Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The most innocent explanation would be pure coincidence, or a coincidence slightly nudged by the fact the recent Apple/GnuTLS bugs are causing an industry-wide look-back at similar old under-reviewed open-source code.

A more sinister explanation would be that evidence of exploitation helped focus attention by each team once it touched them. However, a colleague of Neel Mehta implies that this was an audit-driven discovery without regard to active exploitation (https://news.ycombinator.com/item?id=7558015).

That could still leave the possibility that news of Mehta's discovery leaked, as either a vague hint or as enough info to create larger scans, which then helped tip off the Codenomicon group.

Despite all the reasons for secrecy, non-disclosure, and protection of proprietary methods, I hope each discoverer eventually says more about the steps leading up to discovery.



http://www.openssl.org/news/secadv_20040317.txt -> http://www.openssl.org/news/secadv_20080528.txt -> http://www.openssl.org/news/secadv_20120510.txt -> heartbleed ... a pattern emerges? At least for another one of the discoverers. :) Furthermore "Goto Fail;" is actually cited twice on the http://heartbleed.com and GnuTLS bug once.


Coincidence seems very unlikely, but the other explanations you suggest do seem plausible. Hopefully it's one of those, because otherwise given it's unlikely, it means it was most likely discovered earlier multiple times but not disclosed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: