Sometimes, people do such stupid things that words almost fail me. That’s the case with a Debian ‘improvement’ to OpenSSL that rendered this network security program next to useless in Debian, Ubuntu and other related Linux distributions.
opensslOpen-Source Security IdiotsDigg Linux/Unix upcoming Thu, 08/28/2008 - 10:39
Sometimes, people do such stupid things that words almost fail me. That’s the case with a Debian ‘improvement’ to OpenSSL that rendered this network security program next to useless in Debian, Ubuntu and other related Linux distributions. Debian needs some serious commit reviewDigg Linux/Unix upcoming Fri, 07/11/2008 - 19:11
You’ve probably heard by now about the gaping hole in keys generated by Debian’s OpenSSL. If not, the summary is that your SSH keys and SSL certs were selected from a fixed pool of 215 (32,767) possibilities, and are thus easy to brute-force over the network. Installing And Configuring ProFTPd with OpenSSL on Debian EtchDebian-News.net Fri, 05/30/2008 - 13:18
FTP has been the standard way to do this for as long as I can remember so to make my server as useful as possible Installing an FTP server is a very important program. Distribution Release: PelicanHPC 1.5.1DistroWatch.com: News Tue, 05/20/2008 - 10:20
Michael Creel has announced the release of PelicanHPC 1.5.1 (formerly PrallelKnoppix), a Debian-based live CD designed to make it simple to set up a high-performance computing cluster. Linux gets security black eyeTopix - Linux Fri, 05/16/2008 - 15:31
As has been widely reported, the maintainers of Debian's OpenSSL packages made some errors recently that have potentially compromised the security of any sshd-equipped system used remotely by Debian users. Tags:
Massive flaw in Debian Linux's Open SSL. Affects thousands.Digg Linux/Unix upcoming Fri, 05/16/2008 - 13:17
This is just a little more than a "oops" flaw. This is a huge mistake that WILL affect you Ubuntu users as well!"Moore documents the cause of the bug and explains how easily attackers can create every possible key the flawed OpenSSL implementation can generate." Researcher: Debian cryptography may be flawedTopix - Unix Fri, 05/16/2008 - 07:33
A security researcher has warned that cryptographic keys generated in the last year and a half using Debian OpenSSL may be invalid. Major Crypto Bug Cripples Ubuntu Linux SecurityTopix - Linux Thu, 05/15/2008 - 15:52
OpenSSL is a very important package that brought public key cryptography to the masses; prior to OpenSSL, https web sites were expensive and complicated to build. With the Quickness: HD Moore sets new land speed record with...Topix - Linux Thu, 05/15/2008 - 00:43
So, for those who haven't heard, a Debian packager modified the source used for OpenSSL on Debian based systems to remove the seed used for PRNG used when creating SSL keys. Weakness in OpenSSL on Debian and Ubuntu DiscoveredDigg Linux/Unix upcoming Wed, 05/14/2008 - 22:05
If you are using Debian or any other distro that's based on it (such as Ubuntu), you are advised to update, because a weakness was discovered in the random number generator used by OpenSSL. |
Recent comments
13 weeks 1 day ago
13 weeks 5 days ago