Last updated: April 29, 2026
Crypto breaks rarely; when it does, it’s catastrophic.
Notable incidents
- DigiNotar 2011 — CA compromised; rogue certs for Google. Browser distrust = company death.
- Heartbleed 2014 — OpenSSL bug exposed memory to attacker. Remediation involved rotating every cert.
- POODLE 2014 — SSL 3.0 padding-oracle. End of SSL 3.0.
- Logjam 2015 — DH key-exchange weakness. End of weak DH groups.
- Symantec distrust 2017 — Symantec/Thawte/GeoTrust certs gradually distrusted by browsers due to misissuance.
- ROBOT 2017 — RSA padding oracle. F5, Cisco, others patched urgently.
- SHA-1 deprecation 2017 — gradual phaseout.
Lessons
- Crypto agility (rotate ciphers, certs without rebuild)
- Don’t trust single CA; CT log monitoring
- Patch crypto libraries fast
- Plan for “the algorithm we used yesterday is broken today”
Module Quiz · 5 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.