05.06.2014 - 17:40 [ Masashi Kikuchi / Lepidum.co.jp ]

How I discovered CCS Injection Vulnerability (CVE-2014-0224)

The biggest reason why the bug hasn’t been found for over 16 years is that code reviews were insufficient, especially from experts who had experiences with TLS/SSL implementation. If the reviewers had enough experiences, they should have been verified OpenSSL code in the same way they do their own code. They could have detected the problem.