Date: Fri, 15 Nov 2013 11:38:28 -0800 From: Seth Arnold <seth.arnold@...onical.com> To: oss-security@...ts.openwall.com Subject: Re: cryptographic primitive choices [was: Re: Microsoft Warns Customers Away From RC4 and SHA-1] On Thu, Nov 14, 2013 at 11:58:47PM -0700, Kurt Seifried wrote: > Think of all the things that currently use (often older versions of) > OpenSSL/PolarSSL/GnuTLS/etc and will never get updated... This is an argument for agressively assigning CVEs. If we're going to have devices on our networks that are known to be a decade behind the state of technology we should clearly label them as the security risk they are. (TLS 1.2 is over five years old.) Thanks Download attachment "signature.asc" of type "application/pgp-signature" (491 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.