3 ms·
Wow, someone used <= instead of < and they wrote 5 page report with all those images and charts. The bug is obvious and simple, what is with all those explanati
by kunil 13y ago
Wow, someone used <= instead of < and they wrote 5 page report with all those images and charts. The bug is obvious and simple, what is with all those explanations?
- baq 13y agothis is crypto. there were 'less serious' bugs like initializing arrays to zeros (see debian) that led to catastrophic results, which is what the explanation is about.
- kunil 13y agoI am not saying if bug is critical or not. It is just pages of explanations, charts and stuff. I was expecting a video explanation by the end. If they are targeting non-crypto people (which includes me), explaining how a bad random algorithm affects cryptology would be better instead of showing that algorithm is bad in 5 different ways. Also any link to articles about that Debian bug?
- baq 13y agoexcuse me for inaccuracy - it wasn't a zero-initialization, it was a maintainer who thought he was fixing a bug because he made a compiler warning disappear, which resulted in a whole lot of zeros where there should be some random data. http://www.schneier.com/blog/archives/2008/05/random_number_b.html http://www.schneier.com/blog/archives/2008/05/random_number_... http://research.swtch.com/openssl http://research.swtch.com/openssl
- DanBC 13y agoRandom numbers are used for different things, but mostly generating keys. An attacker that knows everything about your system (all the hardware, and the software, all the sourcecode, everything) should not be able to predict the next bit output by a prng. Errors include: i) using a source that is not random. As mentioned elsewhere some hardware devices provide skewed numbers, and even de-skewing doesn't help too much. ii) using a poor seed. The Debian bug is an example of ii - > This vulnerability was caused by the removal of two lines of code from the original version of the OpenSSL library. These lines were used to gather some entropy data by the library, needed to seed the PRNG used to create private keys, on which the secure connections are based. Without this entropy, the only dynamic data used was the PID of the software. Under Linux the PID can be a number between 1 and 32,768, that is a too small range of values if used to seed the PRNG and will cause the generation of predictable numbers. Therefore any key generated can be predictable, with only 32,767 possible keys for a given architecture and key length, and the secrecy of the network connections created with those keys is fully compromised. (http://en.wikinews.org/wiki/Predictable_random_number_generator_discovered_in_the_Debian_version_of_OpenSSL http://en.wikinews.org/wiki/Predictable_random_number_genera...) (www.schneier.com/blog/archives/2008/05/random_number_b.html)
- pessimizer 13y agohttp://wiki.debian.org/SSLkeys#Technical_Summary http://wiki.debian.org/SSLkeys#Technical_Summary