D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] OpenSSL 1.0.1 "Heartbleed" vulnerability

 

On Tue, Apr 08, 2014 at 08:46:09PM +0100, bad apple wrote:
> Simon also understands why PFS is a *major* mitigation factor in this
> debacle, not sure why everyone else didn't immediately grasp the value
> of it.

Everyone else = me.

I don't think PFS prevents the leaking of usernames and passwords
submitted to a web server (as in: the process). Or that it means
someone with the private key for your X.509 certificate can't do any
harm with it. Or that other sensitive information handled by the server.

I agree not using PFS makes this vulnerability even worse. It's just so
bad even with PFS.
 
> So, what do you all think then? Worst bug in recent history? I'd have to
> go back a fair way to think of something nastier or more widespread than
> this.

I wouldn't know what else deserves that label.

Martijn.


-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq