Page 1 of 1

Crytical crypto bug in Linux

Posted: Wed Mar 05, 2014 9:03 am
by virtual_master
Critical crypto bug leaves Linux, hundreds of apps open to eavesdropping:
http://arstechnica.com/security/2014/03 ... sdropping/
How does it affect .bit SSL/TLS support ?

Re: Crytical crypto bug in Linux

Posted: Thu Mar 06, 2014 9:00 am
by khal
From http://www.coindesk.com/serious-linux-f ... sdropping/ :
Explained Garzik:

“The gnuTLS bug is pretty bad, but very few use gnuTLS in the bitcoin community. OpenSSL is standard.”

Garzik indicated that the use of OpenSSL mitigates a fork risk that is present when using other competing libraries for key software, such as gnuTLS.

He also stated that projects using OpenSSL, Mozilla NSS, Crypto++ or another crypto library are not impacted by the bug.
Namecoin uses crypto++.
Convergence/FreeSpeechMe uses firefox' libs (NSS).


Other than that, we are affected the same way with server daemons using gnuTLS (apache, php, etc).
=> Namecoin servers have been updated.

Re: Crytical crypto bug in Linux

Posted: Thu Mar 06, 2014 1:11 pm
by virtual_master
khal wrote:From http://www.coindesk.com/serious-linux-f ... sdropping/ :
Explained Garzik:

“The gnuTLS bug is pretty bad, but very few use gnuTLS in the bitcoin community. OpenSSL is standard.”

Garzik indicated that the use of OpenSSL mitigates a fork risk that is present when using other competing libraries for key software, such as gnuTLS.

He also stated that projects using OpenSSL, Mozilla NSS, Crypto++ or another crypto library are not impacted by the bug.
Namecoin uses crypto++.
Convergence/FreeSpeechMe uses firefox' libs (NSS).


Other than that, we are affected the same way with server daemons using gnuTLS (apache, php, etc).
=> Namecoin servers have been updated.
Yeah.
Good to know also:
Ankur Nandwani, a developer at Bitmonet, suggested hosted wallet users and the users of bitcoin exchanges would be most affected, but stated that there are easy protections to prevent issues.

“In both cases, an attacker can sniff users credentials, when users are trying to log-in to their account. To reduce the probability of online wallets and exchange credentials from being compromised, it is really important that everyone use two-factor authentication.”

Nandwani said that the bug is evidence that bitcoin users should reduce their reliance on online wallets and exchanges.