7 ms·
be reassured, that "nobody" actually checks thoroughly in practice, so don't rely on it. http://www.h-online.com/newsticker/news/item/Debian-package-of-OpenSSL
by Create 15y ago
be reassured, that "nobody" actually checks thoroughly in practice, so don't rely on it.
http://www.h-online.com/newsticker/news/item/Debian-package-of-OpenSSL-generates-weak-keys-735183.html http://www.h-online.com/newsticker/news/item/Debian-package-...
- 3pt14159 15y agoDoesn't that prove that people do check it? Isn't the point of open source that you can have problems for a time, but eventually you'll be ok? Certainly better than you could write yourself or trust in a closed source system.
- Create 15y agoYes, it is certainly easier to audit than binaries, but one of the main axioms in cryptography is, that it should ensure security for the timeframe until the information protected is still valuable (one can assume, that eventually all crypto is cracked -- the question is when, and how to delay this to ensure functionality). This bug was injected for two years: the damage has been done, with literally over a million of weak keys that pollute the internet. That said, I acknowledge, that the ssl system has (perhaps even more) serious weaknesses beyond the keys themselves. It should have been caught days after commit, and never should have made it into debian stable (and debian has a very slow, thorough release cycle). But telnetd comes to mind, etc. Perhaps only OpenBSD shows consistent true efforts in open source auditing.