[tor-talk] [cryptography] The Heartbleed Bug is a serious vulnerability in OpenSSL

The Doctor drwho at virtadpt.net
Fri Apr 11 12:49:46 PDT 2014


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 04/11/2014 11:02 AM, Cypher wrote:

> I agree that there is no proof that this bug was introduced on
> purpose and it might be a simple oversight (no matter what it looks
> like or could be). We have to keep in mind that one of the things
> spies do is

I think it's safe to say that all of us have made mistakes that later
came back to bite us.  Not all of them were as critical as Heartbleed,
but neither are any of us perfect.

Additionally, a few folks are calling it the Tequila Hypothesis.
Looking at it that way, the heartbeat feature really might have seemed
like a good idea at the time (regardless of whether or not alcohol was
actually involved).

> NSA/GCHQ. Part of the power these agencies wield is that /we'll
> likely never know/ and so we suspect...everyone. Everything.

They do.

- -- 
The Doctor [412/724/301/703] [ZS]
Developer, Project Byzantium: http://project-byzantium.org/

PGP: 0x807B17C1 / 7960 1CDC 85C9 0B63 8D9F  DD89 3BD8 FF2B 807B 17C1
WWW: https://drwho.virtadpt.net/

"Look up! Look down! Now look at Mr. Frying Pan!" --George Newman, _UHF_

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iEYEAREKAAYFAlNIR1oACgkQO9j/K4B7F8FppwCgokjuzqzUOvp0JVkjn6z8qTUF
REAAoKT8Q5uglU9nV9g9NyKaW031HIYv
=t3qU
-----END PGP SIGNATURE-----



More information about the cypherpunks mailing list