http://motherboard.vice.com/read/the-united-states-is-angry-that-china-wants-crypto-backdoors-too “You can’t have it both ways,” Trevor Timm, the co-founder and the executive director of the Freedom of the Press Foundation, told Motherboard. “If the US forces tech companies to install backdoors in encryption, then tech companies will have no choice but to go along with China when they demand the same power.”
Apparently, the NSA may have at least known of this bug for a long time, and you can bet your boots they’ve exploited it against someone. Given their propensity for reading the communications of all and sundry, I somehow doubt that only the ‘bad guys’* were targeted. In any case, if the NSA knew about […]
Just when you might have thought it safe to wander out, a reminder that those heartbeats in TLS work both ways, so a malicious server could compromise your client (browser, VPN, and so on) with interesting results. Check https://reverseheartbleed.com/
OpenSSL is not developed by a responsible team. via Re: FYA: http: heartbleed.com.
This is pretty bad : In short, Heartbeat allows one endpoint to go “I’m sending you some data, echo it back to me”. It supports up to 64 KiB. You send both a length figure and the data itself. Unfortunately, if you use the length figure to claim “I’m sending 64 KiB of data” (for […]