0
A little-known company "Venafi" is suddenly in the news implying
75% of major systems are still vulnerable to Heartbleed. This deserves a rating of "liar liar pants on fire".
The issue isn't
patches but
certificates. Systems are patched, but while they were still vulnerable to Heartbleed, hackers may have stole the certificates. Therefore, the certificates need to be replaced. Not everyone has replaced their certificates, and those that have may have done so incorrectly (using the same keys, not revoking previous).
Thus, what the report is saying is that 75% haven't properly updated their certificates correctly. Naturally, they sell a solution for that problem.
However, even this claim isn't accurate. Only a small percentage of systems were vulnerable to Heartbleed in the first place, and it's hard to say which certificates actually needed to be replaced.
That's why you have the weasely marketing language above. It's not saying 3 out of 4 of
all systems, but
only those that were vulnerable to begin with (a minority). They aren't saying they are still vulnerable to Heartbleed itself, but only that they are vulnerable to breach -- due to the certificates having been stolen.
The entire report is so full of this
Continue reading