3 ms·
Yes, it is certainly easier to audit than binaries, but one of the main axioms in cryptography is, that it should ensure security for the timeframe until the in
by Create 15y ago
Yes, it is certainly easier to audit than binaries, but one of the main axioms in cryptography is, that it should ensure security for the timeframe until the information protected is still valuable (one can assume, that eventually all crypto is cracked -- the question is when, and how to delay this to ensure functionality).
This bug was injected for two years: the damage has been done, with literally over a million of weak keys that pollute the internet. That said, I acknowledge, that the ssl system has (perhaps even more) serious weaknesses beyond the keys themselves. It should have been caught days after commit, and never should have made it into debian stable (and debian has a very slow, thorough release cycle). But telnetd comes to mind, etc. Perhaps only OpenBSD shows consistent true efforts in open source auditing.