Cryptographic weakness on Debian systems
Posted May 13, 2008 22:10 UTC (Tue) by philh
In reply to: Cryptographic weakness on Debian systems
Parent article: Cryptographic weakness on Debian systems
... quite another to trust that they know what they're doing modifying complicated software like this to try to "fix" security problems.
Well, that would be fair comment if Kurt Roeckx (one of the Debian openssl maintainers) had taken it upon himself to make this change in isolation, but as you can see from this thread, the patch was mentioned to the openssl-dev list, without provoking negative comment, so it's difficult to know who one should be pointing fingers at.
Mistakes happen -- looking for someone to blame isn't overly productive at the best of times, and when it is based on false premises, not at all.
to post comments)