized they were able to access a user’s memory, encryption keys, usernames and passwords—”plus a lot of other stuff that we don’t want to mention,” Chartier says. “We saw how serious it was.”
An engineer at Codenomicon, the firm in question, found the bug at the same time as a Google researcher, an amazing coincidence considering that it was introduced back in March 2012.
The whole situation is chilling — not just because we don’t know who might have known about the bug and leveraged it to steal data, but also because it’s such a sobering reminder of how little we know about the software we depend on every day. There are other Heartbleeds out there; it’s just that nobody’s told us about them yet.
More Must-Reads from TIME
- Why Biden Dropped Out
- Ukraine’s Plan to Survive Trump
- The Rise of a New Kind of Parenting Guru
- The Chaos and Commotion of the RNC in Photos
- Why We All Have a Stake in Twisters’ Success
- 8 Eating Habits That Actually Improve Your Sleep
- Welcome to the Noah Lyles Olympics
- Get Our Paris Olympics Newsletter in Your Inbox
Contact us at letters@time.com