Go Back   Club CDFreaks - Knowledge is Power > International Chat: General Topics > Latest News Headlines


Commercial message



Latest News Headlines Discuss, Huge Hole in Open Source Software Found, Leaves Millions Vulnerable at International Chat: General Topics forum; Quote:


Reply
 
Thread Tools
Old 25-05-2008   #1 (permalink)
Moderator
 
platinumsword's Avatar
 
Join Date: Oct 2005
Posts: 2,984
Huge Hole in Open Source Software Found, Leaves Millions Vulnerable

Quote:
It is incredible just how big the effects of the newly discovered error in open source key generation is
Link: http://www.dailytech.com/Huge+Hole+i...ticle11869.htm


platinumsword is offline   Reply With Quote
Old 25-05-2008   #2 (permalink)
CD Freaks Senior Member
 
wazzy's Avatar
 
Join Date: Jan 2006
Location: Under the sheets again!
Posts: 825
Re: Huge Hole in Open Source Software Found, Leaves Millions Vulnerable

Reading that makes me relieved I didn't switch my system over to linux last week
__________________
Show me a sane man and I will cure him .
wazzy is offline   Reply With Quote
Old 25-05-2008   #3 (permalink)
Bob
I donated to the Tsunami fund and all I got was this lousy title
 
Bob's Avatar
 
Join Date: Sep 2004
Location: Looking for my zigzags ~ I come from the no place and i go to the no where
Posts: 16,049
Re: Huge Hole in Open Source Software Found, Leaves Millions Vulnerable

Quote:
Originally Posted by wazzy View Post
Reading that makes me relieved I didn't switch my system over to linux last week
psssst wazzy don't tell debro that
__________________
"You've got a hole in your soul if you don't dig the Blues" .....My New *Build* is Finished.

Click HERE to join CDFreaks.com

Keith Richards ~ "If You Want The Last Laugh........Join The Rolling Stones"
Bob is offline   Reply With Quote
Old 25-05-2008   #4 (permalink)
CDFreaks Resident
 
Chriso's Avatar
 
Join Date: Apr 2003
Location: Liverpool, England
Posts: 2,066
Re: Huge Hole in Open Source Software Found, Leaves Millions Vulnerable

Hmm, that's erm....yeah, not good at all! However it seems to have been limited to a mistake originating in Debian, only affecting Debian and Ubuntu systems. Yay for openSUSE!

So just to clarify, are these keys used for things like remote access via SSH or are they more widespread, for instance being generated for https connections when a server is running one of the aforementioned distros (not many Ubuntu servers that I know of but not sure about Debian)?

I guess it goes to show that all OSs have their flaws, and that no developer is perfect. However if Debian hadn't tried to get clever with their implementation and just left certain things to the openSSH team then it seems this wouldn't have happened!
__________________
Videos of me playing piano, would be nice to have feedback from you all!

[23:49] <Chriso> !seen Boobies
[23:49] <JuPiLeR> I found 430 matches to your query; please refine it to see any output.


OS: openSUSE 10.3 and Windows XP SP2
PSU: Enermax Liberty 400w - Modular
Mobo: Jetway V266B
CPU: AMD AthlonXP 2000+
RAM: 256MB Crucial PC2100 + 512MB Corsair Value Select PC2100
HDD: 120GB Maxtor ATA133 8MB Cache + 320GB Western Digital "RAID Edition" ATA100 8MB Cache
Gfx Card: NVIDIA GeForce 6200 passive cooled
Sound Card: SB Live 1024
DVD-ROM Drive: Asus E-616
CD-RW: LiteON 52246S
DVD-RW: NEC ND2510A in external Firewire enclosure (Prolific chipset)
USB2 Card: ALI chipset (got an NEC chipset one waiting to go in)
Firewire Card: Not sure of chipset...but it seems to work
D-Link Network Card

My old Voodoo 3 2000 PCI has now retired, still in perfect working order though!

Get Firefox!
Join CDFreaks

Chriso is offline   Reply With Quote
Old 29-05-2008   #5 (permalink)
Blown to smitherines
 
debro's Avatar
 
Join Date: Jul 1999
Location: The c@ke mixer
Posts: 9,948
Re: Huge Hole in Open Source Software Found, Leaves Millions Vulnerable

Lol .. limited cypher keys .. err.. oops ...

Luckily it's limited to Debian & debian derivatives and really only affects servers, as they will be generating & distributing keys .. not the general desktop user.

*But Wait! There's still more!

Um, the problem is ... how many corporations are running Debian, or Debian Derivative, servers - Debain is the "Stable release" of the linux world. This problem doesn't just affect Linux users!!!!! It affects anyone which uses a compromised server!!!!!

This problem affects anyone using a debian server -> Anyone using netbanking ever asked their bank what server OS they're using to serve their internet banking site?
Be afraid .. be very afraid Even if you are running windows.
__________________
CDFreaks - Overwhelmed by Ignorance since 2005!
We lost the battle, but we haven't lost the war!
Click Here to sign up to the resistance movement!
Viva La Resistance!

