Live data from Hacker News

SLOTH – Security Losses from Obsolete and Truncated Transcript Hashes

mitls.org

21–22 of 22 posts

Re: SLOTH – Security Losses from Obsolete and Truncated Transcript Hashes

#21
post #13

It's not clear if the JRE6 and the JRE7 are impacted (does the JSSE shipped with them support TLS1.2)? If so, pretty worrying as not supported anymore yet widely deployed.

OpenJDK7 (not sure about 6) is still getting updates. I think Redhat is sponsoring that.

Re: SLOTH – Security Losses from Obsolete and Truncated Transcript Hashes

#22
post #20

Earlier quoted context omitted.

Oh yeah, they're kicking ass on every front of this sub-field. Then, Leroy et al are doing that for compilers and language analysis at INRIA as well. Then Astree is leading it for static analysis of C. France, esp INRIA, seems to be in the lead on verified software with a real-world focus. It will be great when more elsewhere follow suit.

Galois just gave a talk on high assurance crypto at RWC (they made cryptol and other open sourced tools to give formal proofs of security)

Oh yeah, Galois is another one of the greats in the field. They just keep cranking out one practical thing after another. At a higher pace than most it seems. Here are a few good things on their end.

Scrolling their blog is endless insights https://galois.com/blog/

CRYPTOL's open source page http://www.cryptol.net/

SMACCMPilot has things like Ivory language http://smaccmpilot.org/

GitHub site with 8 pages worth of their stuff https://github.com/galoisinc

Post reply on HN