Anyone see this article about TLS security issue?

Here wizards, magicians, sorcerers and everybody can rest a bit and talk about anything they like.

Just remember to respect the rules.

Anyone see this article about TLS security issue?

Postby zxr250cc » Apr 6th, '14, 15:45

Is Mageia also vulnerable to this? Is there anything a normal user can do to mitigate this in security settings?

http://arstechnica.com/security/2014/03 ... sdropping/

??

zxr250cc
'We live in the best of all possible worlds!'
Candide (Voltaire)
User avatar
zxr250cc
 
Posts: 200
Joined: Mar 25th, '12, 23:20
Location: USA, Central time zone

Re: Anyone see this article about TLS security issue?

Postby doktor5000 » Apr 6th, '14, 17:45

Seems either you're not doing updates or you don't read news - you'd be vulnerable to this for over a month.

It's fixed since over a month: https://advisories.mageia.org/MGASA-2014-0117.html
We were even featured in a related press article a few days after that: http://www.pcworld.com/article/2105145/ ... x-bug.html
Cauldron is not for the faint of heart!
Caution: Hot, bubbling magic inside. May explode or cook your kittens!
----
Disclaimer: Beware of allergic reactions in answer to unconstructive complaint-type posts
User avatar
doktor5000
 
Posts: 17629
Joined: Jun 4th, '11, 10:10
Location: Leipzig, Germany

Re: Anyone see this article about TLS security issue?

Postby zxr250cc » Apr 7th, '14, 05:05

I updated tls in my computers as soon as I read the article. I guess I am a month late on this. Where is a reliable place to look for such security news going forward? I use slashdot and other sites for news. Anything more up to date on a daily basis?

I do updates daily on my computers. I had to manually choose the tls update though.

thanks for the reply.
'We live in the best of all possible worlds!'
Candide (Voltaire)
User avatar
zxr250cc
 
Posts: 200
Joined: Mar 25th, '12, 23:20
Location: USA, Central time zone

Re: Anyone see this article about TLS security issue?

Postby doktor5000 » Apr 7th, '14, 21:12

zxr250cc wrote:Where is a reliable place to look for such security news going forward? I use slashdot and other sites for news. Anything more up to date on a daily basis?

Not sure what english sites to recommend. I don't look on a daily basis. Maybe http://arstechnica.com/security/ or something like that?
Actually the only one that I read regularly was http://nakedsecurity.sophos.com/
Cauldron is not for the faint of heart!
Caution: Hot, bubbling magic inside. May explode or cook your kittens!
----
Disclaimer: Beware of allergic reactions in answer to unconstructive complaint-type posts
User avatar
doktor5000
 
Posts: 17629
Joined: Jun 4th, '11, 10:10
Location: Leipzig, Germany

Re: Anyone see this article about TLS security issue?

Postby ITA84 » Apr 8th, '14, 10:08

I don't check daily either, but I read LWN and there are daily workday security fixes posted there for the main distros, Mageia included.
ITA84
 
Posts: 199
Joined: Mar 5th, '13, 18:15

Re: Anyone see this article about TLS security issue?

Postby doktor5000 » Apr 9th, '14, 19:54

FWIW, unrelated but for the recent openssl vulnerability, everybody should read up on http://heartbleed.com/
Cauldron is not for the faint of heart!
Caution: Hot, bubbling magic inside. May explode or cook your kittens!
----
Disclaimer: Beware of allergic reactions in answer to unconstructive complaint-type posts
User avatar
doktor5000
 
Posts: 17629
Joined: Jun 4th, '11, 10:10
Location: Leipzig, Germany


Return to The Wizards Lair

Who is online

Users browsing this forum: No registered users and 1 guest