4 ms·
An important fact that I only recently learned about this vulnerability is that the change that introduced it was not some rushed act: the maintainer raised the
by ckastner 2y ago
An important fact that I only recently learned about this vulnerability is that the change that introduced it was not some rushed act: the maintainer raised the problem they were seeing on the OpenSSL mailing list, proposed a change to fix the problem with a request for feedback, and got some (including from upstream).
The result was a terrible vulnerability, but it seems more of a case of spectacularly bad luck of everyone not spotting the issue.
- yashap 2y agoProbably more lacking automated test coverage than bad luck? For security critical RNG code, seems to me you’d really want to have a test where it generates a tonne of random numbers and asserts that they’re all unique.
- tizvoivo 2y ago[dead]
- bdonlan 2y agoIn this case, the problem was the seed was low entropy, so if you generated a bunch of random numbers with a single initialization of the RNG seed you would get unique values. It's a tricky scenario to test for if you don't know of the failure mode...
- gunapologist99 2y agoIt's not possible to assert that a number is not random (or is). You can look at it and you just don't know. This was the issue with the PRNG blackbox mixing. Obligatory Dilbert https://imgur.com/uR4WuQ0 https://imgur.com/uR4WuQ0 and XKCD: https://xkcd.com/221/ https://xkcd.com/221/
- brokenmachine 2y agoSo if you rolled a dice a few times and happened to get the same number, you'd throw the dice away for not working properly?
- account42 2y agoNo but you might investigate how even the dice really is and if it only happens with dice that have the shiny red swirl painted on one side then maybe consider not doing that.
- orra 2y agoAt the time, it felt like Debian got a lot of flack for the bug, but there's the collaboration attempt you mention above. Plus, the upstream OpenSSL code was invoking undefined behaviour. Hence the compiler could have validly made the exact same transformation as the Debian maintainer. At the time this felt academic: surely compilers can't be that mean! Since then I think undefined behaviour is better understood as a thing to avoid entirely. Then, eight years later, Heartbleed was discovered. And we suddenly all realised how badly maintained OpenSSL was. In their defence, it was pretty much a volunteer job. Thankfully, subsequent funding has improved the situation.