The bug was two years old before anyone outside the code noticed it. Robin Seggelmann's implementation of the TLS heartbeat extension entered the OpenSSL repository on 31 December 2011, was reviewed by Stephen N. Henson, and shipped in OpenSSL 1.0.1 on 14 March 2012. It missed a check on a length field the other party supplied. A machine asked to echo back a heartbeat of an announced size returned that many bytes whether the request contained them or not, filling the difference from whatever lay next in memory — up to 64 kibibytes per heartbeat, and with no total limit, because an attacker could simply ask again. Neel Mehta of Google Security reported it to the OpenSSL team on 1 April 2014; engineers at Codenomicon in Finland found it independently two days later.
What made 7 April unlike other coordinated disclosures was the packaging. OpenSSL released version 1.0.1g and an advisory; Codenomicon released heartbleed.com, a plain-language explanation, the name Heartbleed and a bleeding-heart logo drawn by the Finnish designer Leena Kurjenniska. It was the first vulnerability presented to the public the way a product is launched, and the presentation worked. US-CERT issued its alert on 8 April, listing OpenSSL 1.0.1 through 1.0.1f as affected and telling administrators to treat any key generated on vulnerable software as compromised. Netcraft put roughly half a million secure web servers at risk, about seventeen per cent of those it surveyed. Yahoo, Imgur, Stack Overflow, Slate and DuckDuckGo were among the names identified as vulnerable that first day.
The consequences that could be counted were specific. The Canada Revenue Agency cut public access to its online services, electronic filing included, late on 8 April, mid-season, and pushed the filing deadline from 30 April to 5 May; about 900 social insurance numbers, it said on 14 April, had been removed in a six-hour window that day. On 16 April the RCMP announced charges against Stephen Arthuro Solis-Reyes, 19, of London, Ontario — unauthorised use of a computer and mischief in relation to data — saying it believed he had extracted private information held by the agency by exploiting the bug. In Britain, Mumsnet found in the days after the disclosure that it was affected, closed the hole and reset the passwords on all 1.5 million registered accounts; its founder, Justine Roberts, said on 14 April that the worst case was that every account had been read.
Two arguments ran through the rest of the month. The first was whether private keys could be pulled out. CloudFlare published on 11 April saying it had been unable to retrieve key material, and put up a vulnerable server as a challenge; later the same day it wrote that it had been wrong. Fedor Indutny had used at least 2.5 million requests, Ilkka Mattila of Finland's NCSC-FI about a hundred thousand. Reissue and revoke became the instruction, and it was not free: Cloudflare reckoned on 17 April that its own mass revocation had added some $400,000 a month to GlobalSign's bandwidth bill. The second was the NSA, which Bloomberg reported on 11 April, citing two unnamed sources, had known of the flaw for two years and used it. The agency and the White House denied it; no document has settled it since.
The day after, the patches stopped
Extended support for Windows XP ended on 8 April 2014, more than twelve years after the operating system shipped and one day after Heartbleed — a coincidence of calendars that put two very different kinds of unmaintained code in the same week's news. The consequence arrived quickly. On 26 April Microsoft issued a security advisory for CVE-2014-1776, a use-after-free flaw in Internet Explorer 6 through 11; FireEye, which had found it, said it was already being used in targeted attacks against Internet Explorer 9 to 11 in a campaign the firm called Operation Clandestine Fox, chaining a Flash technique to defeat address-space randomisation and data-execution prevention. US-CERT advised the Enhanced Mitigation Experience Toolkit or another browser until a fix existed. Microsoft shipped one on 1 May and included Windows XP, three weeks after patches for it were supposed to have stopped — the first of three such exceptions, the others being the WannaCry outbreak of May 2017 and a Remote Desktop flaw in May 2019.
Three million cards and a spike in spam
The ordinary breaches of April were drowned out. On 17 April Michaels, the American craft-store chain, confirmed that about three million payment cards had been exposed in two separate intrusions: roughly 2.6 million at Michaels stores between 8 May 2013 and 27 January 2014, and about 400,000 at its Aaron Brothers subsidiary between 26 June 2013 and 27 February 2014, with 54 Aaron Brothers locations confirmed affected. Card numbers and expiry dates were taken, on approximately seven per cent of the cards used in the affected stores during those windows; two security firms engaged by the company said the malware had not been encountered before. Eleven days later, on 28 April, AOL confirmed "unauthorized access to information regarding a significant number of user accounts" — email addresses, postal addresses, address books, encrypted passwords, encrypted answers to password-reset questions and some employee information. It had found the intrusion by noticing a surge of spoofed mail appearing to come from about two per cent of AOL Mail accounts. The company never published a total.
