![]() |
Security: Heartbleed on N900
Hello,
probably all of you read http://heartbleed.com/ openssl version gives "0.9.8n" for my N900. :) Pete |
Re: Security: Heartbleed on N900
There are advantages to running tried-and-true software. :)
|
Re: Security: Heartbleed on N900
Seeing as I'm going to have to replace all my passwords (had a nice manual system going back 15 years), maybe someone wants to look at fixing KeepassX (not the vulnerability, it never compiled properly in the first place)?
http://talk.maemo.org/showthread.php...keepass&page=2 |
Re: Security: Heartbleed on N900
Clients should be mostly safe from Heartbleed. Firefox, Opera, Chrome, Thunderbird, Internet Explorer don't use OpenSSL, and Apple's version of OpenSSL is not recent enough for it.
The problem is the server side with all those web and application servers, proxy servers, etc. all using OpenSSL. It's the TLS heartbeat keep-alive code that is vulnerable. KeepassX does not fall into this category, fortunately. :) |
Re: Security: Heartbleed on N900
Quote:
I agree it would be nice to get KeePassX usable on the N900. |
Re: Security: Heartbleed on N900
Quote:
For those interested, try this out https://github.com/Lekensteyn/pacemaker |
Re: Security: Heartbleed on N900
Looks like the version of OpenSSL in the Nokia repos (and in the Community SSU repos) is so old it doesn't have the bug so it should bev good.
|
Re: Security: Heartbleed on N900
Quote:
but I guess the question is, if there were other security issues, which make it too old in other aspects? |
Re: Security: Heartbleed on N900
The question to be asked then is, will replacing OpenSSL on the N900 with the newest version break anything and if not, should CSSU do that?
|
Re: Security: Heartbleed on N900
Quote:
In any case, nothing (else) broke on my N900 (no CSSU, just somewhat patched 1.3). It's not such a "critical" library that would break something horribly, but with Maemo you never know.. |
All times are GMT. The time now is 19:24. |
vBulletin® Version 3.8.8