Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I remember this bug. It was what made my interest in systems engineering soar. Unfortunately your characterization of it falls quite short.

Here's the mailing list email that inspired the bug:

https://marc.info/?l=openssl-dev&m=114651085826293&w=2

I kind of doubt that some guy that thinks he "knows better than the OpenSSL developers" is saying things like this on their mailing list:

> What I currently see as best option is to actually comment out those 2 lines of code. But I have no idea what effect this really has on the RNG. The only effect I see is that the pool might receive less entropy. But on the other hand, I'm not even sure how much entropy some unitialised data has.

The result was something like 32k sources of entropy which is not enough.

Here's the bug Kurt was trying to fix: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=363516



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: