<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Recycle Bin &#187; ssl</title>
	<atom:link href="http://therecyclebin.wordpress.com/tag/ssl/feed/" rel="self" type="application/rss+xml" />
	<link>http://therecyclebin.wordpress.com</link>
	<description>A repository of comments, code, and opinions.</description>
	<lastBuildDate>Mon, 16 Mar 2009 14:11:00 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='therecyclebin.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/ebffd4fb7788afdd4568e720ddc77607?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>The Recycle Bin &#187; ssl</title>
		<link>http://therecyclebin.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://therecyclebin.wordpress.com/osd.xml" title="The Recycle Bin" />
		<item>
		<title>Serious flaw in OpenSSL on Debian-based Linux</title>
		<link>http://therecyclebin.wordpress.com/2008/05/13/serious-flaw-in-openssl-on-debian-based-linux/</link>
		<comments>http://therecyclebin.wordpress.com/2008/05/13/serious-flaw-in-openssl-on-debian-based-linux/#comments</comments>
		<pubDate>Tue, 13 May 2008 23:38:50 +0000</pubDate>
		<dc:creator>Nathan</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://therecyclebin.wordpress.com/2008/05/13/serious-flaw-in-openssl-on-debian-based-linux/</guid>
		<description><![CDATA[&#160;
[SECURITY] [DSA 1571-1] New openssl packages fix predictable random number generator 
OK, this is kind of a big deal.&#160; It turns out that there is a serious flaw in the OpenSSL packages used on Debian-based Linux distributions, which includes Ubuntu, Xandros, and many others.&#160; The problem appears to be that the random number generator is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therecyclebin.wordpress.com&blog=1016841&post=114&subd=therecyclebin&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>&nbsp;</p>
<p><a href="http://lists.debian.org/debian-security-announce/2008/msg00152.html">[SECURITY] [DSA 1571-1] New openssl packages fix predictable random number generator</a> </p>
<p>OK, this is kind of a big deal.&nbsp; It turns out that there is a serious flaw in the OpenSSL packages used on Debian-based Linux distributions, which includes <a href="http://www.ubuntu.com/usn/usn-612-1">Ubuntu</a>, Xandros, and <a href="http://www.debian.org/misc/children-distros">many others</a>.&nbsp; The problem appears to be that the random number generator is giving predictable, rather un-random results.</p>
<p>From the bulletin:</p>
<blockquote><p>It is strongly recommended that all cryptographic key material which has been generated by OpenSSL versions starting with 0.9.8c-1 on Debian systems is recreated from scratch. Furthermore, all DSA keys ever used on affected Debian systems for signing or authentication purposes should be considered compromised; the Digital Signature Algorithm relies on a secret random value used during signature generation.</p>
</blockquote>
<p>Debian Linux runs many of the websites out there, and a lot of them rely on cryptographic keys for SSL.&nbsp; Replacing these keys (getting them re-signed by a <a href="http://therecyclebin.us/post/Unaccountable-Authority.aspx">Certificate Authority</a>) will surely be a long and expensive process.</p>
<p>Here&#8217;s another gem from the bulletin:</p>
<blockquote><p>OpenSSL&#8217;s DTLS (Datagram TLS, basically &#8220;SSL over UDP&#8221;) implementation did not actually implement the DTLS specification, but a potentially much weaker protocol, and contained a vulnerability permitting arbitrary code execution (CVE-2007-4995).</p>
</blockquote>
<p>These bugs beg the question, why is the Debian team making changes to OpenSSL?&nbsp; Cryptography is hard, and the OpenSSL team has one of the most accurate and respected libraries to date.&nbsp;&nbsp; They should stick to what they&#8217;re good at, like <a href="http://www.debian.org/doc/manuals/debian-reference/ch-package.en.html#fr34">package management</a>, and leave cryptography to the people who know what they&#8217;re doing.&nbsp; As it stands, I&#8217;m not sure if I can trust any SSL connection anymore&#8230;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/therecyclebin.wordpress.com/114/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/therecyclebin.wordpress.com/114/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/therecyclebin.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/therecyclebin.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/therecyclebin.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/therecyclebin.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/therecyclebin.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/therecyclebin.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/therecyclebin.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/therecyclebin.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/therecyclebin.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/therecyclebin.wordpress.com/114/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=therecyclebin.wordpress.com&blog=1016841&post=114&subd=therecyclebin&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://therecyclebin.wordpress.com/2008/05/13/serious-flaw-in-openssl-on-debian-based-linux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ac5a3b4291018ee0fd1bd668c328ab6c?s=96&#38;d=" medium="image">
			<media:title type="html">natenovielli</media:title>
		</media:content>
	</item>
	</channel>
</rss>