Admitting that you've illegally downloaded movies/songs and need help to process/burn is comparable to robbing a bank, and walking into the bank the next day holding the bags of money to deposit them into your account.
Don't be surprised if people laugh at you when you make the headlines.

debro is online now   Reply With Quote
Old 30-05-2008   #6 (permalink)
Moderator
 
Hemispasm's Avatar
 
Join Date: Mar 2002
Location: Goteborg, Sweden
Posts: 4,087
Re: Huge Hole in Open Source Software Found, Leaves Millions Vulnerable

I am not familiar with Linux any more that the average joe but from what i have read already around the web this aint a serious problem since the system will reset the key every ten attempts or so of someone trying to guess it; so even if the combinations are less the key getting reset every 10 guesses makes it almost impossible to brute force it or something.

Am i wrong?
__________________
[Airhead]: How the devil?! I got 69! I am a french lesbian!

*Hemi HATES wallpapers AND pickles* ........ never forget that

*There is one thing more evil than pickles, and that is STATISTICS...*
Hemispasm is offline   Reply With Quote
Old 31-05-2008   #7 (permalink)
Blown to smitherines
 
debro's Avatar
 
Join Date: Jul 1999
Location: The c@ke mixer
Posts: 9,948
Re: Huge Hole in Open Source Software Found, Leaves Millions Vulnerable

I'm not sure of the time that it takes to test every conceivable key available to the encryption .. but it's freaking LONG time. A period which is deemed so long that the relevance of the information is quite low. In the case of "social security numbers" in the USA, that's a 90yr lifetime, so I'm assuming that the time required to brute force the encryption open is many times that.

This problem manifests in 2 ways:
1) Communications encryptions.
2) File encryptions.

If someone intercepts a communications packet (or many packets) between an affected Debian based server and any (OS) client, there is a significantly reduced range of possible encryption keys that the server will use to negotiate comms with the client, so brute forcing the intercepted packets open will be much faster since they only need to check a very small subset of the possible keys. This could mean a matter of days or weeks of brute forcing, meaning the information inside can still be relevant.
How often do you change your internet banking password?

The second way is file encryptions on the servers, or personal file security, which is probably less of a problem than the interception problem, as the crackers would need local access to the server, or to have previously intercepted packets between an affected server & a remote administrator.

That said, crackers could already have intercepted communications with financial institutions, or other matters of interest within the last few years .. and recorded it somewhere ... with the discovery & publication of this limited range, they can now focus on brute-forcing anything recorded since the problem began, and it will likely be open to them within a short time.

*Quick .. everyone change all your internet passwords*
__________________
CDFreaks - Overwhelmed by Ignorance since 2005!
We lost the battle, but we haven't lost the war!
Click Here to sign up to the resistance movement!
Viva La Resistance!

Admitting that you've illegally downloaded movies/songs and need help to process/burn is comparable to robbing a bank, and walking into the bank the next day holding the bags of money to deposit them into your account.
Don't be surprised if people laugh at you when you make the headlines.

debro is online now   Reply With Quote
Old 31-05-2008   #8 (permalink)
Blown to smitherines
 
debro's Avatar
 
Join Date: Jul 1999
Location: The c@ke mixer
Posts: 9,948
Re: Huge Hole in Open Source Software Found, Leaves Millions Vulnerable

*twice as good*
__________________
CDFreaks - Overwhelmed by Ignorance since 2005!
We lost the battle, but we haven't lost the war!
Click Here to sign up to the resistance movement!
Viva La Resistance!

Admitting that you've illegally downloaded movies/songs and need help to process/burn is comparable to robbing a bank, and walking into the bank the next day holding the bags of money to deposit them into your account.
Don't be surprised if people laugh at you when you make the headlines.

debro is online now   Reply With Quote
Old 31-05-2008   #9 (permalink)
CDFreaks Resident
 
zhadoom's Avatar
 
Join Date: Jan 2004
Location: Brasil - RS
Posts: 1,053
Re: Huge Hole in Open Source Software Found, Leaves Millions Vulnerable

I'm a happy user of Slackware at 11 years.
__________________
My drives:
Samsung SH-S203B(SB04 FR FB EOPC)
Samsung SH-W162C TS11
Samsung TS-H552U US09 Just for scanning
BENQ 1620 B7W9
LG H42N@H44N RB01 - Region Reset by Ala42
LG H10A@H10N@H12N UJ13
LG H22N 1.02
LG H55N 1.05
LG GH22NP20 1.00
Sony AD-7190A@DH20A3P XV68 - EOHT - FB - FR - EOS / XV6D
Sony G120A@165P6S MS0R
Pioneer DVR-K17
Pioneer DVR-108 1.18 by nil:
zhadoom is offline   Reply With Quote
Old 31-05-2008   #10 (permalink)
CDFreaks Resident
 
Chriso's Avatar
 
Join Date: Apr 2003
Location: Liverpool, England
Posts: 2,066
Re: Huge Hole in Open Source Software Found, Leaves Millions Vulnerable

I'd be tempted to try slackware out but I like the GNOME desktop way too much...I suppose I could install something along the lines of http://gnomeslackbuild.org/ though.
__________________
Videos of me playing piano, would be nice to have feedback from you all!

