[CentOS] Can we trust RedHAt encryption tools?

Mon Jan 6 20:24:53 UTC 2014
m.roth at 5-cent.us <m.roth at 5-cent.us>

Eero Volotinen wrote:
> Um, I guess you haven't read the news lately - the most used,
>> POSIX-mandated elliptic curve is backdoored by the US NSA - when the
>>
>
> Well, as you know backdoored EC Dual DBRG is not working at all on
> openssl:
> http://marc.info/?l=openssl-announce&m=138747119822324

That I had not seen. I really like the "we will not fix this bug".

    mark