16 years of CVE-2008-0166 – Debian OpenSSL Bug
16years.secvuln.info
16 years of CVE-2008-0166 – Debian OpenSSL Bug
1–10 of 68 posts
Re: 16 years of CVE-2008-0166 – Debian OpenSSL Bug
#2> The security team at Seznam - a Czech search engine and email provider - did not believe me when I reported this issue. They assume that as they are not actively using that key (beta._domainkey.seznam.cz), that means that it cannot be used to forge emails. This is, of course, not true.
Maybe consult a lawyer first, but the entertaining answer would surely be to tell them about the problem in an email from their own domain? (Though seriously, double-check that that's not illegal; funny isn't worth getting arrested.)
Re: 16 years of CVE-2008-0166 – Debian OpenSSL Bug
#3That is OK, but I heard there were lots of security issues with pips too. From one issue to maybe another ?
If you are worried, I would just recreate your keys.
Re: 16 years of CVE-2008-0166 – Debian OpenSSL Bug
#4I enjoyed the... I guess "narrative Q&A" style would be a good enough way to describe it? Regardless, it's fun. > The security team at Seznam - a Czech search engine and email provider - did not believe me when I reported this issue. They assume that as they are not actively using that key (beta._domainkey.seznam.cz), that means that it cannot be used to forge emails. This is, of course, not true. Maybe consult a law…
That being said, a company which is that lax with reported vulnerabilities is not likely to handle "fun" well and even if what you are doing is legal, being involved in a lawsuit is no fun and probably not worth it, since, in the end, you are trying to help them.
Re: 16 years of CVE-2008-0166 – Debian OpenSSL Bug
#5I enjoyed the... I guess "narrative Q&A" style would be a good enough way to describe it? Regardless, it's fun. > The security team at Seznam - a Czech search engine and email provider - did not believe me when I reported this issue. They assume that as they are not actively using that key (beta._domainkey.seznam.cz), that means that it cannot be used to forge emails. This is, of course, not true. Maybe consult a law…
That's the IT sec version of placing your CV on their server to apply :) That being said, a company which is that lax with reported vulnerabilities is not likely to handle "fun" well and even if what you are doing is legal, being involved in a lawsuit is no fun and probably not worth it, since, in the end, you are trying to help them.
Has this actually ever happened or been solicited? That’s an interesting thought experiment.
https://en.wikipedia.org/wiki/Calling_card_(crime)
Re: 16 years of CVE-2008-0166 – Debian OpenSSL Bug
#6So to check your keys, you are asked to grab a pip package. That is OK, but I heard there were lots of security issues with pips too. From one issue to maybe another ? If you are worried, I would just recreate your keys.
https://SLSA.dev/ recommends TUF and Sigstore.dev and trusted containers for build-signing.
Someday, Twine should prompt a PyPI package uploader to sign the package before uploading it, and download it to (prime the CDN cache and) check the Publisher and Package repo signature(s) at least once.
Re: 16 years of CVE-2008-0166 – Debian OpenSSL Bug
#7Re: 16 years of CVE-2008-0166 – Debian OpenSSL Bug
#8I enjoyed the... I guess "narrative Q&A" style would be a good enough way to describe it? Regardless, it's fun. > The security team at Seznam - a Czech search engine and email provider - did not believe me when I reported this issue. They assume that as they are not actively using that key (beta._domainkey.seznam.cz), that means that it cannot be used to forge emails. This is, of course, not true. Maybe consult a law…
Re: 16 years of CVE-2008-0166 – Debian OpenSSL Bug
#9Earlier quoted context omitted.
That's the IT sec version of placing your CV on their server to apply :) That being said, a company which is that lax with reported vulnerabilities is not likely to handle "fun" well and even if what you are doing is legal, being involved in a lawsuit is no fun and probably not worth it, since, in the end, you are trying to help them.
> That's the IT sec version of placing your CV on their server to apply :) Has this actually ever happened or been solicited? That’s an interesting thought experiment. https://en.wikipedia.org/wiki/Calling_card_(crime) https://en.wikipedia.org/wiki/Website_defacement https://attrition.org/mirror/ https://www.zone-h.org/archive
Re: 16 years of CVE-2008-0166 – Debian OpenSSL Bug
#10https://news.ycombinator.com/item?id=40320166
To soon?
(Note I run Debian all over the place, and am generally happy with it.)