Willem Pinckaers on Akamai's flawed OpenSSL allocator patch
1–10 of 79 posts
Re: Willem Pinckaers on Akamai's flawed OpenSSL allocator patch
#2Re: Willem Pinckaers on Akamai's flawed OpenSSL allocator patch
#3(I worked with Willem at Matasano for a couple years, and he knows what he's talking about.)
Re: Willem Pinckaers on Akamai's flawed OpenSSL allocator patch
#4Re: Willem Pinckaers on Akamai's flawed OpenSSL allocator patch
#5Re: Willem Pinckaers on Akamai's flawed OpenSSL allocator patch
#6(I worked with Willem at Matasano for a couple years, and he knows what he's talking about.)
Re: Willem Pinckaers on Akamai's flawed OpenSSL allocator patch
#7'...This patch is a variant of what we've been using to help protect customer keys for a decade.
This should really be considered more of a proof of concept than something that you want to put directly into production. It slides into the ASN1 code rather than adding a new API (OPENSSL_secure_allocate et al), the overall code isn't portable, and so on. If there is community interest, we would be happy to help work on addressing those issues. Let me restate that: do not just take this patch and put it into production without careful review.'
Re: Willem Pinckaers on Akamai's flawed OpenSSL allocator patch
#8There could be other pieces that we're missing, and this patch alone doesn't prove that you can obtain private keys from Akamai's servers with the Heartbleed bug. It just proves that there could be key parts outside of their protected storage area and they suck at creating patches of their modifications. That being said, I'd love to see someone apply Akamai's OpenSSL patch and still pull the key with Heartbleed.
Re: Willem Pinckaers on Akamai's flawed OpenSSL allocator patch
#9Everyone involved in this, from the people who wrote the heartbeat code, the people who committed the code, the people at Akami who wrote this patch, this poster ... all would describe themselves as security engineers. Is everyone but Willem Pinckars incompetent?
I think the one lesson to learn is to treat crypto just like you do cloud providers. Make sure you have an exit strategy from day one; the ability to push a button to roll keys, switch algorithms, switch cert providers, etc.
Re: Willem Pinckaers on Akamai's flawed OpenSSL allocator patch
#10(I worked with Willem at Matasano for a couple years, and he knows what he's talking about.)
The tone of his post is rather unfortunate. Still, he raises good points, even if they are put in an unnecessarily aggressive manner.