Stories
Slash Boxes
Comments

SoylentNews is people

posted by janrinok on Wednesday February 18 2015, @10:20AM   Printer-friendly
from the update-now! dept.

A major announcement on the FreeBSD mailing list landed earlier today:

URGENT: RNG broken for last 4 months in the -current branch [...] This means most/all keys generated may be predictable and must be regenerated. This includes, but not limited to, ssh keys and keys generated by openssl. This is purely a kernel issue, and a simple kernel upgrade w/ the patch is sufficient to fix the issue.

Various security companies and blogs are already reporting duplicate keys spotted in the wild. So, patch your systems!.

[Updates: (1) This pertains to the '-current' branch which is not recommended for use on production systems. (2) The statement about "duplicate keys" was in the original submission, but lacks confirmation. If you can confirm/deny, please reply in the comments with a link to the source.]

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2, Funny) by ThG on Wednesday February 18 2015, @11:12AM

    by ThG (4568) on Wednesday February 18 2015, @11:12AM (#146478)
    Starting Score:    1  point
    Moderation   +1  
       Funny=1, Total=1
    Extra 'Funny' Modifier   0  

    Total Score:   2  
  • (Score: 2) by FatPhil on Wednesday February 18 2015, @02:17PM

    by FatPhil (863) <{pc-soylent} {at} {asdf.fi}> on Wednesday February 18 2015, @02:17PM (#146516) Homepage
    That's OpenBSD. It's also user-space (the C library), not a kernel-based generator.

    Also, when I raised the topic amongst C standard experts (which included committee members) the general consensus was that Ted and Theo were at least in part talking crap. However, it was suggested that I should raise a DR on the standard, so that the wording could leave less room for the misinterpretation that Theo and Ted have tricked themselves into believing.
    --
    Great minds discuss ideas; average minds discuss events; small minds discuss people; the smallest discuss themselves