Ever since the existence of the Heartbleed bug came to light, security experts have been arguing about whether or not private SSL keys can be extracted. It turns out that, while its not easy, it can be done.
CloudFlare launched a challenge earlier this week, asking experts to prove that SSL keys can be obtained. Software engineer Fedor Indutny and Ilkka Mattila of NCSC-FL solved the challenge within 9 hours.
The Heartbleed bug affects a large number of Internet services. The OpenSSL v…