Heartbleed at Twelve: The Day the Internet's Heart Hung Loose
Twelve years ago this spring, the internet learned to distrust its own cryptography layer. On April 7, 2014, the OpenSSL project shipped an emergency advisory alongside a patch, and the world met Heartbleed: CVE-2014-0160, one of the most consequential vulnerabilities since the commercial internet began.
What went wrong
One side sends a small payload and its declared length, and the other side echoes it back to prove the connection is alive. That sounds trivial - and that was the problem.
The server trusted the declared length without checking it against the actual payload. Send one byte but claim it is 65,535 bytes long, and OpenSSL happily echoed back whatever sat in adjacent memory โ up to about 64 KB of it per request. Attackers could repeat this from slightly different offsets, effectively mining the server's process memory.
The "read" keyword matters. This was a buffer over-read, a missing bounds check in tls1_process_heartbeat โ not a crash in a weird edge case. No authentication needed, and no trace in server logs. One quiet bug let remote strangers page through memory holding private keys, passwords, session cookies โ anything the process could touch.
A two-year-old memory bug
The code was written by Robin Seggelmann, who co-authored the heartbeat RFC, and landed in OpenSSL's tree near the end of 2011. It became active with OpenSSL 1.0.1's release, in March 2012, and lived quietly until April 2014. The flaw was found independently by Neel Mehta of Google's security team and by the Finnish security firm Codenomicon, which named it, built the bleeding-heart logo, and stood up heartbleed.com. The fix, OpenSSL 1.0.1g, shipped the same day as the public disclosure.
How widespread
OpenSSL underpins Apache and nginx, which together served most of the web. Early estimates put the heartbeat extension on roughly 17% of secure sites โ around half a million trusted certificates. Patching was frantic and imperfect, because simply having patched did not mean your keys had not already leaked.
The lessons that stuck
Heartbleed taught three things we still lean on. First, memory safety: a missing bounds check in C was enough to empty a server's secrets, and you can't talk about it without recalling the push toward Rust and safer languages. Second, encryption does not protect process memory โ your cipher is only as good as the plaintext sitting around it. Third, adversarial review belongs on the boring features. Nobody audits the "trivial" heartbeat; that's exactly where the ghosts live.
Heartbleed is a reminder that the internet's security is held together by careful, human review of undramatic code. The bug is twenty lines of history. The lesson is permanent.
This retrospective is part of Stack Signal's dev archive. For more on where today's TLS and memory-safety tooling ended up, see our sister site at https://tama.fdhcl.com.
