<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet title="XSL formatting" type="text/xsl" href="http://www.placenet.org/benoit/index.php/feed/rss2/xslt" ?><rss version="2.0"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:wfw="http://wellformedweb.org/CommentAPI/"
  xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
  <title>Harvard Business School of Echec - openssl</title>
  <link>http://www.placenet.org/benoit/index.php/</link>
  <description></description>
  <language>fr</language>
  <pubDate>Sat, 09 Aug 2008 08:26:39 +0200</pubDate>
  <copyright></copyright>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Dotclear</generator>
  
    
  <item>
    <title>/dev/random</title>
    <link>http://www.placenet.org/benoit/index.php/post/2008/05/14/lets-drop-openssl</link>
    <guid isPermaLink="false">urn:md5:df92679804d40407628cca57de03e0fb</guid>
    <pubDate>Wed, 14 May 2008 10:50:00 +0200</pubDate>
    <dc:creator>Benoît Dejean</dc:creator>
        <category>bug</category><category>openssl</category>    
    <description>    &lt;p&gt;About &lt;a href=&quot;http://www.debian.org/security/2008/dsa-1571&quot;&gt;DSA-1571 openssl &lt;/a&gt;, &lt;del&gt;I totally aggree with &lt;a href=&quot;http://blog.drinsama.de/erich/en/linux/2008051401-debian-openssl-desaster&quot;&gt;Eric&lt;/a&gt; ... openssl is just like this &lt;a href=&quot;http://www.xkcd.com/221/&quot;&gt;XKCD strip&lt;/a&gt;. So whatever distro you run, cross your fingers while you generate your keys from so-called uninitialized memory so it's uninitialized enough. Why don't we just drop openssl ?&lt;/del&gt;&lt;/p&gt;


&lt;p&gt;PS: http://wiki.debian.org/SSLkeys gives better explanation. The problem is that one of the cleanups is harmless, while the other one actually commented the code that seeds the PRNG with real entropy. Ouch.&lt;/p&gt;</description>
    
    
    
      </item>
    
</channel>
</rss>