Tested to Work, Not Tested to Secure: Why Critical Crypto Bugs Hide for Years
Author(s):
Gurdeep Gill, Software Engineer Technical Leader, CISCO Systems
Heartbleed (CVE-2014-0160) lurked in OpenSSL for two years. These simple missing bounds check exposed private keys across hundreds of thousands of servers. OpenSSL had passed its tests. The encryption worked correctly. But