Security is our top priority. In this blog, we discuss the HeartBleed OpenSSL vulnerability - and SigningHub's protection against it.
OpenSSL is one of the most commonly used toolkits to implement PKI services. It is free/open source, regularly updated and comes bundled with Linux. You can also install its binaries on Windows.
Although issues in the SSL protocol have been identified in the past, this time most OpenSSL implementations have a critical vulnerability.
Researchers in Codenomicon and Google found the vulnerability inside the OpenSSL implementation code - see this link for more details: CVE-2014-0160.
Once exploited, a threat agent can access sensitive information, including passwords and secure key information. OpenSSL has recently provided a patch to address this vulnerability.