4 ms·
Just curious (I'm a nobody in the security field to doubt anything): What is the process to vet the correctness of the description of the severity? I imagine th
by theCricketer 11y ago
Just curious (I'm a nobody in the security field to doubt anything): What is the process to vet the correctness of the description of the severity? I imagine these notices are pretty important so when they describe subjective things like how difficult and likely it is to take advantage of this loophole, is there a standard for how to assess such things?
- peterle 11y agoThe "severity" is often not accurate. OpenSSL recently marked an issue as lowly severe, but in fact its severity was high. Don't trust them. OpenSSL is bad, use LibreSSL instead. OpenSSL == NSA. For sure they know weaknesses and actively exploit them if required. EDIT: I'm talking about this advisory: https://www.openssl.org/news/secadv/20150108.txt https://www.openssl.org/news/secadv/20150108.txt
- danielhlockard 11y agoI'm not saying you're wrong, I'm just saying LibreSSL isn't bug free either: https://en.wikipedia.org/wiki/LibreSSL#15_October_2015 https://en.wikipedia.org/wiki/LibreSSL#15_October_2015 buffer overflows and memory leaks aren't great.
- peterle 11y agoDidn't say that. Just take a look at a "security comparison" between LibreSSL and OpenSSL: https://en.wikipedia.org/wiki/LibreSSL#Security_and_vulnerabilities https://en.wikipedia.org/wiki/LibreSSL#Security_and_vulnerab... Severity LibreSSL OpenSSL High 0 5 Medium 15 28 Low 7 10 Total 22 43 LibreSSL has had no "high" vulnerabilities, whereas OpenSSL had 5. Decide for yourself which way to go. EDIT: Sorry, can't format that table nicely here..
- bch 11y ago> The "severity" is often not accurate. OpenSSL recently marked an issue as lowly severe, but in fact its severity was high. ... > LibreSSL has had no "high" vulnerabilities, whereas OpenSSL had 5. Decide for yourself which way to go. I'm not defending or apologizing for OpenSSL (or any project), but your rationale isn't consistent, seemingly only trying to evoke an emotional response. Since heartbleed, lots of new SSL implementations have sprung up (Libre, Boring, etc), and hard lights have shone on OpenSSL as well. The scrutiny and competition will come to be win for all consumers of SSL. It's not clear to me (as a consumer) that any project has a huge leg-up over another (though Libre's wholesale dump of a tremendous amount of legacy code sounds like a step in the right direction). Do we even know this won't show up in other (Boring, Libre) implementations as well ? Edit: formatting
- neerdowell 11y ago> I'm not defending or apologizing for OpenSSL (or any project), but your rationale isn't consistent, seemingly only trying to evoke an emotional response. The GP is pointing out that LibreSSL has avoided the 5 vulnerabilities that OpenSSL marked sev:high since the fork. There isn't any inconsistency about that, it's a pure apples-with-apples comparison. > It's not clear to me (as a consumer) that any project has a huge leg-up over another LibreSSL has avoided almost half of the OpenSSL vulnerabilities found since the work. What more do you want?
- deleted 11y ago[deleted]
- peterwwillis 11y agoFormat tip: prefix a block of lines with two spaces (on each line) and a newline before and after the block to turn it into a fixed-width font, then format ASCII-style.
- deleted 11y ago[deleted]
- 102030485868 11y agoThe one the OpenSSL follows is documented here[0]. There's also the CVSS[1] which covers a broader scope. [0]: https://www.openssl.org/policies/secpolicy.html https://www.openssl.org/policies/secpolicy.html [1]: https://en.wikipedia.org/wiki/CVSS https://en.wikipedia.org/wiki/CVSS