LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Syndicated Linux News (https://www.linuxquestions.org/questions/syndicated-linux-news-67/)
-   -   LXer: Critical crypto bug in OpenSSL opens two-thirds of the Web to eavesdropping (https://www.linuxquestions.org/questions/syndicated-linux-news-67/lxer-critical-crypto-bug-in-openssl-opens-two-thirds-of-the-web-to-eavesdropping-4175500981/)

LXer 04-08-2014 09:21 AM

LXer: Critical crypto bug in OpenSSL opens two-thirds of the Web to eavesdropping
 
Published at LXer:

The warning about the bug in OpenSSL coincided with the release of version 1.0.1g of the open-source program, which is the default cryptographic library used in the Apache and nginx Web server applications, as well as a wide variety of operating systems and e-mail and instant-messaging clients. The bug, which has resided in production versions of OpenSSL for more than two years, could make it possible for people to recover the private encryption key at the heart of the digital certificates used to authenticate Internet servers and to encrypt data traveling between them and end users. Attacks leave no traces in server logs, so there's no way of knowing if the bug has been actively exploited.

Read More...


All times are GMT -5. The time now is 03:41 PM.