Heartbleed ‘Still Affects’ 200,000 Devices

The notorious ‘Heartbleed’ vulnerability that caused widespread panic last year is still present on 200,000 connected devices, according to figures from IoT search engine Shodon.

Heartbleed affects OpenSSL, a widely used open source technology used by many websites and applications to safeguard customer data, and compromises any protection by allowing attackers to obtain encryption keys.

Following its discovery in April 2014, vendors and developers rushed to patch Heartbleed, while many major IT firms offered additional support to open source technologies, many of which don’t receive funding in proportion to their importance.

Read More: Heartbleed a Year Later: How the Security Conversation Changed

Heartbleed impact

To put it into perspective, it was estimated that on 10 April 2014, there were 220 million mobile apps sitting on Android phones containing the flaw.

However 18 months on and it appears not everything has been patched. A map Tweeted by Shodon founder John Matherly claims there are 57,272 unprotected devices in the US, 21,660 in Germany, 11,300 in China, 10,094 in France and 9,125 in the UK.

Shodon is able to search for devices and reveals the technical characteristics of anything connected to the web. It can even do so by geographical region, potentially giving attackers potential targets, but also giving administrators a heads-up that not all of their systems are protected.

Loading ...

Heartbreak

“The Shodan search results also tell you when a device is vulnerable to Heartbleed (as well as other SSL info),” said Matherly.

Security expert Graham Clulely agrees the search engine can help identify security threats and also help IT teams see if devices are visible to the outside world when they shouldn’t be.

“IT teams can use tools like Shodan to help them check their company’s security, testing with various filters to determine if web servers – for instance – are running a particular version of Apache, or if devices which shouldn’t be visible to the outside world are revealing their existence online,” he said.

“Clearly, some manufacturers and IT teams have dropped the ball, and failed to update vulnerable systems. My bet is that there will always be devices attached to the internet which are vulnerable to Heartbleed.”

How well do you know open source software? Take our quiz!

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

2 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

2 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

2 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

3 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

3 days ago