300k servers vulnerable to Heartbleed one month later
It's been a month since the Heartbleed bug was announced, so I thought I'd rescan the Internet (port 443) to see how many systems remain vulnerable. Whereas my previous scan a month ago found 600,000 vulnerable systems …
Context & Ripple Effects
A month after OpenSSL's Heartbleed flaw was disclosed on April 7, Errata Security has rerun its Internet-wide scan of port 443: 300,000 servers remain vulnerable, down from 600,000 in its first sweep. The halving is real progress, but it also quantifies how slow patching is even for a bug that lets anyone on the Internet read server memory, as the disclosure coverage explained.
The scan lands alongside two other measures of cleanup lag: an April 18 status check found 0.52% of the top 10K sites and 2% of the top 1M still exposed ten days after disclosure, and Heartbleed-driven certificate revocation had already swollen certificate revocation lists enough to strain bandwidth for authorities and site operators. Eight outlets picked up the rescan within a day, from Ars Technica to PC World — unusual breadth for a single researcher's measurement, and a sign the industry is tracking remediation numbers as closely as the bug itself.
First-order effects
- The roughly 300,000 operators still running unpatched OpenSSL on port 443 face continued exposure of private keys and session memory to any attacker who scans for the flaw.
- Certificate authorities and large site operators keep paying the revocation bill: every newly patched host that rotates keys adds to CRL sizes and the bandwidth costs documented since mid-April.
Second-order effects
- Hosting providers and enterprises with large TLS footprints face mounting pressure to automate patch deployment, since a month-long tail of 300,000 hosts shows manual remediation cannot keep pace with Internet-scale vulnerabilities.
- Security vendors gain a recurring product line in continuous exposure scanning — Errata Security's serial rescans establish the format competitors will be pushed to match as long as the vulnerable population stays measurable.
Third-order effects
- If disclosure-driven rescans become the standard yardstick, vulnerability severity will increasingly be judged by remediation curves rather than CVSS scores alone, shifting accountability toward whoever operates — or funds maintenance of — critical open-source infrastructure like OpenSSL.
The trend: Internet-wide vulnerability disclosure is entering a measurement era where researchers track patch-remediation decay curves publicly, exposing how long-tail and structurally underfunded open-source security maintenance is.