{"id":3546,"date":"2024-05-13T17:24:27","date_gmt":"2024-05-13T22:24:27","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/heartbleed-when-is-it-good-to-name-a-vulnerability"},"modified":"2024-05-13T17:24:27","modified_gmt":"2024-05-13T22:24:27","slug":"heartbleed-when-is-it-good-to-name-a-vulnerability","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/13\/heartbleed-when-is-it-good-to-name-a-vulnerability\/","title":{"rendered":"Heartbleed: When Is It Good to Name a Vulnerability?"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltda078e6cfe6514bb\/64f156c468861b2557c5e10b\/vulnerability_Elena11_shuttersock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/heartbleed-when-is-it-good-to-name-a-vulnerability.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/heartbleed-when-is-it-good-to-name-a-vulnerability.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Back in April 2014, researchers uncovered a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/emergency-ssl-tls-patching-under-way\" rel=\"noopener\">serious vulnerability in OpenSSL<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. There are many serious vulnerabilities, but this one was particularly bad, with security expert Bruce Schneier calling it &#8220;catastrophic.&#8221; On his blog, Schneier wrote, &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.schneier.com\/blog\/archives\/2014\/04\/heartbleed.html\" rel=\"noopener\">On the scale of 1 to 10, this is an 11<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&#8221; The Tor Project <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/blog.torproject.org\/openssl-bug-cve-2014-0160\/\" rel=\"noopener\">issued a similarly stark warning<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, &#8220;If you need strong anonymity or privacy on the Internet, you might want to stay away from the Internet entirely for the next few days while things settle.&#8221;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The official name of the vulnerability was <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/heartbleed-examining-the-impact\" rel=\"noopener\">CVE-2014-0160<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, but most people know its name: Hearbleed.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Finnish company Codenomicon, which discovered the vulnerability alongside Google&#8217;s Neel Mehta, anticipated the magnitude of the issue and decided to give the flaw a name to call attention to it. Codenomicon designed a logo and launched a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/heartbleed.com\/\" rel=\"noopener\">website<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> with resources to help people address the issue quickly.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It was a pretty serious vulnerability, and that&#8217;s why we thought it would be a good idea to have a campaign around it with information,&#8221; says David Chartier, who was Codenomicon&#8217;s CEO at that time (Codenomicon was later acquired by Synopsys). &#8220;We thought it would make everybody&#8217;s life easier if we put a name on it.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www-is-fi.translate.goog\/digitoday\/tietoturva\/art-2000001832843.html\" rel=\"noopener\">Herralan Ossi<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, one of the company&#8217;s security specialists, coined the name Heartbleed, an allusion to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">heartbeat<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, an element of the TLS\/SSL protocol. The heartbeat allows two computers to confirm they are connected to each other even if there&#8217;s no data being transferred between them. The first computer sends a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">heartbeat message<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, or an encrypted data packet, to the other computer at regular intervals, and the second computer returns an identical packet to confirm the connection. The Heartbleed flaw, however, allows attackers to read server memory and send additional information, or &#8220;bleeding out data,&#8221; as Chartier puts it. This way, attackers can extract sensitive information such as passwords and private keys.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The impact was widespread, as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/web.archive.org\/web\/20140415151603\/http:\/mashable.com\/2014\/04\/09\/heartbleed-bug-websites-affected\/\" rel=\"noopener\">many companies<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 a list which included Amazon Web Services, Dropbox, GitHub, Google, Instagram, LassPass, Minecraft, OKCupid, Netflix, Pinterest, Reddit, SoundCloud, Tumblr, Wikipedia, Yahoo and Youtube, to name just a few \u2014 announced that their servers were vulnerable and recommended users to update their passwords.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This huge vulnerability needed a striking mark,&#8221; the logo\u2019s designer, Leena Snidate, told <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.fastcompany.com\/3028982\/why-the-security-bug-heartbleed-has-a-catchy-logo\" rel=\"noopener\">Fast Company<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> at that time. &#8220;The colour choice was immediate for me\u2013deep blood red.