Just a side note here for the uninitiated – OpenSSL happens to be an online-data scrambling software that is used to protect sensitive data, with passwords being one of them. It was in 2013 that NSA leaker Edward Snowden claimed the NSA themselves introduced vulnerabilities to security software on purpose, which has led to such speculation that has since been denied by the NSA.
In fact, Robin Seggelman, a German computer programmer, has already stepped forward to accept responsibility for the Heartbleed bug’s existence, saying, “It’s tempting to assume that, after the disclosure of the spying activities of the NSA and other agencies, but in this case it was a simple programming error in a new feature, which unfortunately occurred in a security-relevant area. It was not intended at all, especially since I have previously fixed OpenSSL bugs myself, and was trying to contribute to the project.”
Well, there you have it – Heartbleed stemmed from Seggelman’s effort in making amends to the OpenSSL cryptographic library at the end of 2011.