9 ms·
OpenSSL Audit
- AceJohnny2 12y agoKey point: "we expect the preliminary results to start coming out towards the beginning of the Summer after we coordinate with the OpenSSL team."
- eyeareque 12y agoMakes sense. OpenSSL needs time to develop fixes.
- some_furry 12y agoIf they're waiting until the summer to publish the preliminary results, this means they probably found some exploitable bugs. This is an exciting development.
- mintplant 12y agoI don't think so. It sounds like the audit hasn't begun yet, and they don't expect to have anything to publish until the summer.
- some_furry 12y agoOh, you might be right. I must have misread it then.
- tomrittervg 12y agoYea, we haven't started yet :)
- Aldo_MX 12y agoHopefully this translates to fixing OpenSSL before disclosing the bug(s)
- damm 12y agoIt's a very sad thing that the world depends on a library that has been virtually unmaintained for years.
- deleted 12y ago[deleted]
- pcunite 12y agoMy understanding is that they received $1M in donations, etc, per year.
- NeutronBoy 12y agoNot quite http://veridicalsystems.com/blog/of-money-responsibility-and-pride/ http://veridicalsystems.com/blog/of-money-responsibility-and... > OSF typically receives about US$2000 a year in outright donations and sells commercial software support contracts and does both hourly rate and fixed price “work-for-hire” consulting as shown on the OSF web site. The media have noted that in the five years since it was created OSF has never taken in over $1 million in gross revenues annually.
- Alupis 12y ago> My understanding is that they received $1M in donations, etc, per year. They were only getting about $2,000 a year and had one active developer. [1] http://arstechnica.com/information-technology/2014/04/tech-giants-chastened-by-heartbleed-finally-agree-to-fund-openssl/ http://arstechnica.com/information-technology/2014/04/tech-g...
- josephg 12y agoSpeaking of OpenSSL, what state are the competing libraries in at the moment? I'd love a version of OpenSSL without all the potentially-insecure legacy code given all the problems its had. Are there decent implementations of OpenSSL in more secure languages like Rust?
- gecko 12y agoF# has a proven implementation, but I doubt that's what you're after. OCaml is also getting one for Mirage, but I don't know its status, and it won't be proven correct.
- gsnedders 12y agomiTLS considers timing attacks as out of scope for the proof, so it's unclear if it's actually secure.
- deleted 12y ago[deleted]
- TheLoneWolfling 12y agoThere's LibreSSL: http://www.libressl.org/ http://www.libressl.org/ But it's not in a more secure language.
- nulterm 12y agoPast Discussion about Ocaml-TLS[1] also mentions Rust somewhere. [1] https://news.ycombinator.com/item?id=8005130 https://news.ycombinator.com/item?id=8005130
- meowface 12y agoA full rewrite of OpenSSL in a better language like Rust will probably take a very long time to be production ready. Your best middleground is LibreSSL, which is still C but is at least written by developers with huge amounts of experience writing secure C.
- trippy_biscuits 12y agoDo people really believe in more secure languages? Are they the same people that think switches make networks secure? Switches don't and neither does a given language. I recall a CTO that would not allow C++ development because he thought the language was insecure. Java was the only language allowed. Even college courses are still teaching that security is one of the benefits of the virtual machine. We only have to look at all the patches for java to see that it hasn't been secure. Then we look at every other software that has been patched to see that nothing is secure. Please stop perpetuating the myth that security is produced by a programming language. People make security happen just like they make it not happen. Obligatory Schneier: https://www.schneier.com/blog/archives/2008/03/the_security_mi_1.html https://www.schneier.com/blog/archives/2008/03/the_security_...
- guelo 12y agoCode review as marketing. Good idea.
- technofiend 12y agoSurprised no one has yet mentioned LibreSSL, OpenBSD's fork which happened after the last major bug. http://www.libressl.org/ http://www.libressl.org/
- hackuser 12y agoIs there any coordination between OpenBSD and the Linux Foundation? For example, did the Linux Foundation consider adopting OpenBSD's fork rather than auditing and fixing the original? EDIT: What is the status of LibreSSL?
- tedunangst 12y agoAuditing and fixing the original still improves LibreSSL, although one of the main goals of LibreSSL was to clean things up to make that easier. Last LibreSSL release was 2.1.4 last week, although a minor update should be coming soon. http://marc.info/?l=openbsd-announce&m=142543818707898&w=2 http://marc.info/?l=openbsd-announce&m=142543818707898&w=2 LibreSSL is going to track OpenBSD versions, so now that OpenBSD 5.7 is done, the LibreSSL 2.1.x series is done (except to receive patches). At some point a 2.2 release will be made, corresponding to new developments.
