|
Message-ID: <20131115193828.GA8495@hunt>
Date: Fri, 15 Nov 2013 11:38:28 -0800
From: Seth Arnold <seth.arnold@...onical.com>
To: oss-security@...ts.openwall.com
Subject: Re: cryptographic primitive choices [was: Re:
Microsoft Warns Customers Away From RC4 and SHA-1]
On Thu, Nov 14, 2013 at 11:58:47PM -0700, Kurt Seifried wrote:
> Think of all the things that currently use (often older versions of)
> OpenSSL/PolarSSL/GnuTLS/etc and will never get updated...
This is an argument for agressively assigning CVEs. If we're going to
have devices on our networks that are known to be a decade behind the
state of technology we should clearly label them as the security risk
they are. (TLS 1.2 is over five years old.)
Thanks
Download attachment "signature.asc" of type "application/pgp-signature" (491 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.