[23:49] <Chriso> !seen Boobies
[23:49] <JuPiLeR> I found 430 matches to your query; please refine it to see any output.


OS: openSUSE 10.3 and Windows XP SP2
PSU: Enermax Liberty 400w - Modular
Mobo: Jetway V266B
CPU: AMD AthlonXP 2000+
RAM: 256MB Crucial PC2100 + 512MB Corsair Value Select PC2100
HDD: 120GB Maxtor ATA133 8MB Cache + 320GB Western Digital "RAID Edition" ATA100 8MB Cache
Gfx Card: NVIDIA GeForce 6200 passive cooled
Sound Card: SB Live 1024
DVD-ROM Drive: Asus E-616
CD-RW: LiteON 52246S
DVD-RW: NEC ND2510A in external Firewire enclosure (Prolific chipset)
USB2 Card: ALI chipset (got an NEC chipset one waiting to go in)
Firewire Card: Not sure of chipset...but it seems to work
D-Link Network Card

My old Voodoo 3 2000 PCI has now retired, still in perfect working order though!

Get Firefox!
Join CDFreaks

Chriso is offline   Reply With Quote
Old 01-06-2008   #11 (permalink)
CDFreaks Resident
 
zhadoom's Avatar
 
Join Date: Jan 2004
Location: Brasil - RS
Posts: 1,053
Re: Huge Hole in Open Source Software Found, Leaves Millions Vulnerable

Quote:
Originally Posted by Chriso View Post
I'd be tempted to try slackware out but I like the GNOME desktop way too much...I suppose I could install something along the lines of http://gnomeslackbuild.org/ though.
Actual Slackware 12.1 includes KDE and GNOME.
__________________
My drives:
Samsung SH-S203B(SB04 FR FB EOPC)
Samsung SH-W162C TS11
Samsung TS-H552U US09 Just for scanning
BENQ 1620 B7W9
LG H42N@H44N RB01 - Region Reset by Ala42
LG H10A@H10N@H12N UJ13
LG H22N 1.02
LG H55N 1.05
LG GH22NP20 1.00
Sony AD-7190A@DH20A3P XV68 - EOHT - FB - FR - EOS / XV6D
Sony G120A@165P6S MS0R
Pioneer DVR-K17
Pioneer DVR-108 1.18 by nil:
zhadoom is offline   Reply With Quote
Old 01-06-2008   #12 (permalink)
CDFreaks Resident
 
Chriso's Avatar
 
Join Date: Apr 2003
Location: Liverpool, England
Posts: 2,066
Re: Huge Hole in Open Source Software Found, Leaves Millions Vulnerable

Quote:
Originally Posted by zhadoom View Post
Actual Slackware 12.1 includes KDE and GNOME.
Really? I thought they dropped GNOME support a while back....might have a go of it this summer when I've got some free time then!

EDIT "and two of the most advanced desktop environments available today: Xfce 4.4.2, a fast, lightweight, and visually appealing desktop environment, and KDE 3.5.9, the latest 3.x version of the full-featured K Desktop Environment."

Their site seems to suggest otherwise....
__________________
Videos of me playing piano, would be nice to have feedback from you all!

[23:49] <Chriso> !seen Boobies
[23:49] <JuPiLeR> I found 430 matches to your query; please refine it to see any output.


OS: openSUSE 10.3 and Windows XP SP2
PSU: Enermax Liberty 400w - Modular
Mobo: Jetway V266B
CPU: AMD AthlonXP 2000+
RAM: 256MB Crucial PC2100 + 512MB Corsair Value Select PC2100
HDD: 120GB Maxtor ATA133 8MB Cache + 320GB Western Digital "RAID Edition" ATA100 8MB Cache
Gfx Card: NVIDIA GeForce 6200 passive cooled
Sound Card: SB Live 1024
DVD-ROM Drive: Asus E-616
CD-RW: LiteON 52246S
DVD-RW: NEC ND2510A in external Firewire enclosure (Prolific chipset)
USB2 Card: ALI chipset (got an NEC chipset one waiting to go in)
Firewire Card: Not sure of chipset...but it seems to work
D-Link Network Card

My old Voodoo 3 2000 PCI has now retired, still in perfect working order though!

Get Firefox!
Join CDFreaks

Chriso is offline   Reply With Quote
 
Reply


If you can't find where you are looking for, then become a member and get an answer fast! We have thousands of people online every moment of the day to help you! Click here



Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Alcoholer Open Source R!Co Copy Protection 2 13-06-2008 20:37
Open source list? Kallen Newbie Forum 1 27-01-2007 11:26
List of all good Open Source Software under Win 9X/2000/XP helpmehelpu General Software 1 08-08-2003 23:16
Open Source Frankrijk , misschien ook Open Source Engeland Mr. Belvedere Dutch: De Woonkamer 1 29-11-2001 12:31


All times are GMT +2. The time now is 12:47.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0