Tag Archive for: OpenSSL

OpenSSL warns vendors against using vulnerability info for marketing

Security advisories for OpenSSL should not be used for competitive advantage, according to the development project behind the widely used cryptography component.

The warning comes from the OpenSSL Project, which has published for the first time guidelines for how it internally handles security problems, part of an ongoing effort to strengthen the project following the Heartbleed security scare in April.

High severity issues such as remote code execution vulnerabilities will be kept private within OpenSSL’s development team, ideally for no longer than a month until a new release is ready.

To read this article in full or to leave a comment, please click here

Network World Security

Google unveils independent “fork” of OpenSSL called “BoringSSL”

dvs

Google is releasing its own independently developed “fork” of OpenSSL, the widely used cryptography library that came to international attention following the Heartbleed vulnerability that threatened hundreds of thousands of websites with catastrophic attacks.

The unveiling of BoringSSL, as the Google fork has been dubbed, means there will be three separate versions of OpenSSL, which is best known for implementing the secure socket layer and transport layer security protocols on an estimated 500,000 websites. Developers of the OpenBSD operating system took the wraps off LibreSSL a few weeks after the surfacing of Heartbleed. Google is taking pains to ensure BoringSSL won’t unnecessarily compete or interfere with either of those independent projects. Among other things, the company will continue to back the Core Infrastructure Initiative, which is providing $ 100,000 in funding to OpenSSL developers so they can refurbish their badly aging code base.

“But we’ll also be more able to import changes from LibreSSL and they are welcome to take changes from us,” Adam Langley, a widely respected cryptography engineer and Google employee, wrote in a blog post introducing BoringSSL. “We have already relicensed some of our prior contributions to OpenSSL under an ISC license at their request and completely new code that we write will also be so licensed.”

Read 6 remaining paragraphs | Comments


Ars Technica » Technology Lab

Latest OpenSSL flaws can lead to information leakage, code execution and DoS

Only two months after the Heartbleed vulnerability in OpenSSL captured global headlines we have another critical update for OpenSSL fixing 6 new flaws.
Naked Security – Sophos

OpenSSL bug, DDoS bust, Snapchat SNAFU and a free Threatsaurus – 60 Sec Security [VIDEO]

Can a bug ever be good? What’s the prison sentence for DDoS criminality? How well does Snapchat protect your data? What’s a Threatsaurus, and why do you want one? Watch and find out!
Naked Security – Sophos