D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] OpenSSL 1.0.1 "Heartbleed" vulnerability

 

On Tue, Apr 08, 2014 at 07:44:51PM +0100, Simon Waters wrote:
> My comments on the page are a bit of a give away ;)

:-)

> I was patching servers, and learning about TLS most of the day. That
> there is more for me to learn about TLS is probably the root of the
> problem, it is too complex.

Indeed. And then people say we should all start using elliptic curve
cryptography.

> I know it was giving false negatives when overloaded. It's evolved a
> fair bit today - hats off to the guy for delivering it so fast and
> scaling it during the day. My efforts at devops pale in comparison.

+1

It was giving a FP on www.example.com, which was nice, as I could use it
in a screen shot for a blog post I wrote on the subject.

This is a nice short video that explains the vulnerability:

http://www.quora.com/Whats-the-impact-of-the-Heartbleed-bug-in-OpenSSL/answer/Zulfikar-Ramzan

Martijn.


-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq