Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It is impossible to prevent the next heartbleed, no one can predict the future.

Even though everything in the article is important and true: You need to take preventive measures into account when building your solutions! You need to make sure that you have security by design in your products, and that you have to learn from disasters etc etc etc..

But you also need to make disaster recovery plans! You need to know what actions to take when the shit hits the fan!



> It is impossible to prevent the next heartbleed, no one can predict the future.

I think that's a little strong. Verify code using theorem provers and such vulnerabilities are all but impossible.

But yes, prepare for the worst anyway.


Then the next heartbleed could be a sidechannel not covered in your theorem. Better prepare in any case.


Side channels are indeed a tough problem, but if all we have to worry about is side channel attacks, we'd be in a pretty good place overall. We're nowhere near that right now.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: