[Cryptography] Amazon releases open source cryptographic module

Ryan Carboni ryacko at gmail.com
Mon Jul 6 14:20:04 EDT 2015


https://www.schneier.com/blog/archives/2008/05/random_number_b.html

Two lines in Debian removed. Reduced cryptographic security by 99.99%.

https://en.wikipedia.org/wiki/Heartbleed#Patch

the addition of one line to fix a bug

https://freedom-to-tinker.com/blog/felten/the-linux-backdoor-attempt-of-2003/

addition of two lines to linux source code by unknown hackers. The addition
of one character would mean the code would not provide root access.

----

I understand that cryptography is extremely subtle. Actually most
programming is pretty subtle.
This is why I'm saying that the length of the code or it's readability is
not a factor.

I'm saying that it's possible for ten lines of code to be backdoored.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.metzdowd.com/pipermail/cryptography/attachments/20150706/9431ed37/attachment.html>


More information about the cryptography mailing list