TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: How much time/effort did Heartbleed cost your team?

9 pointsby ubiabout 11 years ago
Looking for time or dollar impact of Heartbleed on your team:<p>1. &lt; hour 2. Hours 3. Days 4. Weeks 5. Unknown

8 comments

cawabout 11 years ago
Probably around 1-2 man-hours directly. The first bit was myself and my coworker running around trying to figure out what this was and how big of a deal after seeing the post on HN. I manually patched a few non-essential systems to make sure the patches took without a huge dependency tree update, then my coworker rolled it out automatically to all the systems.<p>We spent some follow up time checking Amazon&#x27;s site to make sure our ELBs were updated (because it wasn&#x27;t by the time we patched) and sending out the post-mortem to the team. Our certs were already going to expire, so we renewed them and updated them again via automation.
stevekempabout 11 years ago
Applying the security update took minutes, even on a large number of hosts, thanks to automation.<p>The harder part was working out how to treat things from there, did we need to assume we&#x27;d been hit in the past, and regenerate certificates? That took a good couple of hours of debate with different people.<p>Call it half a day to be generous.
debacleabout 11 years ago
We run + manage our own servers, have ~4 dedicated servers and a large amount of VPSes. We lost about 7 man-days patching, cleaning up, updating certs, PR, etc.
bowlichabout 11 years ago
About a half-day of work. Fixing our systems went pretty quick, but had to go track down a lot of clients&#x27; accounts and systems to rekey their certs.
akg_67about 11 years ago
I spent couple of hours for installing the patch, sending users security alert email and updating users&#x27; dashboard with security alert.
anthony_francoabout 11 years ago
About 10 minutes. Just had to check and see if we had an affected version.
kogirabout 11 years ago
1-2 hours of my time.
SomeoneWeirdabout 11 years ago
few hours for our sysadmin, I suppose.