EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

03.05.14

Panic Over Transport Layer Security (TLS) Flaw Which is Already Patched

Posted in GNU/Linux, Security at 12:44 pm by Dr. Roy Schestowitz

Bad news sells better

Summary: What the media is not really telling us about the GnuTLS vulnerability

The corporate press has shown its ignorance by characterising GNU as “Linux” and describing an already-patched flaw as the worst thing since proprietary software. Some went as far as suggesting that the NSA was behind it [1] and Muktware rebutted [2] the seminal article [3] which started a lot of the panic (at the time of writing there are dozens of articles about this, but we don’t need to feed them with links). What we have here is another case of Dan Goodin creating panic in the Microsoft-friendly Ars, just as he had done when he worked for the Microsoft-friendly The Register. The only shocking thing is the amount of press coverage this received. PGP/GPG, OpenSSH, OpenSSL etc. were previously named here for flaws that had been found (in the context of Red Hat and the NSA [1, 2, 3]). These are not so uncommon. One just needs to keep up to date (patched) — one that which Apple’s customers cannot do. They can’t even write their own patches.

Related/contextual items from the news:

  1. NSA did it again? This time GnuTLS fails to check malicious certificates
  2. Yes there was a security hole in Linux, but Red Hat already fixed it

    Originally reported by Ars Technica, the fix was available by the time the general public was made aware of it. It’s actually fairly similar to a certain security hole that lived for a year and could have allowed for exploits to be used in the wild.

  3. Critical crypto bug leaves Linux, hundreds of apps open to eavesdropping

    The bug in the GnuTLS library makes it trivial for attackers to bypass secure sockets layer (SSL) and Transport Layer Security (TLS) protections available on websites that depend on the open source package. Initial estimates included in Internet discussions such as this one indicate that more than 200 different operating systems or applications rely on GnuTLS to implement crucial SSL and TLS operations, but it wouldn’t be surprising if the actual number is much higher. Web applications, e-mail programs, and other code that use the library are vulnerable to exploits that allow attackers monitoring connections to silently decode encrypted traffic passing between end users and servers.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 16/12/2014: Google and ODF, Civilization: Beyond Earth Comes to GNU/Linux

    Links for the day



  2. Bill Gates' Pet Troll Intellectual Ventures is Collapsing as Founder Quits

    Intellectual Ventures founder leaves after an exceptionally large round of layoffs, despite [cref 77299 recent subsidies from Sony and Microsoft]



  3. Keeping Software Patents Out of Europe Following the Demise of Software Patents in the US

    Instability in the EPO seemingly prevents further expansion of patent scope, which is the subject of scrutiny of EPO staff



  4. Links 15/12/2014: OSI 2014 Annual Report, GPLv2 Court Test

    Links for the day



  5. Links 14/12/2014: Calligra 2.9 Beta, Krita 2.9 Beta

    Links for the day



  6. Software Patents Are Dying in the US, But Patent Lawyers Refuse to Admit It

    Patent lawyers continue to distort the reality of software patents' demise in the United States



  7. Links 13/12/2014: Android Wear “Lollipop”, European Commission and FOSS

    Links for the day



  8. Time to Take Microsoft Out of British Aviation Before Planes Crash Into Buildings

    London's mighty Heathrow Airport among those affected by a Microsoft-reliant air traffic control system which is not being able to properly recover from an outage, and not for the first time either



  9. News From France and Germany: Battistelli Under Fire, But Not Fired Yet, Just Firing His Opposition

    The régime headed by Benoît Battistelli and his criminal deputy continues to overthrow or pressure out everyone who is not 'loyal' to the régime



  10. Links 12/12/2014: Linux++, KDE Frameworks 5.5.0, Calligra 2.8.7

    Links for the day



  11. The USPTO is Broken: New Evidence Presented

    The scope of patents, as evidenced by some statistical figures and individual patents, shows that the USPTO is broken and must be reformed or dismantled



  12. US Patent Reform (on Trolls Only) More or Less Buried or Ineffective

    An update on efforts to reform the patent system in the United States, including the possibly imminent appointment of Michelle Lee to USPTO leadership role



  13. Software Patents in Canada Not Dead Yet

    Canada's patent status quo increasingly like that of the United States and Canadian giants like BlackBerry now pose a threat to software developers



  14. Dreaming of a Just Christmas: When a Third of EPO Walks Out to Revolt and European Judges Attack the EPO Over Abuses

    Information about the abuses of Battistelli et al. at the EPO are finally receiving wider coverage and increasing the strain on Battistelli's authoritarian reign



  15. Links 11/12/2014: Red Hat Enterprise Linux 7.1 Beta, Firefox 35 Plans

    Links for the day



  16. Ubuntu Core Announcement is Not About Microsoft and Hosting Ubuntu on Azure is Worse Than Stupid

    The power of media spin makes the idea of hosting Free software under the control of an NSA PRISM and back doors partner seem alluring



  17. France Gets Involved in Battistelli's Abuses in the EPO - Part XII (Updated)

    The EPO scandal has officially spilled over to France, where a French Senator got involved and starts asking serious questions



  18. Rolling of Heads Likely Imminent at EPO

    The European patent system is shaking as management breaks the rules, staff is protesting against the management every week, and charges of corruption resurface



  19. Links 11/12/2014: systemd 218, Empire Total War

    Links for the day



  20. Links 10/12/2014: Fedora 21, Ubuntu Core

    Links for the day



  21. Links 9/12/2014: Fedora 21 and Torture Report Are Out

    Links for the day



  22. Exclusive: The Enlarged Board of Appeal Complains About Battistelli's Corrupt Management to the Administrative Council (Updated)

    Text of the complaint from the Enlarged Board of Appeal (EBoA) reaches Techrights, demonstrating just how rampant the abuse in Battistelli's EPO has become



  23. Protests Against EPO Corruption Approach 1,000 in Attendance

    EPO staff at all levels is revolting against the management of the EPO, whose dismissal seems to be only a matter of time



  24. Links 9/12/2014: Greg Kroah-Hartman Interview, Fedora 21 Imminent

    Links for the day



  25. EPO Staff Protests Today and Protested Last Week, Targeting Corruption in the Institution

    PO staff is demonstrating against abuse by the management of the EPO, today we well as in prior days



  26. Links 7/12/2014: New Linux Release, Marines and Prisoners on GNU/Linux

    Links for the day



  27. EPO Scandal: Benoît Battistelli's Arrogance Recognised by European Delegations

    Battistelli’s Nixon moment and the evasive nature of his approach towards external delegations that are troubled by his behaviour



  28. CBS Brushing Aside and Away Microsoft's History of Blackmail and Bribes Against Linux

    Putting in context some of the poor reporting (or whitewash) regarding Microsoft's bribe (disguised as "partnership") to Barnes & Noble



  29. Links 7/12/2014: Typhoon Hagupit, AURORAGOLD

    Links for the day



  30. EPO Imploding: Battistelli Throws a Fit at EPO's Investigation Unit

    Patent institution of Europe is showing signs of tear as protests intensify and suppression of these protests -- as well as suppression of investigation -- intensifies as well


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts