Live data from Hacker News

OpenSSL.org hacked?

openssl.org

91–98 of 98 posts

Re: OpenSSL.org hacked?

#91

Earlier quoted context omitted.

Or maybe they should have plaintext access, because then they can get the software if they don't have an SSL-enabled HTTP client, and they can compare the digital signature of the sources later via 3rd parties. But this is all crap, really. OpenSSL is a library distributed across tens of thousands of independent providers all over the internet. Nobody needs to get it from the main site, and even if they do, there's a…

You seem to have completely missed the fact that HSTS can be combined with an STS preloaded list, to which the previous comment author also gave you a reference to read. HSTS is TOFU (trust-on-first-use) by default, but the TOFU portion can be upgraded to a full PKI-based authentication mechanism just fine using preloaded lists, which doesn't require any previous visits whatsoever. Furthermore, it's just embarrassing…

In reverse:

1. These attacks don't bear at all on cryptographic building blocks, because any script kiddie can brute force a login or fuzz an input, etc. Has nothing to do with crypto at all. Has nothing to do with their code at all. Completely different systems with completely different attacks with incredibly different requirements... it's worlds apart. There is nothing about defacing a website or even MITM that could ever be compared to breaking a crypto library.

2. HSTS is quite a bit different from the PKI of TLS. That said, what you are basically saying is "HSTS is the same thing as HTTPS when you add the URL to the browser's STS whitelist". (Which could be avoided altogether if you just type "https")

So what your argument really boils down to is: a crypto library is worthless because we really need to use HSTS because OpenSSL.org users are too stupid to type "https".

Not only is this inaccurate and nonsensical, it's just a crappy security model. Now I have to manage HSTS exactly the same way TLS certs are managed and basically reproduce one protocol into a pseudo-protocol and juggle both, keeping things like RFC 6797 in mind. Suddenly the complexity's gone up enormously over time, only to prevent MITM on the client, and we don't even consider whether or not the content was compromised before the connection of the client to the server.

Even if the server is hacked, you still have absolutely no guarantee if the content was modified, because you're not verifying the content once you download it. But sure. Let's freak out about the possibility of a one-sided MITM to the client over HTTP (which every idiot knows is not secure by design), because that's clearly the most important or likely attack to be worried about right now.

Re: OpenSSL.org hacked?

#93
post #27
post #12

Earlier quoted context omitted.

This shows that website security depends on far more than just deploying over SSL.

Who runs OpenSSL? Is it again volunteer? I think big companies need to step in and help creating infrastructure for these big projects.

This seems to be based on the humorous idea that big companies provide better security.

Re: OpenSSL.org hacked?

#94

Earlier quoted context omitted.

But what if they return a joke, so funny, that it kills whoever reads it?

Then they should split on spaces and only read one word at a time

This is a proven method, but care must be taken to make sure no individual gets more than on word to translate at a time.

https://en.m.wikipedia.org/wiki/The_funniest_joke_in_the_wor...

Re: OpenSSL.org hacked?

#95

Earlier quoted context omitted.

But what if the page uses HTML5 audio to "jump the gap" and reprogram all nearby electronic devices to attack you on 1/1/2014!?

That's professional paranoia right there. Someone give this man a job and a hard hat.

A tin-foil hat would probably be better off for his situation.

It prevents mind reading.

Re: OpenSSL.org hacked?

#97
post #88

Earlier quoted context omitted.

Ever seen a graffiti of someones name you can't even decipher on the back of a trash can at the far off bus stop near the forest? It's kind of like that.

Well, that makes sense. But why announce that you're Turkish? For example, there are lots of Russian hackers and skiddies, but I have never seen a cr3w called RussiaStrongSec.

Sometimes they are spreading a political message (I've seen more Syrian hackers than Turkish on defaced websites recently, incidentally) so they want to spread their identity. Just like hacking groups that are in it for infamy spread their identity.

Of course in some cases they may be false flag operations, always a possibility worth keeping in mind.

Re: OpenSSL.org hacked?

#98

Earlier quoted context omitted.

Obviously, VM should have no access to audio outputs, display driver should be rewritten to scramble output to be only viewable using a Lenslok-like device and the whole setup should run on a isolated computer staying in a clean room with a dead-man switch installed that - in case of unforeseen consequences - would quickly power a whole apartment down and call for emergency.

I think you're neglecting to consider the possibility of seismic communication by doing a lot of client-side computation to make the CPU fan kick on and off.

[deleted]
Post reply on HN