OpenSSLFact's profile picture. One terrible, frightening line of OpenSSL code each day. 365 days a year until the madness ends. Maintained by @matthew_d_green.

OpenSSL Fact

@OpenSSLFact

One terrible, frightening line of OpenSSL code each day. 365 days a year until the madness ends. Maintained by @matthew_d_green.

OpenSSL Fact 已轉發

In crypto: VERSIONING > NEGOTIATION. Nobody in the history of cryptography has ever gotten negotiation right.


OpenSSL Fact 已轉發

OpenSSL thinks 15 is a prime number: blog.hboeck.de/archives/841-D… /cc @OpenSSLFact


OpenSSL Fact 已轉發

Fun OpenSSL fact: ssleay became OpenSSL because RSA - that RSA - aqui-hired Eric Young, the EAY in ssleay


#if 1 if (pseudorand == 2) { /* generate patterns that are more likely to trigger BN library bugs */ ... #whaaaaa


OpenSSL Fact 已轉發

@OpenSSLFact "It recently occurred to me that 0^0^0^0^0^0^0 == 0" #opensslhumour des/des_locl.h


bn_rand(...){ /* make a random number and set the top and bottom bits */ time(&tim); RAND_add(&tim,sizeof(tim),0.0); #miningyourpsandqs


if ( (s->options&SSL_OP_TLS_BLOCK_PADDING_BUG) && !s->expand)


/*The aim of right-shifting md_size is so that the compiler doesn't figure out that it can remove div_spoiler...which I hope is beyond it.*/


OpenSSL Fact 已轉發

OpenSSL wikibook, nice initiative en.m.wikibooks.org/wiki/OpenSSL


/* EEK! Experimental code starts */


MT @Code_Analysis The kind of things you find when you let a robot look at OpenSSL: viva64.com/en/b/0183/


OpenSSL Fact 已轉發

.@solardiz @Code_Analysis "Consider inspecting the '*ptr++' pattern. Probably meant: '(*ptr)++'." << In OpenSSL's case, probably not :(


OpenSSL vs. best practices (RSA decryption edition Part 2, cont'd from Part 1 bit.ly/SWu3Sx) oi50.tinypic.com/29qbjhw.jpg


A random discussion of AES timing attacks pastebin.com/raw.php?i=Z8Hz…


/* Construct the per-ENGINE context. We create it blindly and then use a lock to check for a race... pastebin.com/raw.php?i=n9vQ…


/* ...so all future session negotiations will fail due to conflicts.*/ pastebin.com/raw.php?i=5FT4…


OpenSSL vs. best practices (RSA decryption edition) oi50.tinypic.com/10xv6fc.jpg


此帳戶目前尚未追蹤任何人
Loading...

Something went wrong.


Something went wrong.