Skip to content

Comment on Ask HN: openSSL/heartbleed for internal company apps?

Comments

Yes, definitely.

You should consider all servers running a vulnerable OpenSSL installation to be compromised. You'll need to rekey all your certificates.

Do not trust the fact that "the servers are internal" because if your perimeter has been breached you will most likely know only after the fact.

Personally, I tend to treat internal services with the same process I use for external services, they just come second on the list.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.