IWETHEY v. 0.3.0 | TODO
1,095 registered users | 1 active user | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New And it's exactly as bad as stated.
CloudFlare have challenged people to extract their private keys. Mission accomplished, by two people:

http://www.engadget....dflare-challenge/

OK, so this was a stupid buffer overflow. But wait! There's more! The OpenSSL software actually and intentionally circumvents the system malloc, that, in the case of OpenBSD at least, would have prevented this flaw from being the giant clusterfuck it actually is:

Reddit: http://www.reddit.co...ploit_mitigation/

The inimitable Theo on the openbsd.misc list on Gmane:
http://article.gmane...enbsd.misc/211963

Analysis of what's wrong (answer: everything) with OpenSSL's memory allocator:
http://www.tedunangs...sl-freelist-reuse

Article describing the general utter shittiness of OpenSSL's code:
https://www.peereboo...html/openssl.html

New Damn!
So, it wasn't the A Team assigned to develop and maintain critical infrastructure that is SSL.
Alex

“There is a cult of ignorance in the United States, and there has always been. The strain of anti-intellectualism has been a constant thread winding its way through our political and cultural life, nurtured by the false notion that democracy means that "my ignorance is just as good as your knowledge.”

-- Isaac Asimov
New Irony.
That last site has a self-signed certificate.

Wade.
Just Add Story http://justaddstory.wordpress.com/
     Heartbleed and OpenSSL - (folkert) - (27)
         Re: Heartbleed and OpenSSL - (pwhysall) - (6)
             #1353 - (Another Scott) - (1)
                 :0) -NT - (mmoffitt)
             Well dammit -NT - (drook)
             It is even more fun than that - (scoenye) - (1)
                 Look for "pacemaker" as related to heartbleed... - (folkert)
             Amazing... - (folkert)
         It now has its own website.. - (Ashton) - (2)
             Most damning point IMO - (drook) - (1)
                 Yes... this. ^^^ -NT - (folkert)
         XKCD is cool today - (drook) - (1)
             wow - (crazy)
         SJMN: White House and NSA deny they knew about it. - (Another Scott) - (10)
             Re: SJMN: White House and NSA deny they knew about it. - (pwhysall) - (9)
                 I find this comment at Wonkette plausible. - (Another Scott) - (4)
                     Note the followup if you use Chrome. - (Another Scott) - (3)
                         So Google doesn't understand the implications of... - (a6l6e6x) - (2)
                             Deliberately turned off as of 2012 - (scoenye) - (1)
                                 I wonder if "Lifelock" is getting a spike in business... :-( -NT - (Another Scott)
                 Hola Peter.. Query: - (Ashton) - (3)
                     Re: Hola Peter.. Query: - (pwhysall) - (2)
                         hehe. -NT - (Another Scott)
                         No they wouldn't ... they've got Policies -NT - (drook)
         And it's exactly as bad as stated. - (pwhysall) - (2)
             Damn! - (a6l6e6x)
             Irony. - (static)
         Possible nasty side effect on Debian if OpenSWAN is used - (scoenye)

If I bought someone a G5 and they did this to it, I'd break their face.
104 ms