Patch OpenSSL on November 1 to avoid “critical” security vulnerability
1–10 of 217 posts
Re: Patch OpenSSL on November 1 to avoid “critical” security vulnerability
#2Re: Patch OpenSSL on November 1 to avoid “critical” security vulnerability
#3No post body was provided.
Re: Patch OpenSSL on November 1 to avoid “critical” security vulnerability
#4How many times does this have to happen before we start rejecting components written in unsafe languages?
Re: Patch OpenSSL on November 1 to avoid “critical” security vulnerability
#5No post body was provided.
Re: Patch OpenSSL on November 1 to avoid “critical” security vulnerability
#6How many times does this have to happen before we start rejecting components written in unsafe languages?
You first. What browser and OS are you posting from?
Re: Patch OpenSSL on November 1 to avoid “critical” security vulnerability
#7November 1st is a bank holiday in France, so a lot of sysadmins won’t be happy and systems will be vulnerable.
Re: Patch OpenSSL on November 1 to avoid “critical” security vulnerability
#8Quoted post unavailable.
Get started then. We can't use something with no track record nor releases published in production systems.
Re: Patch OpenSSL on November 1 to avoid “critical” security vulnerability
#9> And by widely leveraged, I mean almost completely ubiquitous, if you’re using HTTPS, chances are you’re using OpenSSL. Almost everyone is.
This is probably a bit of an exaggeration. There are quite a few other SSL implementations that actually are also "widely leveraged"[1]. In particular, LibreSSL was forked and cleaned up after Heartbleed. Google uses BoringSSL. GnuTLS is widely used and unrelated to OpenSSL.
[1] https://en.wikipedia.org/wiki/Comparison_of_TLS_implementati...