- hackuser 12y agoThanks. Did OpenBSD get the funding they sought for LibreSSL? How mature is it at this point? I see it's included (?) with OpenBSD, which is a good sign.
- nailer 12y agolibressl's binary is already half the size of openssl. I wonder if the audit is re-doing existing work to some extent.
- Alupis 12y ago> libressl's binary is already half the size of openssl What does binary size have to do with quality? OpenSSL has been around for a long time, and still is the standard for most deployments. It will take a long time before LibreSSL has been proven enough to become the standard for anything outside the BSD community. For as nasty as the OpenSSL code appears to be, it sure did work (and worked well) for a long time. Remember, OpenSSL really only had 1 developer and only received around $2,000 a year in donations prior to Heartbleed[1] (which is grossly pathetic for such a critical piece of software). If those numbers had been tenfold or more, perhaps the bugs that led to Heartbleed may have been found and fixed long before they were an issue. Thankfully the Linux Foundation and the Core Infrastructure Initiative are aiming to remedy this. [1] http://arstechnica.com/information-technology/2014/04/tech-giants-chastened-by-heartbleed-finally-agree-to-fund-openssl/ http://arstechnica.com/information-technology/2014/04/tech-g...
- HashThis 12y agoI wish they can turn their fuzzers and similar tests that they build into an open source test suite that can be run by anyone, and into the future. That would be a great public contribution from this work.
- zobzu 12y agoWll thats pretty awesome :) I'm hoping we don't have to patch everything tomorrow but.. ;) On a side note - a lot of libs start to implement their own crypto because "OpenSSL code sux its terrible and buggy!" impression. This scares me. These won't get much exposure and will most likely be full of implementation bugs that nobody will ever review - except bad guys and the NSA.
- derefr 12y agoOpenSSL isn't the be-all-and-end-all of crypto. Simple crypto can be done simply, as it is in e.g. Tarsnap. If all you need is to pair your clients with your servers, a little bit of glue on top of NaCl is a whole lot easier to trust than the whole TLS ecosystem. What OpenSSL is, is a magic wand that can set up encrypted tunnels between peers that don't have pre-existing mutual key pairing, by making use of well-known X.509 certificates and the CA infrastructure. Don't try to make that kind of wand yourself; 99.999% of such wands are really misidentified Wands of +5 Foot Shooting.
- toast0 12y agoGiven that we know OpenSSL is a Wand of +3 Foot Shooting[1], seeing what kind of modifier you can roll doesn't seem so terrible. :) [1] I rolled my own CA bundle this week, turns out I need to include 4 1024-bit certs because the endpoints I hit are chaining to them for legacy clients, and OpenSSL didn't understand to stop when it got to a cert it knew until 1.0.2 which was released in January. Given what happened the last time I upgraded OpenSSL versions, I'm not inclined to upgrade right away. Seriously, the week after we upgraded to OpenSSL 1.0.1, heartbleed came out; serves us right for wanting to support TLS 1.1 and 1.2 and PFS.
- yuhong 12y agoOne of the more unfortunate cases is the Equifax one which expires in 2018.
- nailer 12y ago> On a side note - a lot of libs start to implement their own crypto because "OpenSSL code sux its terrible and buggy!" impression. I don't think they'd do that - it's be far easier to grab libressl or boringssl. If you're aware that openssl is buggy, you're probably aware that writing your own crypto when you're not a cryptographer is worse.
- arca_vorago 12y agoI have been using Hiawatha webserver which uses PolarSSL, and have avoided almost all of the recent bugs (on the servers that weren't running other things). I really like PolarSSL, but they just got bought up by ARM, so I'm a bit scared for the project. Regarding SSL, I just generally consider it borked and try not to trust it if possible. SSH/VPN are just about the only thing I do trust (and even then with trepidation). Once again, I think the many eyes theory only works when the code is sufficiently simple/terse. I bet if you did a study on lines of code in proportion to security vulnerabilities you would find a correlation (obviously not necessarily a causation).
- xorcist 12y agoPolarSSL has had their own fair share of nasties. Only a few months after Heartbleed they had a remote code execution in the ASN.1-parser. They fixed it quickly however, and keep a current CVE list at their home page. It just goes to show that all popular SSL options are more or less bad (and the same goes for IPsec).