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Branded Vulnerabilities Trend\">The Branded Vulnerabilities Trend<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the case of Heartbleed, branding the flaw with a name and the logo helped get media attention and was successful in raising awareness around the issue. A <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.pewresearch.org\/internet\/2014\/04\/30\/heartbleeds-impact\/2\/\" rel=\"noopener\">Pew Research Center<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> survey from April 2014 (within weeks of the vulnerability being disclosed) showed that 64% of internet users were aware of the bug, 39% of users took actions to secure their online accounts such as changing passwords, and 29% felt their personal information was put at risk because of the bug.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Some organizations quickly patched their systems, while others took longer to respond. Ten years later, there are still around 60,000 servers running Heartbleed OpenSSL around the world, according to Chartier. He recommends companies know their attack surface better and test thoroughly the open-source tools they use.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Heartbleed was among the first vulnerabilities to be branded with a name and logo, a practice later embraced by other researchers for other vulnerabilities. While some followed Codenomicon&#8217;s strategy to highlight serious threats, others applied catchy names to less critical, mundane bugs. Some names were downright silly, such as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/POODLE\" rel=\"noopener\">POODLE<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/FREAK\" rel=\"noopener\">FREAK<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-2118\" rel=\"noopener\">Badlock<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/twitter.com\/x0rz\/status\/1128201244504465408\" rel=\"noopener\">Thrangrycat<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (which was also named using three angry cat emojis) and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.csoonline.com\/article\/558385\/backdoor-dubbed-pork-explosion-lets-attackers-go-hog-wild-on-android-phones.html\" rel=\"noopener\">Pork Explosion<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The branded vulnerabilities trend prompted many in the information security community to raise their eyebrows. In <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/web.archive.org\/web\/20160731213147\/http:\/community.hpe.com\/t5\/Security-Research\/Naming-and-graphic-design-services-for-bugs-now-available\/ba-p\/6728183#.V55uR-zP3wO\" rel=\"noopener\">an April Fool&#8217;s Day blog post in 2015<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Brian Gorenc, Trend Micro&#8217;s vice president of Threat Research, offered &#8220;two hours of graphic design work to create a logo specific to your bug,&#8221; as part of what has been dubbed the &#8220;No More Ugly Bugs&#8221; movement.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sometimes, the name of the bug was blown out of proportion. &#8220;[N]ot every named vulnerability is a severe vulnerability despite what some researchers want you to think,&#8221; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/insights.sei.cmu.edu\/blog\/vulnonym-stop-the-naming-madness\/\" rel=\"noopener\">wrote<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> Leigh Metcalf for Carnegie Mellon&#8217;s Software Engineering Institute blog. &#8220;Sensational names are often the tool of the discoverers to create more visibility for their work.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This trend of choosing dramatic names for vulnerabilities has sparked discussions about the balance between necessary caution and excessive hype. &#8220;You can go overboard with branding,&#8221; says Mikko Hypp\u00f6nen, Chief Research Officer at WithSecure. &#8220;Every mundane vulnerability doesn&#8217;t need a website and a logo \u2013 even though marketing departments would like that.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Balance Between Marketing and Security\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Balance Between Marketing and Security<\/span><\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Deciding to name a vulnerability or not is a tricky call to make. &#8220;For every Heartbleed, there are just a bunch of bugs that are not as serious as people think they are,&#8221; says Dustin Childs, head of Threat Awareness at Trend Micro&#8217;s Zero Day Initiative (ZDI). &#8220;We need to be careful with what we name, and with how we promote it. It&#8217;s very easy to go from doing well for the community to overpromoting something for personal gain.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Childs argues that vulnerabilities with widespread exploitation or those impacting multiple products deserve names. However, he believes that bugs affecting specific systems should simply be referred to by their CVEs. &#8220;I don&#8217;t think one bug affecting Windows should be named. I don&#8217;t think one bug affecting Mac OS should be named,&#8221; Childs says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ZDI does not name their bugs because that&#8217;s not a line the organization wants to cross, &#8220;even though it is clear sometimes that line needs to be crossed,&#8221; Childs says.