Skip to main content

OpenSSL Foundation president asks for more financial support in the wake of Heartbleed

If the organizations, companies, and governments that employ OpenSSL with their websites want to ensure that their sites stay secure from future threats like Heartbleed down the line , Steve Marquess, the president of the OpenSSL Software Foundation, asks that the entities which use OpenSSL donate more money towards its operations, the LA Times reports . Marquess made the case for additional funding in this blog post .

“While OpenSSL does ‘belong to the people’ it is neither realistic nor appropriate to expect that a few hundred, or even a few thousand, individuals provide all the financial support,” Marquess wrote. “The ones who should be contributing real resources are the commercial companies and governments who use OpenSSL extensively and take it for granted.”

Recommended Videos

Marquess specifically took members of the Fortune 1000, list to task in his note.

“I’m looking at you, Fortune 1000 companies. The ones who include OpenSSL in your firewall/appliance/cloud/financial/security products that you sell for profit, and/or who use it to secure your internal infrastructure and communications. The ones who don’t have to fund an in-house team of programmers to wrangle crypto code, and who then nag us for free consulting services when you can’t figure out how to use it. The ones who have never lifted a finger to contribute to the open source community that gave you this gift. You know who you are.”

Marquess also names the U.S. Department of Defense in his note as an agency that could provide additional funding, calling an investment in OpenSSL a “no-brainer.”

MORE: How to check if your favorite website is vulnerable to Heartbleed

OpenSSL is a data encryption method employed by many websites that safeguard the data you type into your Web browser. OpenSSL contains a function known as a heartbeat option. While a person is visiting a website that encrypts data using OpenSSL, his or her computer periodically sends and receives messages to check whether both his PC and the server on the other end are both still connected, following a pattern similar to a heartbeat. The Heartbleed bug means hackers can send fake heartbeat messages, which can trick a site’s server into relaying data that’s stored in its RAM — including sensitive information such as usernames, passwords, credit card numbers, emails, and more. This web comic also explains how Heartbleed works.

According to Marquess, the OpenSSL Foundation only pulls in about $2,000 per year in donations, with the rest of its funding coming in via support contracts it honors, where part-time technicians assist clients with problems that are specific to them. Overall, the OpenSSL Foundation has never surpassed $1 million in annual funding. On top of that, then OpenSSL is understaffed, according to Marquess, with the entire team consisting of a single full-time staff member, and a handful of part-timers.

Konrad Krawczyk
Former Computing Editor
Konrad covers desktops, laptops, tablets, sports tech and subjects in between for Digital Trends. Prior to joining DT, he…
QuickBooks’ new AI agents accelerate business efficiency
The Sales page of Intuit QuickBooks Online on a laptop.

Intuit is reimagining business operations, and its latest upgrade to QuickBooks is a paradigm shift. Starting July 1, U.S. customers will have access to AI agents that are deployed across QuickBooks Online, backed by redesigned web and mobile interfaces. This virtual team will dramatically reduce the time businesses spend on manual tasks, up to 12 hours a month, according to Intuit’s internal data.

These aren’t your general-purpose chatbots. They’re vertical-specific, domain-trained tools integrated within QuickBooks ecosystem to handle complex tasks autonomously and proactively. Early results are speaking for themselves: 78% of customers report that Intuit’s AI makes running their business easier, while 68% say they now have more time to grow their business instead of being buried in the back office.

Read more
The best MacBook is on sale at 20% off, but probably not for much longer
Apple MacBook Air 13 M4 front view showing display and keyboard.

Are you on the hunt for MacBook deals? You should go for our favorite model -- the 13-inch Apple MacBook Air M4 -- while it's on sale. The version with 16GB of RAM and a 256GB SSD is $200 off from both Amazon and Best Buy, which slashes the laptop's price from $999 to a more affordable $799. You're going to have to be quick though, as Apple deals rarely last long. If you want to get this laptop at 20% off, you need to finalize your transaction for it right now.

$799 at Amazon

Read more
8 of the best GPUs I recommend after 200 hours of testing
RTX 3080 graphics cards among other GPUs.

With the demands of modern PC games, no less than one of the best graphics cards will do, preferably in partnership with one of the best processors. We've reviewed dozens of GPUs and spent over 200 hours benchmarking them, and these are the cards that we've tested and can still swear by despite the current state of the GPU market.

Graphics cards are not cheap right now, but the models listed below remain competitive. Some are pricier than they were at launch, but we hand-picked the ones that are still readily available and worth your money. With Nvidia's RTX 50-series, AMD's RDNA 4, and Intel's Arc Battlemage out in full swing, we're spoiled for choice, and it's all a matter of hunting down a good deal selling close to the recommended list price (MSRP).

Read more