View all newsletters
Receive our newsletter - data, insights and analysis delivered to you

OpenSSL faces major security audit post-Heartbleed

Cryptography Services will check integrity of Transport Layer Security.

By Jimmy Nicholls

OpenSSL is set to receive its first major security audit since the Heartbleed bug was uncovered last April, prompting a slew of patches from many of the biggest companies on the web.

The scheme is being paid for as part of the Linux Foundation’s Core Infrastructure Initiative fund worth $1.2m (£800,000), and will be conducted by the NCC Group’s Cryptography Services, which has recently investigated the security of TrueCrypt, an encryption service used by Edward Snowden.

A statement released by Cryptography Services said: "This audit had been mentioned before, absent details, but with the effort OpenSSL has been making we finally feel the codebase is stable enough to announce and undertake this now.

"OpenSSL has been reviewed and improved by the Academic community, commercial static analyser companies, validation organisations, and individual review over the years – but this audit may be the largest effort to review it, and is definitely the most public."

According to the auditors, the primary focus on the scheme will be the stacks of Transport Layer Security (TLS), a technology that was built to replace the security layer SSL.

"While the audit won’t cover every single corner of the codebase, we believe it will be a useful component of the broader efforts being undertaken to improve OpenSSL’s engineering and security," Cryptography Services added.

"This is a fairly large audit, so we expect the preliminary results to start coming out towards the beginning of the Summer after we coordinate with the OpenSSL team."

Content from our partners
Powering AI’s potential: turning promise into reality
Unlocking growth through hybrid cloud: 5 key takeaways
How businesses can safeguard themselves on the cyber frontline

Other projects in the Core Infrastructure Initiative include an attempt to survey hundreds of open source projects in a bid to make the Internet more secure.

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how Progressive Media Investments may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU