Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
Check out the new SourceForge HTML5 internet speed test! No Flash necessary and runs on all devices. ×

Submission + - Six new OpenSSL vulnerabilities addressed (www.cio.in)

dachshund writes: "Six new vulnerabilities have been addressed in OpenSSL. The most serious is a timing-based attack against Datagram TLS, capable of completely recover the plaintext from encrypted messages. This flaw was discovered by Nadhem Alfardan and Kenny Paterson at Royal Holloway University. The remaining attacks deal with potential denial of service issues, as well as bug that could potentially leak fragments of memory over the Internet due to the use of an uninitialized buffer. This puts the cap on a year of TLS vulnerabilities headlined by the recent BEAST attack."

Submission + - Toyota Sudden Acceleration Report can be Unredacte (cryptographyengineering.com)

dachshund writes: You may remember a year or two ago, Toyota vehicles were having problems with sudden acceleration. Earlier this year, NASA and NHTSA systematically reviewed the engine control code and cleared them. Or maybe not. You see, the report they wrote was heavily redacted. However, it appears that the redaction wasn't done right, and the missing pieces can be recovered simply by copying and pasting from the cached versions of the PDF files. These reports are really begging for a crowdsourced reading. Some of the details certainly raise my interest. For example:

Any duty command from the PID controller greater than or equal to 88% will perpetually open the throttle and lead to WOT [wide open throttle]. This also means that any duty greater than 88% will be interpreted by the hardware as a 100% duty command.


Slashdot Top Deals

"The chain which can be yanked is not the eternal chain." -- G. Fitch

Working...