Stories
Slash Boxes
Comments

SoylentNews is people

posted by janrinok on Wednesday February 18 2015, @10:20AM   Printer-friendly
from the update-now! dept.

A major announcement on the FreeBSD mailing list landed earlier today:

URGENT: RNG broken for last 4 months in the -current branch [...] This means most/all keys generated may be predictable and must be regenerated. This includes, but not limited to, ssh keys and keys generated by openssl. This is purely a kernel issue, and a simple kernel upgrade w/ the patch is sufficient to fix the issue.

Various security companies and blogs are already reporting duplicate keys spotted in the wild. So, patch your systems!.

[Updates: (1) This pertains to the '-current' branch which is not recommended for use on production systems. (2) The statement about "duplicate keys" was in the original submission, but lacks confirmation. If you can confirm/deny, please reply in the comments with a link to the source.]

This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 5, Informative) by Anonymous Coward on Wednesday February 18 2015, @10:36AM

    by Anonymous Coward on Wednesday February 18 2015, @10:36AM (#146467)

    Apparently this issue only affects people running the current version (unstable/testing branch). If you're on 10.1 (the latest production release) you should be fine.

  • (Score: 2, Troll) by E_NOENT on Wednesday February 18 2015, @11:10AM

    by E_NOENT (630) on Wednesday February 18 2015, @11:10AM (#146477) Journal

    Schadenfreude levels: increasing...

    --
    I'm not in the business... I *am* the business.
  • (Score: 2, Funny) by ThG on Wednesday February 18 2015, @11:12AM

    by ThG (4568) on Wednesday February 18 2015, @11:12AM (#146478)
    • (Score: 2) by FatPhil on Wednesday February 18 2015, @02:17PM

      by FatPhil (863) <{pc-soylent} {at} {asdf.fi}> on Wednesday February 18 2015, @02:17PM (#146516) Homepage
      That's OpenBSD. It's also user-space (the C library), not a kernel-based generator.

      Also, when I raised the topic amongst C standard experts (which included committee members) the general consensus was that Ted and Theo were at least in part talking crap. However, it was suggested that I should raise a DR on the standard, so that the wording could leave less room for the misinterpretation that Theo and Ted have tricked themselves into believing.
      --
      Great minds discuss ideas; average minds discuss events; small minds discuss people; the smallest discuss themselves
  • (Score: 4, Informative) by Marand on Wednesday February 18 2015, @11:30AM

    by Marand (1081) on Wednesday February 18 2015, @11:30AM (#146483) Journal

    It sounds like they got their RNG from Debian [debian.org] :)

    • (Score: 0) by Anonymous Coward on Thursday February 19 2015, @03:52AM

      by Anonymous Coward on Thursday February 19 2015, @03:52AM (#146832)

      Which was defective by design (Debian). Intentional "oops lets fuck with what the OpenBSD guys did RNG wise". """oops"""
      It was intentional.

      Same with systemd.

  • (Score: 5, Informative) by TheRaven on Wednesday February 18 2015, @11:37AM

    by TheRaven (270) on Wednesday February 18 2015, @11:37AM (#146484) Journal
    First, this is only in -CURRENT, it is not in any release. The pre-built images for -CURRENT come with a warning saying 'don't use this in production'. Bugs happen in -CURRENT, that's why it exists - to allow wider testing before things get merged back into a release.

    Second, a big [citation needed] for the 'Various security companies and blogs are already reporting duplicate keys spotted in the wild' - none of them have reported them to the FreeBSD project or on the project's mailing lists...

    --
    sudo mod me up
    • (Score: 0) by Anonymous Coward on Wednesday February 18 2015, @07:55PM

      by Anonymous Coward on Wednesday February 18 2015, @07:55PM (#146655)

      The second one is somewhat right. Shodan's blog is reporting numerous duplicate keys found in ssh installs. However, that does not appear to be related to this PRNG issue.

  • (Score: 4, Funny) by Anonymous Coward on Wednesday February 18 2015, @11:44AM

    by Anonymous Coward on Wednesday February 18 2015, @11:44AM (#146485)
    • (Score: -1, Disagree) by Anonymous Coward on Wednesday February 18 2015, @12:13PM

      by Anonymous Coward on Wednesday February 18 2015, @12:13PM (#146493)

      Randall is a fucking asshole who fucks canine bitch anuses and calls all of his bitches Megan.

    • (Score: 4, Funny) by Anonymous Coward on Wednesday February 18 2015, @01:05PM

      by Anonymous Coward on Wednesday February 18 2015, @01:05PM (#146502)

      Obligatory Dilbert [dilbert.com]

    • (Score: 2) by fritsd on Wednesday February 18 2015, @01:28PM

      by fritsd (4586) on Wednesday February 18 2015, @01:28PM (#146504) Journal

      It doesn't say *who* at the IEEE committed that patch ;-)

  • (Score: 0) by Anonymous Coward on Wednesday February 18 2015, @12:32PM

    by Anonymous Coward on Wednesday February 18 2015, @12:32PM (#146496)

    If you can confirm/deny, please reply in the comments with a link to the source.

    This is the internet, the wild west of anonymity and irresponsible expression of free speech. I can be convinced to confirm or deny these statements based on your willingness to offset my efforts with appropriate compensation. Here is a link [google.com] to my source.