An advisory, and a hundred thousand cash machines
India's Heartbleed was an advisory rather than an incident. CERT-In issued a warning describing the improper bounds checking in the handling of TLS and DTLS heartbeat packets and the remote reading of memory it allowed. Its director general, Gulshan Rai — who would move to the Prime Minister's Office the following year as the country's first national cyber security coordinator — said the team had also written to large users and other organisations about the steps to be followed to mitigate the risk. By the third week of April no compromise had been reported in the country. Indian government websites turned out to be less exposed than most, for an unflattering reason: departments had been sluggish about updating their certificates and their software, and that is what kept the risk comparatively low.
The other April deadline mattered more here. Well over a lakh cash machines were operating in India, many of them on Windows XP, and the Reserve Bank had warned in March that banking and ATM services might be affected once Microsoft's support ended on 8 April; the Indian Banks' Association's chief executive, M V Tanksale, said only older machines were likely to have trouble. Neither problem was solved quickly. About 60 per cent of the country's 220,000 ATMs were still running XP as late as May 2017, and in January 2017 Shodan counted roughly 5,800 services in India still answering the heartbeat request — eighth in the world. All of it ran alongside a general election whose polling opened on 7 April. The duty to say what had been lost, and how fast, came much later — with CERT-In's six-hour direction of 2022 and the DPDP Act of 2023.
Cortana, in beta, in one country
Microsoft opened its Build conference in San Francisco on 2 April 2014, two months into Satya Nadella's tenure as chief executive, and used the opening keynote to introduce Cortana, a voice assistant built on Bing and named for a character in Halo. It shipped inside Windows Phone 8.1 in beta, and only where a handset's region was set to the United States; Britain and China were promised for the second half of the year, and the finished code reached the Preview for Developers programme on 14 April, the first chance for anyone outside Redmond to wire an application into it. On 7 April Vicarious, a Californian firm attempting to model the neocortex in software, said Jeff Bezos, Jerry Yang, Janus Friis and Marc Benioff had joined a funding round it declined to size. On 28 April bioengineers at Stanford described Neurogrid, sixteen custom chips on a tablet-sized board simulating a million neurons on a fraction of a computer's power. Microsoft deprecated the Cortana app in 2023, its place in Windows taken by Copilot; Alphabet absorbed Vicarious in 2022.
Two hundred million, spent on the endpoint
Palo Alto Networks completed its purchase of Cyvera on 10 April 2014, roughly $200 million for a Tel Aviv company of fifty-five people whose product blocked exploits on the endpoint rather than recognising malware after the event — an unusual purchase for a firm that sold firewalls. The technology shipped that September as Traps and was folded into Cortex XDR five years later. Two days before the deal closed, Symantec published the nineteenth volume of its Internet Security Threat Report, describing 2013 as "the year of the mega data breach": data breaches up 62 per cent, more than 552 million identities exposed, eight incidents of more than ten million identities each, targeted attacks up 91 per cent, ransomware up 500 per cent and twenty-three zero-day vulnerabilities. Verizon's annual breach report followed at the end of the month, sorting a decade of incidents into nine recurring patterns. Broadcom bought Symantec's enterprise business, and its brand, in 2019.
⏳ Time capsule — April 2014
- On 1 April an earthquake of magnitude 8.2 struck off the coast of northern Chile, prompting tsunami warnings; a magnitude 7.7 aftershock followed on 2 April, after which President Michelle Bachelet declared the north of the country a disaster zone.
- On 7 April polling opened in India's general election, the first of nine phases running to 12 May, with 834,082,814 registered voters; turnout reached 66.44 per cent and results were declared on 16 May.
- On 15 April a total lunar eclipse of umbral magnitude 1.2918 was visible across much of the Western Hemisphere, totality lasting one hour and eighteen minutes — the first of a tetrad of four consecutive total eclipses.
- On 16 April the South Korean ferry Sewol capsized off the country's south-west coast with 476 people aboard; 304 died, most of them pupils and teachers from a single high school in Ansan.
A patch is not a fix
Twelve years on, the technical ending is the least flattering part. Patching the library was the easy half; replacing the keys and certificates exposed while it ran was the half that dragged. About 30,000 of more than half a million affected certificates had been reissued by 11 April 2014, and by 9 May only 43 per cent of affected sites had reissued at all. The tail runs much longer. Shodan counted 199,594 services still answering a heartbeat request in January 2017, and about 75,000 of those were also running Linux 3.x behind expired certificates. The first large breach publicly attributed to the bug did not arrive until August 2014 — four months after every administrator in the world had been told what to do.
The other ending was about money, and it is the one this archive keeps returning to. In April 2014 the library carrying a substantial share of the world's encrypted traffic was maintained by a handful of volunteers, only one of them full-time, on donations of roughly $2,000 a year. On 24 April the Linux Foundation announced the Core Infrastructure Initiative: thirteen companies, among them Amazon Web Services, Facebook, Google, IBM, Intel and Microsoft, pledging $100,000 a year each for three years, with OpenSSL among the first projects funded and two full-time core developers paid for. The initiative was later superseded by the Open Source Security Foundation. The argument it was founded to settle has not been settled; the archive replays it at December 2021 and again at March 2024.