Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 15 Nov 2013 11:38:28 -0800
From: Seth Arnold <seth.arnold@...onical.com>
To: oss-security@...ts.openwall.com
Subject: Re: cryptographic primitive choices [was: Re:
 Microsoft Warns Customers Away From RC4 and SHA-1]

On Thu, Nov 14, 2013 at 11:58:47PM -0700, Kurt Seifried wrote:
> Think of all the things that currently use (often older versions of)
> OpenSSL/PolarSSL/GnuTLS/etc and will never get updated...

This is an argument for agressively assigning CVEs. If we're going to
have devices on our networks that are known to be a decade behind the
state of technology we should clearly label them as the security risk
they are. (TLS 1.2 is over five years old.)

Thanks

Download attachment "signature.asc" of type "application/pgp-signature" (491 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.