Thirty years of old software are being cleaned up all at once. And frankly, that's good news.
There are two programs that you have never installed and will probably never see. Yet you use them hundreds of times a day. They are called OpenSSL and curl.
The first one is your browser's little padlock. It's what scrambles the conversation between your phone and your bank, so that nobody in the middle can read what is going through. The second retrieves a page or a file from the internet when a device needs it. It's tucked away in your router, your TV, your printer and your car's GPS.
Both are more than twenty-five years old. Both are maintained by a handful of people. And since January, they have been read through like never before.
Old machinery, complete overhaul. It creaks a little, but it comes out in better shape.
The programs everyone uses and nobody knows
We often imagine that a modern device is a block made entirely by one brand. In reality, it's a pile of little pieces of software written elsewhere, often for free and sometimes a very long time ago. Everyone reuses them as they are because they work well.
Seven objects in the house, the same little bit of code inside, and nobody knows its name.
Those bits are not easy to replace. They were installed in 1998, they do the job, so we move on to something else. Twenty-five years later, they are still running in billions of devices. Yet nobody had time to reopen the hood and check every line. It's not neglect. It's a question of human time. Seriously reviewing an entire program could keep an engineer busy for weeks. So we didn't do it.
Why nobody had seen these bugs for twenty-five years
There was already an automatic method for looking for flaws, and it had done a fine job. The principle is pretty brute-force: we send millions of absurd pieces of data to the program until it crashes. A crash is immediately obvious. The machine can therefore report: "there is a problem here".
The trouble is that most flaws do not make the program crash. They do worse. The program carries on quietly and does exactly what it is asked to do, without checking whether the person asking it has the right to.
A door being battered in makes a noise. A door being opened politely for you, much less so.
To find these flaws, shaking the program is not enough. You have to read its code, understand what it is supposed to do, then spot the gap between the two. In other words, you needed a competent, expensive and slow human. That wall has just fallen. From now on, tools can automate a large part of reading that code.
And then, all of a sudden, we find everything
On January 27, OpenSSL announced twelve previously unknown vulnerabilities all at once. All of them had been discovered by a specialist company's system, during a single campaign. Some had been sleeping in the code for twenty-five to twenty-seven years, even though OpenSSL is one of the most reviewed programs on the planet. Twenty-seven years. The bug was older than half of its users.
This is not just a lucky break. In early August, a team from Palo Alto Networks published the results of two months of automated analysis: 3,915 programs examined, 14,090 flaws found. More than nine out of ten belonged to the invisible category, the one that never makes the program crash. About a third were serious.
Fourteen thousand defects discovered in two months. Each one represents one fewer hole in software you use.
The movement is widespread. Mozilla wrote it down in black and white: since February, the Firefox team has been using these tools relentlessly to find and fix old defects. At Chrome, the number of vulnerabilities fixed and published has increased more than sixfold since the start of the year. At GitHub, it has increased more than fivefold.
Nobody suddenly started coding worse in January. We simply started looking.
This week again, on August 14, a vendor announced that it had found more than 2,400 defects in 269 programs. One of them was hiding in code written forty years ago. Those are the vendor's figures and nobody has checked them, so be careful. But the trend itself is no longer really up for debate.
What it means for you
This is where I find this story really heartening. People talk about it everywhere as a catastrophe, while I believe it's exactly the opposite.
These defects didn't just appear. They were already there yesterday and ten years ago, in your internet box as well as in your browser. The only thing protecting you was that nobody had time to look for them. That's not security, that's luck. Now we're bringing them to light. Once discovered, they can be fixed for good.
There is a precedent, and it has aged rather well. In 2002, Microsoft stopped developing Windows for about ten weeks to have all its code reviewed by its own teams. At the time, everyone thought the operation was crazy, costly and humiliating. Yet this project transformed a system that caught a virus every week into something usable. It still took a giant company, months of work and a single product. This time, the same thing is happening to thousands of programs at once, for the price of an electricity bill.
Concretely, tomorrow's software will be cleaner than yesterday's. Not perfect, nobody promised you perfection. But your internet box, your browser, your phone and the little device that controls your heating all use pieces of code that are going through their first technical inspection. In two years, the same code library will be noticeably more solid than it is today. And you won't have had to do anything.
There's one simple condition left: your device must still receive updates. A patch that is never installed is useless. The real losers are therefore the 2019 printer whose brand has disappeared and the €39 camera that hasn't received anything for three years. For everything else, keep automatic updates enabled and let it do its thing.
The downside, because there is one
Finding a defect has become almost free. Fixing it hasn't. And that hasn't been multiplied by anything at all.
The guy who looks after curl is called Daniel Stenberg. He is now receiving so many reports that he made a radical decision this summer. Many of these reports are beautifully written stories produced by a machine, but contain no real bug. From July 1 to August 3, he therefore closed the mailbox. No more reports accepted, either by form or by email. Nothing.
The best IT decision of the year fits on a piece of cardboard.
The summary published on August 3 is simple: only one message arrived during the entire month, and no incident took place. Daniel Stenberg says that, a few days after the start of the break, the whole team felt relieved. A holiday feeling, with one less weight on their chests. When you know that this piece of code runs in almost everything on this planet that has a network connection, it makes you think.
Here is the real challenge for the coming years. Finding bugs is almost taken care of. Now we need to help the few people who fix them not drown.
What I think about it
For twenty-five years, the excuse was always the same: nobody has time to review this code. It was true, and everyone made do with it, me first.
That excuse is dead. And I think that's fantastic. We are entering a period where old software can improve as it ages, instead of quietly rotting away in its corner. A program from 1998 gets a complete overhaul, then comes out clean, solid and rid of its original flaws. It's exactly the kind of news we had never had before in computing.
So yes, there is noise, bogus reports and exhausted maintainers. That's the price of this period, and it will get sorted out. But in five years, what runs in your house will be noticeably more solid than what runs there today. It's been a long time since I wrote a sentence like that.






Join the conversation
You need an account to comment on this article. Creating one is free and takes under a minute.
No comments yet.