Predictable RNG in the vulnerable Debian OpenSSL package
the What and the How
Original File: 25c3-2995-en-predictable_rng_in_the_vulnerable_debian_openssl_package.mp4 |
About: Predictable RNG in the vulnerable Debian OpenSSL package | Report Broken File | embed video
About: Predictable RNG in the vulnerable Debian OpenSSL package | Report Broken File | embed video
Recently, the Debian project announced an OpenSSL package vulnerability which they had been distributing for the last two years. This bug makes the PRNG predictable, affecting the keys generated by openssl and every other system that uses libssl (eg. openssh, openvpn).
Persons:- Luciano Bello
- Maximiliano Bertacchini