

{"id":10766,"date":"2014-07-03T05:22:53","date_gmt":"2014-07-03T09:22:53","guid":{"rendered":"http:\/\/streamingradioguide.com\/startingover\/?p=10766"},"modified":"2014-07-03T05:22:53","modified_gmt":"2014-07-03T09:22:53","slug":"the-real-heartbleed-boogeyman","status":"publish","type":"post","link":"https:\/\/streamingradioguide.com\/startingover\/?p=10766","title":{"rendered":"The real Heartbleed boogeyman"},"content":{"rendered":"<p>It&#8217;s been three months now, and the triage has moved beyond the panic phase.  The powers that be have thrown resources to look at the state of OpenSSL and they have released a report and a roadmap of how to fix it.  Google has decided it can&#8217;t be fixed.<\/p>\n<p>In a rational world, OpenSSL should have been the most tightly controlled and monitored &#8220;Open Source&#8221; product there is, given that it is protecting the privacy of communications and essential to make sure you are connecting to the real secure web server.<\/p>\n<p>The value to a hacker was not so much the possibility of finding a private encryption key as it is that OpenSSL is used on most non-Microsoft web servers and it invisibly leaked random chunks of memory.<\/p>\n<p>This vulnerability was only found because two people &#8211; one at Google and another former Microsoft Internet Police Officer went looking for a problem.<\/p>\n<p>The report is that OpenSSL has<br \/>\n&#8211; no code review process<br \/>\n&#8211; no coding standards<br \/>\n&#8211; no process to approve new features<br \/>\n&#8211; inaccurate or non-existent documentation<br \/>\n&#8211; secret undocumented APIs<br \/>\n&#8211; bug reports that nobody is investigating<\/p>\n<p>Every few days, I have Fedora check for software updates.   Yesterday, the web server updated 35 products with new versions.  How do I know that the update to Python doesn&#8217;t have a new vulnerability put in by accident or on purpose?  &#8220;Just trust me&#8221;<\/p>\n<p>One of the first things that was done was a code audit &#8211; using software tools to automatically search for coding errors &#8211; it found other significant errors and vulnerabilities.<\/p>\n<p>Another major freeware (but not open source) encryption product called TrueCrypt decided to kill itself when faced with the prospect of a second more rigorous code audit &#8211; and admitted to having unfixed security vulnerabilities.  Snowden used TrueCrypt &#8211; so far, no law enforcement agency has succeeded in breaking into a TrueCrypt volume unless they are given the password<\/p>\n<p>Locks on doors are designed to keep honest people out.  If people want to break the law to get in, you can&#8217;t design a door strong enough to stop them.  While you&#8217;re busy installing 4 inch thick armor on the door, they&#8217;re cutting a hole in your roof and coming in through the attic.<\/p>\n<p>When war between governments officially moves onto the Internet, we&#8217;ll find out just how many Trojan horses full of enemy soldiers we invited behind our defenses because we believed in free stuff.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s been three months now, and the triage has moved beyond the panic phase. The powers that be have thrown resources to look at the state of OpenSSL and they have released a report and a roadmap of how to &hellip; <a href=\"https:\/\/streamingradioguide.com\/startingover\/?p=10766\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-10766","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/posts\/10766","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10766"}],"version-history":[{"count":2,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/posts\/10766\/revisions"}],"predecessor-version":[{"id":10768,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/posts\/10766\/revisions\/10768"}],"wp:attachment":[{"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10766"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10766"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10766"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}