Free Republic
Browse · Search
News/Activism
Topics · Post Article

Commentary from Daily Tech:
A simple programming error reduced the entropy in the generated program keys created by the OpenSSL library. Why does this matter? The OpenSSL library's key generation and other routines are used by the SSH remote access program, the IPsec Virtual Private Network (VPN), the Apache Web server, secure email clients, programs that offer secure internet portals and more.

In a nutshell, a 128-bit encryption key, instead of having 10^38 possible values (making it effectively impossible to guess they key), really only has 32,767 possible values, meaning that guessing the key becomes trivial

All your encryption keys are belong to us


1 posted on 05/25/2008 3:18:16 PM PDT by PapaBear3625
[ Post Reply | Private Reply | View Replies ]


To: ShadowAce; chance33_98; Calvinist_Dark_Lord; PenguinWry; GodGunsandGuts; CyberCowboy777; Salo; ...

Preliminary tech ping


2 posted on 05/25/2008 3:20:33 PM PDT by PapaBear3625 ("In a time of universal deceit, telling the truth is a revolutionary act." -- George Orwell)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: PapaBear3625

And what liberal arts degree did this “programmer” have? Obviously no math degree.


3 posted on 05/25/2008 3:21:37 PM PDT by Da Coyote
[ Post Reply | Private Reply | To 1 | View Replies ]

To: PapaBear3625

So you get something for free and what - demand it is as secure as something you pay for? Silly people.


4 posted on 05/25/2008 3:23:29 PM PDT by edcoil
[ Post Reply | Private Reply | To 1 | View Replies ]

To: PapaBear3625
... cracking the keys of these poor Linux and Ubuntu computer systems ...

Butbutbutbut I thought only evil Windows systems were vulnerable. /sarc

6 posted on 05/25/2008 3:25:58 PM PDT by LiberConservative ("Typical" White Guy)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: PapaBear3625

Bill Gates, is that you?


7 posted on 05/25/2008 3:26:07 PM PDT by Eddie01 (one more for the road is actually a really bad idea)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: PapaBear3625

debian screwed up and modified something they shouldn’t have. The OpenSSL Project itself does not have the bug nor does any non-debian based system.


8 posted on 05/25/2008 3:30:20 PM PDT by ezsmoke
[ Post Reply | Private Reply | To 1 | View Replies ]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

21 posted on 05/25/2008 3:51:02 PM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: PapaBear3625

Bookmarking for later


35 posted on 05/25/2008 6:32:18 PM PDT by BreitbartSentMe (Ex-Dem since 2001 *Folding@Home for the Gipper - Join the FReeper Folders*)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: PapaBear3625

ROTFLMAO!!!

Geez, I thought open source meant “thousands of programmers” would review the source code and therefore the source code would be secure. WHAT A GAFF!


39 posted on 05/25/2008 8:15:23 PM PDT by CodeToad
[ Post Reply | Private Reply | To 1 | View Replies ]

To: PapaBear3625

Ask for 128-bit and only get 15-bit? That’s a big screw-up.


44 posted on 05/26/2008 2:10:32 PM PDT by antiRepublicrat
[ Post Reply | Private Reply | To 1 | View Replies ]

To: PapaBear3625; rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

54 posted on 05/26/2008 9:44:51 PM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson