LWN.net Logo

Impact of the Debian OpenSSL vulnerability

Impact of the Debian OpenSSL vulnerability

Posted May 16, 2008 19:03 UTC (Fri) by clugstj (subscriber, #4020)
Parent article: Impact of the Debian OpenSSL vulnerability

If the only source of entropy was the PID of the process generating the key, wouldn't it be
easy to produce a list of ALL of the weak keys?


(Log in to post comments)

Impact of the Debian OpenSSL vulnerability

Posted May 16, 2008 20:09 UTC (Fri) by kmccarty (subscriber, #12085) [Link]

Yes, and it is already done, see reference 3 of the article.

Impact of the Debian OpenSSL vulnerability

Posted May 16, 2008 20:14 UTC (Fri) by kmccarty (subscriber, #12085) [Link]

correcting myself slightly...

it appears that they have not yet generated (or at least not made available) keys that would
have been created by 64-bit or big-endian systems, but those would only be a small subset of
the total number of Debian-generated keys out in the wild.

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds