Slashdot is powered by your submissions, so send in your scoop


Forgot your password?

Comment Re:wrong direction. (Score 3, Insightful) 132

The big companies probably want more control over the project than LibreSSL will allow them. They've been burned once by relying on old-style Unix community dev. But it's also entirely their own fault for not funding and auditing the open source code they were building their billions on.

Seems to me LibreSSL is the way to go, but I can also see why the corporations would just use it as a side-stream for hints on what to fix. They have enough resources to rewrite openSSL from the inside rather than the the LibreSSL tear-down approach. Having both projects is really a benefit for LibreSSL as longs as it gets sufficient interest and resources.

Comment Re:now I never looked into it (Score 1) 420

Some actual energy and costs figures are here:
(Concerns a different region in California, but has been put together well.)

In the political battle in Santa Cruz last year, a key contention was that the proposed carbon offsets were not a real benefit to the environment.

Comment Re:News: Not just webservers use OpenSSL! (Score 1) 59

Yes, LiteSpeed web server, a common drop-in replacement for Apache, had the bug even when the shell of a LAMP stack did not. LS patched it.

If this bug had been in 0.9.8 the web would be in a real disaster now. Many web ISP's stay behind a few versions on the stack. I've got one that runs the oldest PHP version still in release. That's a bit extreme. So the bug hit more big companies.

Comment mixes special ed (Score 3, Insightful) 798

The special ed kids with learning disabilities are mixed with the ones with behavioral/emotional disabilities in this school. In other words, people that get made fun of, and people that are a danger to them. Sheep and wolves. Must make the regular classrooms nice to remove both the slow learners and troublemakers.

The same thing happens in homeless shelters, where it's hard to protect the defenselessly mentally ill from the bad guys. And prisons, where a lot of mentally ill people live due to the policies of our country.

Another problem in this case is that the police and the judge are an extension of the school administration, and see themselves that way. Also, it is a small Western Pennsylvania school district surely dominated by athletics. Also, we don't know the full story. This could be the best school in the world, but I somehow doubt it.

Comment $1b corps (Score 2) 268

They all need to be contributing to OpenSSL or a fork.

In a typical year the OpenSSL project receives about US$2000 in donations.

This week we have received roughly 200 donations totaling nearly
US$3000. Amounts have ranged between $0.02 and $300, and I notice that
some individuals have made multiple contributions.

Security theater is sometimes more like security exhaustion.

Comment Re:Whatever you may think ... (Score 1) 447

Clearly $billion corporations like RedHat are going to spend more time auditing code commits, with or without lawsuits. Google found this bug and I wonder what kind of fork / NSS migration / whatever solution will emerge. NSS is from Mozilla, and Google revenue funds Mozilla.

Maybe it will go as far as "OpenSSL considered harmful" and anything linked to it will be flagged. That would be too sensible.

Comment Re:What I want to know is... (Score 1) 239

Here's a sad post from one year ago:

Is it possible to ensure by a configuration parameter, that curl uses OpenSSL, and not NSS to retrieve https content? I need to ensure this, in order to enforce compliance with FIPS140-2, which RHEL6.2 has certified?

By the way I know NSS does a lot of FIPS compliance, but part of the Heartbleed problem for the "normal" user is that it is hard to tell what openssl is linked into. We had it in our web server daemon even though shell "openssl version" showed a good version.

Slashdot Top Deals