How I Tripped Over the Debian Weak Keys Vulnerability
Posted: Tue, 9 April 2024
| permalink
|
No comments
Those of you who haven’t been in IT for far, far too long might not know that next month will be the 16th(!) anniversary of the disclosure of what was, at the time, a fairly earth-shattering revelation: that for about 18 months, the Debian OpenSSL package was generating entirely predictable private keys.
The recent xz-stential threat (thanks to @nixCraft for making me aware of that one), has got me thinking about my own serendipitous interacti...
Read more at hezmatt.org