Current time: 04-13-2025, 07:13 PM
Teh interesting tech news stub thread
#29
XKCD offers advice in a comic strip.

[Image: security_holes.png]

From the forums of the same site.
http://forums.xkcd.com/viewtopic.php?f=7...36#p670397

<[anonymous]> Sgeo: put simply, there were two very similar lines of code
<[anonymous]> one made valgrind mad, and was more or less useless anyway
<[anonymous]> the other was absolutely vital
<[anonymous]> both were commented out at the same time \o/
<[anonymous]> and so the crypto keys were generated based soley on the PID
<[anonymous]> anyway here's what's affected:
<[anonymous]> Any DSA key (openssl, openvpn, ssh) used on a debian or ubuntu machine since september 2006
<[anonymous]> Any RSA key generated on the same
<[anonymous]> if you're paranoid, passwords sent on a connection where either machine was affected
<[anonymous]> All those keys/passwords should be regenerated/changed

...If you understood that, you're probably going to have to regenerate your keys.

Another (better) explanation: http://metasploit.com/users/hdm/tools/debian-openssl/
Reply


Messages In This Thread
Teh interesting tech news stub thread - by Grim - 01-10-2008, 03:55 PM
RE: Teh interesting tech news stub thread - by Sforza - 05-21-2008, 11:09 PM
Teh interesting tech news stub thread - by Serene - 03-11-2008, 05:58 PM

Possibly Related Threads…
Thread Author Replies Views Last Post
  Teh Interesting Military Technology News Thread Lord_Leperman 54 90,095 10-01-2015, 04:41 AM
Last Post: J.E_Magog
  ISP Discussion and Q&A thread Shintetsu 32 46,655 01-12-2011, 06:43 PM
Last Post: Shintetsu
Tongue The Redfox sucks thread wanzerfreak 33 52,459 10-30-2008, 09:02 AM
Last Post: Shintetsu

Forum Jump:


Users browsing this thread: 6 Guest(s)