3 ms·
Complex code is never good for security. In 2006, a small change was made to the Debian port of OpenSSL to do something like remove a few compiler warning messa
by soitgoes 16y ago
Complex code is never good for security. In 2006, a small change was made to the Debian port of OpenSSL to do something like remove a few compiler warning messages. Unfortunately, it had the side effect of making the random number generator predictable. This security flaw wasn't discovered for over a year and in that time many weak keys were generated and used. See here for more info: http://wiki.debian.org/SSLkeys http://wiki.debian.org/SSLkeys