On Wed, May 14, 2008 at 12:48:41AM +0200, chefren wrote:Of course it is wrong to /depend/ on uninitialized mem to stir a random pool. Often "uninitialized" means lots of zeroes or predictable stack contents. But the actual Debian diff that was committed removes any stirring, it seems. From a quick view, no actual data from the passed in argument is being used to stir the pool anymore. Now that is the real problem. Because even if you have collected nice date with high entropy to seed the PRNG, it will be ignored. The openssl-dev list did not spot that, and indeed, that is disturbing. But Kurt never actually posted a diff there: so it's easy for the two two sided to be talking about different things. As for the arrogance: i'm pretty sure openssl proper contains more bugs. When I wrote our dc(1) (which uses the bignum lib from openssl) that occurred whan adding 0 to a bignum A, which resulted in A not being equal to the result. I was quite suprised that bug was never found before. Probably crypto code only covers parts of the bignum functionality. The handing of that bug was adequate, though. -Otto
| Greg Kroah-Hartman | [PATCH 008/196] Chinese: add translation of volatile-considered-harmful.txt |
| Chuck Ebbert | Why do so many machines need "noapic"? |
| Bernd Paysan | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Karsten Keil | [PATCH] mISDN cleanup user interface |
git: | |
| Thomas Glanzmann | GIT Packages for Debian Etch |
| Johannes Sixt | [PATCH 04/40] Windows: Use the Windows style PATH separator ';'. |
| Steven Grimm | StGIT vs. guilt: What's the difference? |
| Nguyen Thai Ngoc Duy | Re: VCS comparison table |
| Marcos Laufer | dmesg IBM x3650 OpenBSD 4.3 |
| askthelist | Packets Per Second Limit? |
| Richard Stallman | Real men don't attack straw men |
| Jason Dixon | Re: About Xen: maybe a reiterative question but .. |
| KOSAKI Motohiro | [bug?] tg3: Failed to load firmware "tigon/tg3_tso.bin" |
| Natalie Protasevich | [BUG] New Kernel Bugs |
| Kasper Sandberg | Re: Realtek 8111c weirdness problems, apic/msi, and normal bug |
| Francois Romieu | Re: 8169 Intermittent ifup Failure Issue With RTL8102E Chipset in Intel's New D945... |
| Shared swap partition | 9 hours ago | Linux general |
| high memory | 2 days ago | Linux kernel |
| semaphore access speed | 2 days ago | Applications and Utilities |
| the kernel how to power off the machine | 2 days ago | Linux kernel |
| Easter Eggs in windows XP | 2 days ago | Windows |
| Root password | 2 days ago | Linux general |
| Where/when DNOTIFY is used? | 2 days ago | Linux kernel |
| How to convert Linux Kernel built-in module into a loadable module | 2 days ago | Linux kernel |
| Linux 2.6.24 and I/O schedulers | 2 days ago | Linux kernel |
| USB Driver -- Interrupt Polling -- A Little Help Please | 2 days ago | Linux general |
