3 ms·
>A good debian maintainer will also review code of their packages and make sure such trickery has no chance to be afood Except for that time that Debian develo
by ohithereyou 7y ago
>A good debian maintainer will also review code of their packages and make sure such trickery has no chance to be afood
Except for that time that Debian developers "knowing better" completely neutered most cryptography on all updated Debian systems[1]:
>Affected keys include SSH keys, OpenVPN keys, DNSSEC keys, and key material for use in X.509 certificates and session keys used in SSL/TLS connections. Keys generated with GnuPG or GNUTLS are not affected, though.
Massive, rapid key rotation schemes had do be implemented to cover their screwup because all keys were trivially enumerable, to the point where all affected keys were blacklisted[2].
[1] https://www.debian.org/security/2008/dsa-1571 https://www.debian.org/security/2008/dsa-1571
[2] https://security.stackexchange.com/questions/3422/what-is-the-openssh-blacklist-package-is-it-related-to-the-debian-openssl-bug https://security.stackexchange.com/questions/3422/what-is-th...