The Heartbleed Challenge
61–70 of 125 posts
Re: The Heartbleed Challenge
#62Earlier quoted context omitted.
Cloudfare isn't making the same claim - they're just saying it doesn't seem to happen on their (modified) Nginx setup.
I do not understand what you are trying to convey in your message. I never mentioned Cloudflare and neither did the comment I was responding to. What part of my comment led you to believe I was presenting/responding-to a claim made by cloudflare?
But maybe you meant that he's alrady been proven wrong, and the nsa would be another? Then I did misinterpret that bit.
Re: The Heartbleed Challenge
#63OpenSSL/0.9.8o zlib/1.2.3.4 libidn/1.15 libssh2/1.2.6 Host: www.cloudflarechallenge.com Accept: / PrivateKey: EiS3mdBFanVEaeRkk4otJRRHFTGi6tVZUJKl5v7rGpjJnY0gTn4PWSlOJqA2l32o Content-Length: 1721 Content-Type: application/x-www-form-urlencoded Expect: 100-continue
Re: The Heartbleed Challenge
#64Re: The Heartbleed Challenge
#65Re: The Heartbleed Challenge
#66Re: The Heartbleed Challenge
#67Re: The Heartbleed Challenge
#68Earlier quoted context omitted.
I'm disgusted they chose to share it with you early and not the major Linux distros...
There's no way to share such a bug with the major Linux distros and let them deploy a fix to users without making it public at the same time. Even assuming that the distros commit to handle the fix submission and silently repackage openssl (which they don't always do, depending on their policy), the word would get out minutes after it's pushed to the update servers. So telling major Linux distros == telling the publi…
Re: The Heartbleed Challenge
#69Earlier quoted context omitted.
You all are involved in so many great open source projects -- just wanted to give a shout-out to Conformal. People do notice and appreciate your contributions. How many full-time people are working there?
we appreciate your supportive comments :) there are about 10 of us at conformal.
Re: The Heartbleed Challenge
#70Earlier quoted context omitted.
I'm disgusted they chose to share it with you early and not the major Linux distros...
There's no way to share such a bug with the major Linux distros and let them deploy a fix to users without making it public at the same time. Even assuming that the distros commit to handle the fix submission and silently repackage openssl (which they don't always do, depending on their policy), the word would get out minutes after it's pushed to the update servers. So telling major Linux distros == telling the publi…