Main Contents

Debian’s patch against OpenSSL

May 13, 2008

A critical security advisory has been released: a Debian packager maintainer modified the source code of OpenSSL removing the seeding of the random number generator: the cryptographic keys generated on Debian (and derivate distros) from 2006 to today are guessable.
Here’s the patch:

(xkcd.com)

Filed under: debian, security |

Leave a comment