Thirty years of old software are being cleaned up all at once. And honestly, that's good news.

Thirty years of old software are being cleaned up all at once. And frankly, that's good news.


There are two programs you have never installed and will probably never see. Yet you use them hundreds of times a day. They are called OpenSSL and curl.

The first is your browser's little padlock. It's what scrambles the conversation between your phone and your bank, so that no one in the middle can read what's being sent. The second retrieves a page or a file from the internet when a device needs it. It's hidden inside your router, your television, your printer, and your car's GPS.

Both are more than twenty-five years old. Both are maintained by a handful of people. And since January, they have been reviewed as never before.

An old industrial machine, half dusty and half restored, inspected by small robots in a workshop

Old machinery, complete overhaul. It creaks a little, but comes out in better condition.

The programs everyone uses and nobody knows

We often imagine that a modern device is a block made entirely by one brand. In reality, it's a stack of small software components written elsewhere, often for free and sometimes a very long time ago. Everyone reuses them as-is because they work well.

Cutaway of a house where seven devices contain the same small gear connected by a dotted line

Seven objects in the house, the same little piece of code inside, and nobody knows its name.

These components are not easy to replace. They were installed in 1998, they do their job, so people move on to something else. Twenty-five years later, they are still running in billions of devices. Yet no one had time to reopen the hood and check every line. This isn't negligence. It's a matter of human time. Seriously reviewing an entire program could keep an engineer busy for weeks. So it wasn't done.

Why nobody had seen these bugs for twenty-five years

There was already an automated method for looking for flaws, and it had been very useful. The principle is fairly crude: send millions of nonsensical inputs to the program until it crashes. A crash is immediately visible. The machine can therefore report: “there's a problem here.”

The trouble is that most flaws don't make the program crash. They do worse. The program carries on quietly and executes exactly what it is asked to do, without checking whether the person asking has the right to do so.

On the left, a door smashed in with a battering ram and an alarm; on the right, the same door politely opened by a doorman while the thief walks through

A door being smashed in makes a sound. A door opened for you politely, much less so.

To find these flaws, shaking the program is not enough. You have to read its code, understand what it is supposed to do, then identify the gap between the two. In other words, you needed a skilled, expensive, and slow human. That barrier has now fallen. From now on, tools can automate a large part of this code review.

And then, all at once, everything turns up

On January 27, OpenSSL announced twelve previously unknown vulnerabilities all at once. All of them had been discovered by a specialized company's system during a single campaign. Some had been sleeping in the code for twenty-five to twenty-seven years, even though OpenSSL is one of the most thoroughly reviewed programs on the planet. Twenty-seven years. The bug was older than half of its users.

This isn't just a stroke of luck. In early August, a team from Palo Alto Networks published the results of two months of automated analysis: 3,915 programs examined, 14,090 flaws found. More than nine out of ten belonged to the invisible category, the kind that never makes the program crash. Around a third were serious.

Un tapis roulant industriel deverse des milliers de rapports sur un petit bureau ou une personne est ensevelie

Fourteen thousand defects discovered in two months. Each one represents one fewer hole in software you use.

The movement is widespread. Mozilla stated plainly that, since February, the Firefox team has been using these tools relentlessly to find and fix old defects. At Chrome, the number of vulnerabilities fixed and disclosed has increased more than sixfold since the beginning of the year. At GitHub, it has increased more than fivefold.

Graphique en barres de la progression du nombre de failles corrigees et publiees depuis janvier 2026 par editeur

No one suddenly started coding worse in January. We simply started looking.

This week again, on August 14, a publisher announced that it had found more than 2,400 defects in 269 programs. One of them was hiding in code written forty years ago. These are the publisher's figures, and no one has verified them, so caution is warranted. But the trend itself is no longer really up for debate.

What this means for you

This is where I find the story truly heartening. Everyone is talking about it as a catastrophe, whereas I believe it is exactly the opposite.

These defects have not just appeared. They were already there yesterday and ten years ago, in your router as well as in your browser. The only thing protecting you was that no one had time to look for them. That's not security; it's luck. Now, we're bringing them to light. Once discovered, they can be properly fixed.

There is, incidentally, a precedent, and it has aged rather well. In 2002, Microsoft stopped developing Windows for around ten weeks to have its own teams review all its code. At the time, everyone thought the operation was crazy, costly, and humiliating. Yet that project transformed a system that caught a virus every week into something usable. It still took a giant company, months of work, and a single product. This time, the same thing is happening to thousands of programs at once, for the price of an electricity bill.

Concretely, tomorrow's software will be cleaner than yesterday's. Not perfect—no one promised you perfection. But your router, your browser, your phone, and the little box that controls your heating all use pieces of code that are going through their first technical inspection. In two years, the same code library will be considerably more robust than it is today. And you will have had nothing to do.

There is just one simple condition: your device must still receive updates. A patch that is never installed is useless. The real losers, then, are the 2019 printer whose brand has disappeared and the $39 camera that has received nothing for three years. For everything else, keep automatic updates enabled and let it happen.

The downside, because there is one

Finding a defect has become almost free. Fixing it has not. And that has not been multiplied at all.

The person in charge of curl is named Daniel Stenberg. He is now receiving so many reports that he made a radical decision this summer. Many of these reports are beautifully written stories produced by a machine, but contain no actual bug. From July 1 to August 3, he therefore closed the mailbox. No more reports accepted, either by form or by email. Nothing.

Une boite aux lettres debordant de courrier avec une pancarte de retour le 3 aout, et un homme au calme dans un transat

The year's best IT decision fits on a piece of cardboard.

The report published on August 3 is simple: a single message arrived throughout the entire month, and no incident occurred. Daniel Stenberg says that, a few days after the pause began, the entire team felt relieved. It felt like a vacation, with one less weight on their chests. When you know that this piece of code runs in almost everything on this planet with a network connection, it gives you pause.

Here is the real challenge for the coming years. Finding bugs is almost taken care of. Now we need to help the few people who fix them avoid drowning.

What I think

For twenty-five years, the excuse was always the same: no one has time to review this code. It was true, and everyone made do with it, myself included.

That excuse is dead. And I think that’s wonderful. We’re entering a period when old software can improve as it ages, instead of slowly rotting away in its corner. A program from 1998 undergoes a complete overhaul, then comes out clean, solid, and rid of its original flaws. It’s exactly the kind of news we had never seen before in computing.

So yes, there’s noise, bogus reports, and exhausted maintainers. That’s the price of this period, and it will be sorted out. But in five years, what runs in your home will be significantly more robust than what runs there today. It’s been a long time since I wrote a sentence like that.

Join the conversation

You need an account to comment on this article. Creating one is free and takes under a minute.

  • The XMLTV file, free to download every day
  • Comment on articles and reply to other readers
  • Get an e-mail when an article you follow is updated

No comments yet.

Une erreur s'est produite. Cette application peut ne plus répondre jusqu'à ce qu'elle soit rechargée.Veuillez contacter l'auteur. Reload 🗙