This question originally appeared on Quora: Whose fault is the Heartbleed bug?. Answer by Phillip Remaker, Distinguished Services Engineer “Fault” is hard to assign here. And unproductive.The architect of the DTLS heartbeat protocol and author of the relevant OpenSSL code is Dr. Robin Seggelmann. He has admitted full responsibility for the bug. Dr. Stephen Henson reviewed the code and did not notice any problem. None of the testers discovered the bug. Users did not notice a problem for over two years.