Re: Only 2 pairs of eyes reviewed the openssl code change that introduced heartbleed

Gideon Guillen <[email protected]>
Newsgroups gmane.org.user-groups.linux.philippine
Message-ID <CAAa7TbFbvvQmpO=4t9vGz7gPpM_i8nKtdfqHCd0p1HUkaL1G6w@mail.gmail.com>
On Apr 13, 2014 4:22 AM, "Rogelio Serrano" <[email protected]>
wrote:
>
>
> On 12 Apr 2014 20:48, "fooler mail" <[email protected]> wrote:
> >
> > you don't get it also.... plan B is to deny that is not intentional
>
> He put it there on purpose? Where is that coming from? The guy apologised!

Well given there are already news that the NSA exploited the bug, even
though they denied it. Of course the if this guy was paid by the NSA to
insert this "backdoor", he will never, ever admit it.

That's why for stuff like OpenSSL, they need to change the process for
accepting patches,  probably two or three levels of approval. And there
should be a regular code audit by a very reliable third party.

_________________________________________________
Philippine Linux Users' Group (PLUG) Mailing List
http://lists.linux.org.ph/mailman/listinfo/plug
Searchable Archives: http://archives.free.net.ph
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.