First time accepted submitter bobo the hobo writesThe FreeBSD random number has been discovered to be generating possibly predictable SSH keys and SSL certificates for months. Time to regenerate your keys and certs if using FreeBSD-Current. A message to the freebsd-current mailing list reads in part: “If you are running a current kernel r273872 or later, please upgrade your kernel to r278907 or later immediately and regenerate keys. I discovered an issue where the new framework code was not calling randomdev_init_reader, which means that read_random(9) was not returning good random data. read_random(9) is used by arc4random(9) which is the primary method that arc4random(3) is seeded from.” Read more of this story at Slashdot.
View the original here:
FreeBSD-Current Random Number Generator Broken
If you’ve ever gone elbow-deep inside your computer to do some tweaking, you know all about the joys(?) of meticulously applying thermal paste or grease. Even if you’re a pro at applying the goop, there’s a trick that you probably don’t know about: You can just use Nutella instead . Seriously. Read more…
The man who built the free email encryption software used by whistleblower Edward Snowden, as well as hundreds of thousands of journalists, dissidents and security-minded people around the world, is running out of money to keep his project alive. Read more…