DaemonForums  

Go Back   DaemonForums > DaemonForums.org > News

News News regarding BSD and related.

Reply
 
Thread Tools Display Modes
  #1   (View Single Post)  
Old 5th February 2016
comet--berkeley comet--berkeley is offline
Real Name: Richard
Package Pilot
 
Join Date: Apr 2009
Location: California
Posts: 163
Default OpenSSL fixes bug, gets dissed by German gov: That's so random ... not

The Register, 4 February 2016

Days after fixing a rare but dangerous key recovery attack, the developers of OpenSSL have been dealt a fresh blow with a poor review of the technology from a German government agency.

An extensive security study and code review on OpenSSL by Sirrix AG (and sponsored by the BSI (Bundesamt für Sicherheit in der Informationstechnik, a German federal government agency)1 returned multiple problems in the software. The report (German language original and official English language summary) highlights multiple issues with the RNG (Random Number Generator, a core component of crypto systems) and compiler flags.

http://www.theregister.co.uk/2016/02...man_gov_audit/
__________________
When you see a good move, look for a better one.
--Lasker

Last edited by comet--berkeley; 6th February 2016 at 08:21 PM. Reason: fix spacing
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
OpenSSL 1.0.1k released with 8 security fixes shep News 3 16th January 2015 11:47 AM
OpenSSL fixes DoS bug in recent bug fix J65nko News 0 20th January 2012 12:02 AM
Attacks on German mTAN banking users J65nko News 1 5th April 2011 09:38 PM
New version of OpenSSL fixes two vulnerabilities J65nko News 0 9th December 2010 02:56 AM
New Internet Legislation Embarrasses German Government J65nko News 0 18th February 2010 11:03 PM


All times are GMT. The time now is 03:34 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick