Skip to navigation
   
Davey Winder's Blog

Two years of compromised Linux security exposed

By Davey Winder in Editorial

Posted in Blog, Linux, Security, Internet, e-commerce on May 26, 2008 at 11:40 am

Permalink | Author Profile

A recently revealed vulnerability with Debian OpenSSL cryptographic libraries, covered in detail within the Debian Security Advisory DSA-1571-1, allows secure web sessions to be potentially decrypted by an attacker. In fact, the vulnerability impacts on Debian children distros as well, but that is almost by the by. What isn’t is the reasoning for the vulnerability to exist in the first place. Now you might be assuming that, like most of these things, a bit of unintentionally sloppy and insecure programming during development was to blame. While the words sloppy and insecure certainly still spring to mind, unintentional most certainly does not.

You see, according to an excellent piece of analysis at Dark Reading it appears that the programmer was “using Valgrind to debug applications in an effort to prevent security flaws. But two lines of code from the OpenSSL libraries caused Valgrind to complain, which prompted the programmer to take them out after an inquiry and short discussion on the OpenSSL development mailing list.” Amazing as it may seem, this simple act resulted in “two years’ worth of weakened cryptographic key creation (both SSH keys sand SSL certificates) on Debian-based systems.”

In effect, the work-around meant that every single one of the 32,767 cryptographic keys could now be generated ahead of time and that means a brute force attack becomes, pretty much, child’s play.

In his Dark Reading analysis, John Sawyer claims that this means “All communications that had been perceived as “secure” for the past two years — and into the unforeseeable future — could now be compromised if their encryption was based on the flawed keys and certificates.”

Sure, the developers concerned were only trying to make something more secure, and there was certainly no malicious intent involved here. But the irony is that it proves Linux can be just as insecure as Windows in some regards, perhaps even more so. More so, why so? Well, the perception is that Linux is secure, period. Working from that basis, users are perhaps more inclined to think less about the security and privacy implications of their online sessions. In the case of Debian users that could have devastating implications.

And the moral of this tale? Be it Linux or Windows, the user should always treat security seriously and never expect the OS to be a virtual fortress…

12345
Rated: 100% (1 votes)
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Comment by Richard Chapman - May 26, 2008 on 4:32 pm

It’s been a long tough road for the advocates of Microsoft’s monolithic operating system and its less than stellar record on security. They have suffered greatly under the taunts and ridicule of the Open source advocates. Their only comeback was the absurdly simplistic logic that popularity equates to vulnerability.

“Now, finally a chink in the (we can now say) supposedly impenetrable Linux security. Ha Ha Linux. We knew the whole time you had security troubles just like the rest of us. From now on if anyone tries to say we’re insecure we’ll throw this report right in their face. Yes, time after time, no matter often there’s a question of Windows security we can show the world that Linux isn’t secure either. See? A flaw was found in May 2008.”

Two questions: How long did it take for a fix to be posted? At what point does this become old news?

Comment by diffid - June 3, 2008 on 8:39 am

Only noobs build secure systems from Linux Distos repositories, experienced and professionals build their own distro and compile their libraries especially security related ones from the horses mouth, the creators themselves not the package managers. yet again people who simply do not understand what ‘Linux’ is tar it all with the same brush, you can do that with windows as you do not have the same level of control as with Linux, but there will be hundreds of mission critical ‘Linux’ systems out their that won’t entertain the idea of a package manager messing with the sources.

Once and for all Linux is not like Windows it can be honed down to the last nut and bolt to suit the application it is required for.

Poor reporting and naive ignorance of what ‘Linux’ is.

Comment by Davey Winder - June 4, 2008 on 11:08 am

>How long did it take for a fix to be posted?

Two years by the look of it… There is a big difference between time to fix after disclosure and time to fix after distribution. Two years is two years, that’s a pretty big window of opportunity.

>Only noobs build secure systems from Linux Distos repositories

Thank goodness ‘noobs’ don’t use Linux then, otherwise they might find themselves in all sorts of trouble.

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

virtual machine prison Paris Hilton Ballmer payments Internet Battery hubdub Windows 7 remote DNS Apple Twitter Eee Bill Gates science documentation open source universe help Finjan betting ISPA Google stupid outsourcing fun man-in-the-middle digitise storage crime politics Rant symantec virtual world Adobe library ecommerce privacy Application Funny scam Facebook archiving Programming carbon copy MSN Jesus Phone trust Hack biometrics home Yahoo code standards malware copyright statistics VPN dumb office BOFH world of warcraft virus Trojan Mars environment HPC scareware OCR terrorism credit card fraud Microsoft tech NASA Kill Switch news sick Flash Web Development social networking global stupidity second life FBI hardware printing graphics fool Noro rootkits green theft productivity phishing Vista policy Rumour black hat ID Theft Texting chips worm christmas Gartner banks China e-commerce security workplace development hacking adware MSNBC exploit Deal money remote working Lotus hypervisor worker staffing survey computing spam Supercomputer Top 500 Olympics data teleworking millions Mobile Phone Big Brother work Death Video Health MessageLabs AMD VM Texas Instruments gaming iPhone 3G Performance computing Eee PC compromise payment server Project Space email debian IP shopping museum Microchip MiniBook size mobile Linux NBC students transactional security Software network avatar fraud report migration Blogging InfoSec web 2.0 technology xmas web Energy linkedin iPhone Zango holidays Digg Government BSI Steve Jobs botnet economics hacker search USA computer books Silverlight XP banking Russia Obama patch management scan OS SMS broadband CAPTCHA Firefox IBM Business data protection service surveys ASUS SSL Windows IDC The Federation Research
Advertisement
Advertisement
Advertisement