[109952] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: Flaws in OpenSSL FIPS Object Module

daemon@ATHENA.MIT.EDU (Peter Gutmann)
Wed Dec 5 17:13:03 2007

From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: cryptography@metzdowd.com, paul.hoffman@vpnc.org,
	perry@piermont.com
In-Reply-To: <p06240804c379d62c6acd@[192.168.1.62]>
Date: Tue, 04 Dec 2007 21:53:52 +1300

Paul Hoffman <paul.hoffman@vpnc.org> writes:
>At 9:58 AM -0500 12/3/07, Perry E. Metzger wrote:
>>I don't know if people have been following this, but it is interesting
>>from the point of view of studying how the FIPS process does (or does
>>not) interact with the underlying goal of producing assured systems.
>
>Another interesting part is that open-source systems are much more
>susceptible to being attacked by competitors (that is, having their
>validation suspended) than are closed-source systems.

That's a good problem statement for the dark side of "many eyes make bugs
shallow".

Peter.

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post