SlideShare ist ein Scribd-Unternehmen logo
1 von 2
Downloaden Sie, um offline zu lesen
90% of Impacted Cloud Providers Still Haven’t Updated Certificates 
1 Week After Heartbleed 
As we’ve reported, hundreds of cloud providers were vulnerable to the Heartbleed 
bug in OpenSSL even days after the vulnerability was widely publicized. Looking at 
the latest data pulled this morning, much progress has been made and there are only 
42 Cloud Security services that are vulnerable to Heartbleed. For these services, 
user data, passwords, and private keys for these services can be stolen using a simple 
exploit. 
However, more alarming today is the number of cloud services that have not fully 
addressed their past vulnerability. After patching SSL, the next step cloud providers 
must take is to reissue their certificates. As reported by CloudFlare, Heartbleed can be 
used by an attacker to access private keys and impersonate a website. Since 
Heartbleed exploits don’t leave a trace in server logs, cloud providers must assume 
their private keys have been compromised even if they don’t have any evidence of 
them being stolen. 
Certificate updates trail Heartbleed patching 
Most websites have patched SSL but they are reissuing and revoking certificates at a 
much slower pace. Netcraft reported that only 30,000 websites (out of more than 
500,000) reissued new certificates by the end of last week, and even fewer have 
revoked their certificates. While not completely eliminating the risk of a 
man-in-the-middle attack (MITM) this is a critical step in reducing the risk of these 
attacks. 
Skyhigh is tracking certificate updates across cloud providers and as of this morning 
only 13.3% of Cloud Security service providers affected by Heartbleed have updated 
their certificates. A smaller percentage have both reissued and revoked their 
certificates, making them vulnerable to impersonation in a phishing scam or 
man-in-the-middle attack. Most certificate authorities have agreed to replace 
certificates for free, but there are complaints they aren’t prepared for the volume of 
certificates that need to be reissued.
Already we’re seeing that Heartbleed has exposed not just a vulnerability in SSL but 
vulnerabilities in the way we approach security. According to security researcher 
Bruce Schneier: 
“We’ve learned how hard the human aspects of a security system are to coordinate. 
We’re learning that we don’t have the infrastructure necessary to quickly revoke 
millions of certificates and issue new ones. We’re learning that some of our critical 
open-source software is maintained by volunteers who have busy lives, and that often 
no one else is evaluating that software’s security. We’re learning how complicated the 
process of disclosing a vulnerability of this magnitude is.” 
Cleaning up and determining your exposure 
Aside from critical infrastructure your company uses, corporate IT departments are 
being asked to quantify their exposure. With over 96% of companies using cloud 
services impacted by Heartbleed, the chances that your sensitive data was vulnerable 
is extremely high. Skyhigh has already provided our customers with the cloud 
security services they use that were impacted, and we’re extending those audits to 
any company for free. 
Author : 
Lauren Ellis is a research analyst covering the technology industry’s top trends & 
topics, focusing on Cloud Security, Cloud Computing, Data Loss Prevention etc.,

Weitere ähnliche Inhalte

Andere mochten auch

93e23 msi ms-7101_rev_2b_sch
93e23 msi ms-7101_rev_2b_sch93e23 msi ms-7101_rev_2b_sch
93e23 msi ms-7101_rev_2b_schDomingo Arroyo
 
90010 - MINI VINTAGE FRAME
90010 - MINI VINTAGE FRAME90010 - MINI VINTAGE FRAME
90010 - MINI VINTAGE FRAMEEmma Lawson
 
Изделие 9П148 Инструкция По Эксплуатации
Изделие 9П148 Инструкция По ЭксплуатацииИзделие 9П148 Инструкция По Эксплуатации
Изделие 9П148 Инструкция По ЭксплуатацииRimsky Cheng
 
Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...
Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...
Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...Notis Mitarachi
 
94721 633594523450156250
94721 63359452345015625094721 633594523450156250
94721 633594523450156250rjcai
 

Andere mochten auch (9)

