How the Debian OpenSSL bug almost spawned a disaster
When news broke last year about the serious flaw in the Debian OpenSSL pseudorandom number generator, security experts knew it was a serious problem and warned users to regenerate any keys that had been created using the vulnerable versions of the OpenSSL package. More here
Nate Lawson, an expert on cryptography, today described in detail why the situation could have turned out much differently: Not only was every key that had been generated by the vulnerable versions compromised, so was every key used on systems running those vulnerable versions of Debian.
Debian News RSS Feed
No Response to “How the Debian OpenSSL bug almost spawned a disaster” »
No comments yet.
RSS feed for comments on this post. TrackBack URI
Leave a comment