SlideShare a Scribd company logo
1 of 2
Download to read offline
90% of Impacted Cloud Providers Still Haven’t Updated Certificates 
1 Week After Heartbleed 
As we’ve reported, hundreds of cloud providers were vulnerable to the Heartbleed 
bug in OpenSSL even days after the vulnerability was widely publicized. Looking at 
the latest data pulled this morning, much progress has been made and there are only 
42 Cloud Security services that are vulnerable to Heartbleed. For these services, 
user data, passwords, and private keys for these services can be stolen using a simple 
exploit. 
However, more alarming today is the number of cloud services that have not fully 
addressed their past vulnerability. After patching SSL, the next step cloud providers 
must take is to reissue their certificates. As reported by CloudFlare, Heartbleed can be 
used by an attacker to access private keys and impersonate a website. Since 
Heartbleed exploits don’t leave a trace in server logs, cloud providers must assume 
their private keys have been compromised even if they don’t have any evidence of 
them being stolen. 
Certificate updates trail Heartbleed patching 
Most websites have patched SSL but they are reissuing and revoking certificates at a 
much slower pace. Netcraft reported that only 30,000 websites (out of more than 
500,000) reissued new certificates by the end of last week, and even fewer have 
revoked their certificates. While not completely eliminating the risk of a 
man-in-the-middle attack (MITM) this is a critical step in reducing the risk of these 
attacks. 
Skyhigh is tracking certificate updates across cloud providers and as of this morning 
only 13.3% of Cloud Security service providers affected by Heartbleed have updated 
their certificates. A smaller percentage have both reissued and revoked their 
certificates, making them vulnerable to impersonation in a phishing scam or 
man-in-the-middle attack. Most certificate authorities have agreed to replace 
certificates for free, but there are complaints they aren’t prepared for the volume of 
certificates that need to be reissued.
Already we’re seeing that Heartbleed has exposed not just a vulnerability in SSL but 
vulnerabilities in the way we approach security. According to security researcher 
Bruce Schneier: 
“We’ve learned how hard the human aspects of a security system are to coordinate. 
We’re learning that we don’t have the infrastructure necessary to quickly revoke 
millions of certificates and issue new ones. We’re learning that some of our critical 
open-source software is maintained by volunteers who have busy lives, and that often 
no one else is evaluating that software’s security. We’re learning how complicated the 
process of disclosing a vulnerability of this magnitude is.” 
Cleaning up and determining your exposure 
Aside from critical infrastructure your company uses, corporate IT departments are 
being asked to quantify their exposure. With over 96% of companies using cloud 
services impacted by Heartbleed, the chances that your sensitive data was vulnerable 
is extremely high. Skyhigh has already provided our customers with the cloud 
security services they use that were impacted, and we’re extending those audits to 
any company for free. 
Author : 
Lauren Ellis is a research analyst covering the technology industry’s top trends & 
topics, focusing on Cloud Security, Cloud Computing, Data Loss Prevention etc.,

More Related Content

Viewers also liked

93e23 msi ms-7101_rev_2b_sch
93e23 msi ms-7101_rev_2b_sch93e23 msi ms-7101_rev_2b_sch
93e23 msi ms-7101_rev_2b_schDomingo Arroyo
 
90010 - MINI VINTAGE FRAME
90010 - MINI VINTAGE FRAME90010 - MINI VINTAGE FRAME
90010 - MINI VINTAGE FRAMEEmma Lawson
 
Изделие 9П148 Инструкция По Эксплуатации
Изделие 9П148 Инструкция По ЭксплуатацииИзделие 9П148 Инструкция По Эксплуатации
Изделие 9П148 Инструкция По ЭксплуатацииRimsky Cheng
 
Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...
Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...
Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...Notis Mitarachi
 
94721 633594523450156250
94721 63359452345015625094721 633594523450156250
94721 633594523450156250rjcai
 

Viewers also liked (9)

93e23 msi ms-7101_rev_2b_sch
93e23 msi ms-7101_rev_2b_sch93e23 msi ms-7101_rev_2b_sch
93e23 msi ms-7101_rev_2b_sch
 
