[CentOS] Can we trust RedHAt encryption tools?

m.roth at 5-cent.us m.roth at 5-cent.us
Mon Jan 6 20:24:53 UTC 2014


Eero Volotinen wrote:
> Um, I guess you haven't read the news lately - the most used,
>> POSIX-mandated elliptic curve is backdoored by the US NSA - when the
>>
>
> Well, as you know backdoored EC Dual DBRG is not working at all on
> openssl:
> http://marc.info/?l=openssl-announce&m=138747119822324

That I had not seen. I really like the "we will not fix this bug".

    mark




More information about the CentOS mailing list