OpenSSL Security Proves Many Eyes Approach | Internet News

OpenSSL Security Proves Many Eyes Approach

Jun 9, 2014
1 minute read

The lessons of Heartbleed have been learned well. The open-source OpenSSL Project disclosed and patched seven security updates on June 5, and the process was markedly different from the activity that led up to the disclosure of the Heartbleed flaw in April.

One thing that has changed for OpenSSL since Heartbleed surfaced is that there is money on the table to find and fix flaws. HP’s ZDI pays security researchers for their vulnerability disclosures.

The Linux Foundation’s Core Infrastructure Initiative (CII) now has $5.4 million in funding raised in response to Heartbleed. CII is funding efforts, including OpenSSL, to help improve security. One of the CII-funded initiatives is an audit of OpenSSL by the Open Crypto Audit Project (OCAP), which has only just begun.

In the post-Heartbleed era, there will be more OpenSSL security updates, and that’s a good thing. Open-source security isn’t about pretending we live in a world without vulnerabilities; it’s about finding the vulnerabilities that exist and fixing them in a responsible manner, just like OpenSSL is now doing.

Read the full story at eWEEK:
New OpenSSL Flaws Aren’t a Heartbleed Repeat

Sean Michael Kerner is a senior editor at InternetNews.com. Follow him on Twitter @TechJournalist.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.