9 22 Ss2
9 22 Ss29 22 Ss2
9 22 Ss2
 
Food labelling and advertising
Food labelling and advertisingFood labelling and advertising
Food labelling and advertising
 
90010 - MINI VINTAGE FRAME
90010 - MINI VINTAGE FRAME90010 - MINI VINTAGE FRAME
90010 - MINI VINTAGE FRAME
 
Изделие 9П148 Инструкция По Эксплуатации
Изделие 9П148 Инструкция По ЭксплуатацииИзделие 9П148 Инструкция По Эксплуатации
Изделие 9П148 Инструкция По Эксплуатации
 
9/11 incident
9/11 incident9/11 incident
9/11 incident
 
Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...
Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...
Επίκαιρη Επερώτηση Ν. Μηταράκη και Βουλευτών ΝΔ σχετικά με τα Μεταλλεία Χαλκι...
 
94721 633594523450156250
94721 63359452345015625094721 633594523450156250
94721 633594523450156250
 
9.1.2access
9.1.2access9.1.2access
9.1.2access
 

Recently uploaded

The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 

Recently uploaded (20)

The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 

90% of impacted cloud providers still haven’t updated certificates 1 week after heartbleed

  • 1. 90% of Impacted Cloud Providers Still Haven’t Updated Certificates 1 Week After Heartbleed As we’ve reported, hundreds of cloud providers were vulnerable to the Heartbleed bug in OpenSSL even days after the vulnerability was widely publicized. Looking at the latest data pulled this morning, much progress has been made and there are only 42 Cloud Security services that are vulnerable to Heartbleed. For these services, user data, passwords, and private keys for these services can be stolen using a simple exploit. However, more alarming today is the number of cloud services that have not fully addressed their past vulnerability. After patching SSL, the next step cloud providers must take is to reissue their certificates. As reported by CloudFlare, Heartbleed can be used by an attacker to access private keys and impersonate a website. Since Heartbleed exploits don’t leave a trace in server logs, cloud providers must assume their private keys have been compromised even if they don’t have any evidence of them being stolen. Certificate updates trail Heartbleed patching Most websites have patched SSL but they are reissuing and revoking certificates at a much slower pace. Netcraft reported that only 30,000 websites (out of more than 500,000) reissued new certificates by the end of last week, and even fewer have revoked their certificates. While not completely eliminating the risk of a man-in-the-middle attack (MITM) this is a critical step in reducing the risk of these attacks. Skyhigh is tracking certificate updates across cloud providers and as of this morning only 13.3% of Cloud Security service providers affected by Heartbleed have updated their certificates. A smaller percentage have both reissued and revoked their certificates, making them vulnerable to impersonation in a phishing scam or man-in-the-middle attack. Most certificate authorities have agreed to replace certificates for free, but there are complaints they aren’t prepared for the volume of certificates that need to be reissued.
  • 2. Already we’re seeing that Heartbleed has exposed not just a vulnerability in SSL but vulnerabilities in the way we approach security. According to security researcher Bruce Schneier: “We’ve learned how hard the human aspects of a security system are to coordinate. We’re learning that we don’t have the infrastructure necessary to quickly revoke millions of certificates and issue new ones. We’re learning that some of our critical open-source software is maintained by volunteers who have busy lives, and that often no one else is evaluating that software’s security. We’re learning how complicated the process of disclosing a vulnerability of this magnitude is.” Cleaning up and determining your exposure Aside from critical infrastructure your company uses, corporate IT departments are being asked to quantify their exposure. With over 96% of companies using cloud services impacted by Heartbleed, the chances that your sensitive data was vulnerable is extremely high. Skyhigh has already provided our customers with the cloud security services they use that were impacted, and we’re extending those audits to any company for free. Author : Lauren Ellis is a research analyst covering the technology industry’s top trends & topics, focusing on Cloud Security, Cloud Computing, Data Loss Prevention etc.,