[HN Gopher] Ask HN: Is your organisation patching the critical O...
___________________________________________________________________
Ask HN: Is your organisation patching the critical OpenSSL
vulnerability?
I'm wondering how many organisations aren't really aware yet of how
serious this is. "OpenSSL warns of critical security vulnerability
with upcoming patch We don't have the details yet, but we can
safely say that come Nov. 1, everyone -- and I mean everyone --
will need to patch OpenSSL 3.x. "
https://www.zdnet.com/article/openssl-warns-of-critical-security-
vulnerability-with-upcoming-patch/
Author : andrewstuart
Score : 6 points
Date : 2022-10-29 21:32 UTC (1 hours ago)
| dontbenebby wrote:
| Just in time for devil's night -- Chris Krebs is gonna be PISSED
|
| Edit: I don't _have_ an organization.
| aborsy wrote:
| I don't know, but I wonder if OpenSSH is affected too?
| altdataseller wrote:
| I am still using OpenSSL 1.0.x and it does not seem to be
| impacted, so no I will not.
| tkiolp4 wrote:
| No. A few months ago, in our security Slack channel we reported
| of vulnerabilities in a few of our micro services regarding
| vulnerable cyphers being used... security team didn't do
| anything. I doubt they'll do something about OpenSSL in our
| systems. We operate in around 10 countries, millions of
| customers. Valued in a few billion dollars.
| technion wrote:
| Depending on context, "vulnerable ciphers" often lead to high
| priority vulnerability alerts that aren't a significant threat
| in practice. For example, best security practice would have
| disabled tls 1.0 years ago but most major services only did
| this in the past year as they dropped internet Explorer
| support. That's a long way from an actual breach and further
| still from a potential potential rce.
| anizan wrote:
| ECDH is anyway unsafe and easily cracked.
| anizan wrote:
| ECDH is anyway unsafe and easily cracket.
___________________________________________________________________
(page generated 2022-10-29 23:01 UTC)