The Heartbleed Bug
31–40 of 547 posts
Re: The Heartbleed Bug
#32Here's the patch/commit, I don't know why it's not linked form the OpenSSL changelog or heartbleed.com. A suspicious lack of transparency. http://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=...
Re: The Heartbleed Bug
#33How's that for responsible disclosure?
Re: The Heartbleed Bug
#34What a great writeup. Comprehensive without being overly verbose, answers to "what does this mean?" and "does this affect me?", and clear calls to action. While I'm not happy at having to spend my Monday patching a kajillion machines, I welcome more vulnerability writeups in this vein.
Writeup was too long. We need to know the short and sweet of what to fix.
Re: The Heartbleed Bug
#35Earlier quoted context omitted.
The bug is in the handling of the TLS protocol itself (actually, in a little-used extension of TLS, the TLS Record Layer Heartbeat Protocol), and isn't exposed in applications that just use TLS for crypto primitives.
Sooo in layman's terms - we only need to be worrying about HTTPS and not SSH ?
Re: The Heartbleed Bug
#36As of now (21:04 UTC) this isn't fixed in Debian https://security-tracker.debian.org/tracker/CVE-2014-0160 nor Ubuntu http://people.canonical.com/~ubuntu-security/cve/2014/CVE-20... Got a long night ahead :/
Re: The Heartbleed Bug
#37Re: The Heartbleed Bug
#38Earlier quoted context omitted.
The bug is in the handling of the TLS protocol itself (actually, in a little-used extension of TLS, the TLS Record Layer Heartbeat Protocol), and isn't exposed in applications that just use TLS for crypto primitives.
Does sshd only use TLS/OpenSSL "for crypto primitives"? Or not use OpenSSL at all?
Re: The Heartbleed Bug
#39To me it sounds kind of like finding out the fence in your backyard was cut open two years ago. Except in this case the backyard is two thirds of the internet.
Re: The Heartbleed Bug
#40Are people going straight to buying new domain names for every TLS bug discovered these days?
I'd be surprised if heartbleed.com was still available in 2014
http://www.networksolutions.com/whois/results.jsp?domain=hea...