• [^] # Re: ...

    Posté par . En réponse au journal OpenSSL est mort, vive (le futur) LibreSSL. Évalué à 4.

    Enfin c'est bien beau de faire un fork mais si personne ne l'utilise, il ne sera jamais audité et aura potentiellement plein de trou.

    [...]Henson apparently failed to notice a bug in Seggelmann's implementation,[21] and introduced the flawed code into OpenSSL's source code repository on December 31, 2011. The vulnerable code was adopted into widespread use with the release of OpenSSL version 1.0.1 on March 14, 2012. Heartbeat support was enabled by default, causing affected versions to be vulnerable by default.

    http://en.wikipedia.org/wiki/Heartbleed#Appearance

    Depending on the time of day, the French go either way.