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Childs agrees, though, that in the case of serious vulnerabilities like Heartbleend or Log4j, using a name instead of a CVE makes a difference. &#8220;CVEs are very useful from a documentation perspective,&#8221; he says. &#8220;But when you&#8217;re talking to your C-suite, to folks who are making decisions but aren&#8217;t necessarily technical, it&#8217;s easier to have a name to call something. It makes the conversation simpler.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Naming vulnerabilities also creates problems, especially when the name makes the bug seem either too benign or too scary. &#8220;No sysadmin likes to patch unnecessarily or before understanding the scope of a vulnerability and the options for mitigating exploits,&#8221; says Sean O&#8217;Brien, lecturer in cybersecurity at Yale Law School and founder of Yale Privacy Lab.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It is why sysadmins and security experts responsible for patching vulnerabilities need to consider their priorities carefully and avoid the pitfall of rushing to patch a bug solely because it has a sinister name and is in the news.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">O&#8217;Brien adds that, when choosing a name for a vulnerability, organizations should be careful with humor, which could downplay the seriousness of a threat or even make people angry. &#8220;That&#8217;s especially true when bias about the origin of a threat creeps into the name,&#8221; he says. &#8220;I don&#8217;t think most American security professionals would warm up to a name like <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">Crappy Eagle<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> about a vulnerability that likely emerged from an NSA arsenal.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In recent years, various organizations have started to think that the name should reflect the seriousness of the threat, as well as how the bug can be exploited. One initiative that aimed to settle the issue was <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.ctrl.blog\/entry\/sensational-vulnonym.html\" rel=\"noopener\">Vulnonym<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which attempted to give researchers guidance in naming CVEs. This initiative, however, had limited success.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I don&#8217;t think we need a central org that names vulnerabilities,&#8221; security researcher Martijn Grooten, former editor of the Virus Bulletin, says. &#8220;For most practical purposes, CVEs work just fine.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ten years after Heartbleed, the security community continues to grapple with naming vulnerabilities. &#8220;It&#8217;s always going to be tough to strike that balance as security and marketing often have different interests,&#8221; Grooten adds. &#8220;The important thing for me will be to always make claims that are accurate.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/heartbleed-when-is-it-good-to-name-a-vulnerability\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Back in April 2014, researchers uncovered a serious vulnerability in<\/p>\n","protected":false},"author":12,"featured_media":3547,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3546","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/heartbleed-when-is-it-good-to-name-a-vulnerability.jpg?fit=1000%2C563&ssl=1",1000,563,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/heartbleed-when-is-it-good-to-name-a-vulnerability.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/heartbleed-when-is-it-good-to-name-a-vulnerability.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/heartbleed-when-is-it-good-to-name-a-vulnerability.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/heartbleed-when-is-it-good-to-name-a-vulnerability.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/heartbleed-when-is-it-good-to-name-a-vulnerability.jpg?fit=1000%2C563&ssl=1",1000,563,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/heartbleed-when-is-it-good-to-name-a-vulnerability.jpg?fit=1000%2C563&ssl=1",1000,563,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/heartbleed-when-is-it-good-to-name-a-vulnerability.jpg?fit=1000%2C563&ssl=1",1000,563,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/heartbleed-when-is-it-good-to-name-a-vulnerability.jpg?resize=825%2C563&ssl=1",825,563,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/heartbleed-when-is-it-good-to-name-a-vulnerability.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/heartbleed-when-is-it-good-to-name-a-vulnerability.jpg?fit=1000%2C563&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3546","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3546"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3546\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3547"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3546"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3546"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3546"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}