Very good “Diagnosis of the OpenSSL Heartbleed Bug” by @ex509: blog.existentialize.com/diag… BTW: “Start writing alternatives in safer languages”
2
4
6
@stilkov actual lesson is don’t do your own memory management; this failure transcends language
1
Replying to @assaf
@assaf If your language doesn’t allow you to do memory management, that seems like a plus

Apr 9, 2014 · 9:16 PM UTC

1
Replying to @stilkov
@stilkov except they all do. it's called array. reuse an array, copy data in/out, eventually data leaks out.
2
@assaf Of course you can do anything in any language. Doesn’t mean you actually would.
2