Wednesday, July 16, 2014

LibreSSL not safe - Culprit is PRNG



I am not losing hope (yet)



(From the article)

The first "preview" release of OpenSSL alternative LibreSSL is out, and already a researcher says he has found a "catastrophic failure" in the version for Linux.

The problem resides in the pseudo random number generator (PRNG) that LibreSSL relies on to create keys that can't be guessed even when an attacker uses extremely fast computers.



The link below has more information:-

http://arstechnica.com/security/2014/07/only-a-few-days-old-openssl-fork-libressl-is-declared-unsafe-for-linux/

No comments:

Post a Comment