Archive 14. May 2008

Debian and OpenSSL: The Aftermath - for anyone who has doubts whether they need to recreate their keys: "However, rather than fix the calls to RAND_add(), the Debian maintainer instead removed the code that added the buffer handed to ssleay rand add() to the pool. This meant that the pool ended up with essentially no entropy. Clearly this was a very bad idea." - yes, "essentially no entropy" when generating keys is a really bad idea. Ouch.

Panorama freedom in danger - great, now they're making photography completely impossible by requiring every little thing to be registered with permission in triplicate and checked with the big boss first. What nonsense? Public space is public space, even if there's some alleged art crap standing around. With the cultural understanding of our prolethicians (who are usually responsible for the "beautification" of public space), these things are mostly just disruptive to photography anyway... (yes, I saw the note about "commercial use" - but since commercial intent is often attributed to blogs, photo bloggers quickly find themselves in a gray area)

Vendors Are Bad For Security - about the "bugfix" in Debian that has made all generated OpenSSL keys more or less unusable since 2006. Thanks for the extra work, you idiots. Funny also the comments in which the OpenSSL developer gets his own rant stuffed back down his throat because the OpenSSL idiots did not deem it necessary to deal with the fix suggested by the Debian developers (except for one who actually signaled thumbs-up). Well. All software sucks.

Wallraff exposes malpractices in bread factory - how to make a lot of noise with small bread rolls ...