93e23 msi ms-7101_rev_2b_sch
93e23 msi ms-7101_rev_2b_sch93e23 msi ms-7101_rev_2b_sch
93e23 msi ms-7101_rev_2b_sch
 
9 22 Ss2
9 22 Ss29 22 Ss2
9 22 Ss2
 
Food labelling and advertising
Food labelling and advertisingFood labelling and advertising
Food labelling and advertising
 
90010 - MINI VINTAGE FRAME
90010 - MINI VINTAGE FRAME90010 - MINI VINTAGE FRAME
90010 - MINI VINTAGE FRAME
 
Изделие 9П148 Инструкция По Эксплуатации
Изделие 9П148 Инструкция По ЭксплуатацииИзделие 9П148 Инструкция По Эксплуатации
Изделие 9П148 Инструкция По Эксплуатации
 
9/11 incident
9/11 incident9/11 incident
9/11 incident
 
Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...
Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...
Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...
 
94721 633594523450156250
94721 63359452345015625094721 633594523450156250
94721 633594523450156250
 
9.1.2access
9.1.2access9.1.2access
9.1.2access
 

Kürzlich hochgeladen

Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embeddingZilliz
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfSeasiaInfotech2
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostZilliz
 

Kürzlich hochgeladen (20)

Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embedding
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdf
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
 

90% of impacted cloud providers still haven’t updated certificates 1 week after heartbleed

  • 1. 90% of Impacted Cloud Providers Still Haven’t Updated Certificates 1 Week After Heartbleed As we’ve reported, hundreds of cloud providers were vulnerable to the Heartbleed bug in OpenSSL even days after the vulnerability was widely publicized. Looking at the latest data pulled this morning, much progress has been made and there are only 42 Cloud Security services that are vulnerable to Heartbleed. For these services, user data, passwords, and private keys for these services can be stolen using a simple exploit. However, more alarming today is the number of cloud services that have not fully addressed their past vulnerability. After patching SSL, the next step cloud providers must take is to reissue their certificates. As reported by CloudFlare, Heartbleed can be used by an attacker to access private keys and impersonate a website. Since Heartbleed exploits don’t leave a trace in server logs, cloud providers must assume their private keys have been compromised even if they don’t have any evidence of them being stolen. Certificate updates trail Heartbleed patching Most websites have patched SSL but they are reissuing and revoking certificates at a much slower pace. Netcraft reported that only 30,000 websites (out of more than 500,000) reissued new certificates by the end of last week, and even fewer have revoked their certificates. While not completely eliminating the risk of a man-in-the-middle attack (MITM) this is a critical step in reducing the risk of these attacks. Skyhigh is tracking certificate updates across cloud providers and as of this morning only 13.3% of Cloud Security service providers affected by Heartbleed have updated their certificates. A smaller percentage have both reissued and revoked their certificates, making them vulnerable to impersonation in a phishing scam or man-in-the-middle attack. Most certificate authorities have agreed to replace certificates for free, but there are complaints they aren’t prepared for the volume of certificates that need to be reissued.
  • 2. Already we’re seeing that Heartbleed has exposed not just a vulnerability in SSL but vulnerabilities in the way we approach security. According to security researcher Bruce Schneier: “We’ve learned how hard the human aspects of a security system are to coordinate. We’re learning that we don’t have the infrastructure necessary to quickly revoke millions of certificates and issue new ones. We’re learning that some of our critical open-source software is maintained by volunteers who have busy lives, and that often no one else is evaluating that software’s security. We’re learning how complicated the process of disclosing a vulnerability of this magnitude is.” Cleaning up and determining your exposure Aside from critical infrastructure your company uses, corporate IT departments are being asked to quantify their exposure. With over 96% of companies using cloud services impacted by Heartbleed, the chances that your sensitive data was vulnerable is extremely high. Skyhigh has already provided our customers with the cloud security services they use that were impacted, and we’re extending those audits to any company for free. Author : Lauren Ellis is a research analyst covering the technology industry’s top trends & topics, focusing on Cloud Security, Cloud Computing, Data Loss Prevention etc.,