Possibly linux@lemmy.zip to Linux@lemmy.mlEnglish · 9 months agoXZ backdoor in a nutshelllemmy.zipimagemessage-square156fedilinkarrow-up11.14Karrow-down110
arrow-up11.13Karrow-down1imageXZ backdoor in a nutshelllemmy.zipPossibly linux@lemmy.zip to Linux@lemmy.mlEnglish · 9 months agomessage-square156fedilink
minus-squaredan@upvote.aulinkfedilinkarrow-up3·9 months ago OpenSSL did add to the entropy pool a bunch uninitialized memory and the PID. Did they have a comment above the code explaining why it was doing it that way? If not, I’d blame OpenSSL for it. The OpenSSL codebase has a bunch of issues, which is why somewhat-API-compatible forks like LibreSSL and BoringSSL exist.
Did they have a comment above the code explaining why it was doing it that way? If not, I’d blame OpenSSL for it.
The OpenSSL codebase has a bunch of issues, which is why somewhat-API-compatible forks like LibreSSL and BoringSSL exist.