D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] OpenSSL 1.0.1 "Heartbleed" vulnerability

 

On Sat, Apr 12, 2014 at 06:44:40AM +0100, Simon Waters wrote:
> Bad Apple specifically said auditing, and I think this is the key.

Exactly.

It is kind of odd, given the tech industry's focus on compliance, that
you can still use a relatively poorly audited piece of software to
protect your secure connections.

And even to protect the key to your castle, as things just took a turn
for the worse:

http://blog.cloudflare.com/answering-the-critical-question-can-you-get-private-ssl-keys-using-heartbleed

Martijn.


-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq