The Heartbleed Bug and What Changed After
One missing bounds check in OpenSSL exposed private keys across roughly half a million servers.
50 guides on the protocol's timeline, its biggest security failures, and how certificates went from expensive to free.
One missing bounds check in OpenSSL exposed private keys across roughly half a million servers.
In 2016, a free, automated certificate authority changed what "having HTTPS" cost — and who could afford it.
Three named attacks in three years, each exploiting a different flavor of intentionally weakened cryptography.
One compromised Dutch CA, thousands of fraudulent certificates, and the industry response that followed for a decade.
Why early SSL was legally required to be weak outside the US — and how that shaped the web for a decade.
The full arc, from the first mis-issuance reports to the final migration deadline.
A decade-long, deliberately gradual retirement — and the research that finally proved it necessary.
A nation-state-grade attack that used a broken hash function to forge a Microsoft-trusted certificate.
A decade of the green address bar — introduced with confidence, removed after the data came in.
Every named vulnerability between 2011 and 2018 fed directly into what TLS 1.3 removed.
Netscape's first public version of SSL. Contained significant weaknesses and was formally prohibited in modern TLS by 2011.
A full redesign after SSL 2.0's flaws. Widely adopted for over a decade before being deprecated following the POODLE vulnerability in 2014.
The IETF took over the protocol from Netscape and renamed it TLS. Based closely on SSL 3.0.
Introduced stronger, more flexible cryptographic algorithm support. Remained the dominant version on the web for over a decade.
A critical flaw in OpenSSL exposed server memory, including private keys, across a huge share of the internet's HTTPS servers.
Free, automated, domain-validated certificates went from a niche idea to the default expectation for the entire web.
A leaner, faster, more secure handshake — and the formal deprecation of legacy cryptographic algorithms still allowed under TLS 1.2.
Browsers began actively flagging plain HTTP pages, accelerating industry-wide HTTPS adoption.