Oh look, another Op...
 

  You don't need to be an 'investor' to invest in Singletrack: 6 days left: 95% of target - Find out more

[Closed] Oh look, another OpenSSL vulnerability that's worse than heartbleed

6 Posts
5 Users
0 Reactions
132 Views
Posts: 251
Full Member
Topic starter
 

[i]Tatsuya Hayashi, the researcher who found one of the critical bugs, told the Guardian that the latest flaw "may be more dangerous than Heartbleed" as it could be used to directly spy on people's communications.

Heartbleed was deemed to be one of the most critical internet vulnerabilities ever when it was uncovered in April. OpenSSL is supposed to protect people’s data with digital keys but has been exposed as flawed numerous times in recent months.

The latest vulnerability was introduced in 1998 and has been missed by both paid and volunteer developers working on the open-source project for 16 years.[/i]

[url= http://www.theguardian.com/technology/2014/jun/06/heartbleed-openssl-bug-security-vulnerabilities ]http://www.theguardian.com/technology/2014/jun/06/heartbleed-openssl-bug-security-vulnerabilities[/url]

Although, I guess if it's been there 16 years maybe it's not *that* bad?


 
Posted : 06/06/2014 10:01 am
 TimP
Posts: 1782
Free Member
 

I have no idea what the title means so I opened it up. Still none the wiser.

Would blu-tac help?


 
Posted : 06/06/2014 10:07 am
 DezB
Posts: 54367
Free Member
 

People get paid to find vulnerabilities.. they find vulnerabilities


 
Posted : 06/06/2014 10:09 am
Posts: 251
Full Member
Topic starter
 

[i]Would blu-tac help? [/i]

40 years of paid and unpaid Blu-Tac research hasn't found any security vulnerabilities with it.

But you never know.


 
Posted : 06/06/2014 10:09 am
 TimP
Posts: 1782
Free Member
 

It does tend to leave greasy marks on walls, but that would not really count as a security risk.


 
Posted : 06/06/2014 10:23 am
Posts: 77347
Free Member
 

Oh for god's sake, really?

On the bright side, at least after last time I've now got extensive documentation as to where OpenSSL is running.


 
Posted : 06/06/2014 12:32 pm
Posts: 8819
Full Member
 

Same here with our products. That doesn't make it easier to get the fixes in, test them and release them before the next tranche get released though.

Heartbleed has focussed the mind of both customers and researchers and I fully expect OpenSSL to get a lot more attention in the upcoming months. So at least I won't be bored.


 
Posted : 06/06/2014 1:04 pm

6 DAYS LEFT
We are currently at 95% of our target!