[Ach] Fwd: Bug/Ba in OpenSSL

Aaron Zauner azet at azet.org
Mon Nov 25 04:36:36 CET 2013


I'm not aware of any projects or code that is using this random number
generator of the FIPS module in OpenSSL. There is a lot of unused but still
implemented code in OpenSSL. I might be wrong, if so please provide details.

BTW. Matt Green wrote an insteresting blog post about this RNG:
http://blog.cryptographyengineering.com/2013/09/the-many-flaws-of-dualecdrbg.html


On Mon, Nov 25, 2013 at 1:45 AM, Pepi Zawodsky <pepi.zawodsky at maclemon.at>wrote:

> This just popped up on Twitter:
> https://twitter.com/matthew_d_green/status/404771525363892224
>
> Best regards
> Pepi
>
> _______________________________________________
> Ach mailing list
> Ach at lists.cert.at
> http://lists.cert.at/cgi-bin/mailman/listinfo/ach
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.cert.at/pipermail/ach/attachments/20131125/a1f00960/attachment.html>


More information about the Ach mailing list