10 ms·
The press is all over this topic, but as usual doesn't do its research well enough. Some insight: the bug was submitted in December 2011 and was only present in
by tbolse 12y ago
The press is all over this topic, but as usual doesn't do its research well enough. Some insight: the bug was submitted in December 2011 and was only present in OpenSSL 1.0.1 - not in previous releases. 1.0.1 was released on 14th of March 2012. It usually takes a long time until this new versions get largely adopted into other software. Even today 1.0.1 isn't used everywhere. That leads me to doubt that the agencies could have used this vulnerability for a very long time. A year seams reasonable, years rather not. It's very sad thou, that they choose not to contribute to secure software and rather exploit the vulnerability.