﻿<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>George Ou's technology blog</title>
    <description>George Ou's technology blog: Making tech easy</description>
    <link>http://www.formortals.com/Home/tabid/36/BlogId/1/Default.aspx</link>
    <language>en-US</language>
    <managingEditor>george_ou@lanarchitect.net</managingEditor>
    <webMaster>Admin@formortals.com</webMaster>
    <pubDate>Wed, 03 Dec 2008 00:49:34 GMT</pubDate>
    <lastBuildDate>Wed, 03 Dec 2008 00:49:34 GMT</lastBuildDate>
    <docs>http://backend.userland.com/rss</docs>
    <generator>Blog RSS Generator Version 3.4.0.39853</generator>
    <item>
      <title>All 2006-2008 Debian &amp; Ubuntu crypto keys worthless</title>
      <description>&lt;p&gt;&lt;font size="2"&gt;One day after the Debian Linux project &lt;/font&gt;&lt;a href="http://www.debian.org/security/2008/dsa-1571"&gt;&lt;font size="2"&gt;announced a massive flaw&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt; where&amp;#160;its&amp;#160;implementation of OpenSSL key generators only used 15 bits of entropy (32,768 combinations), HD Moore (creator of Metasploit) has released a &lt;/font&gt;&lt;a href="http://metasploit.com/users/hdm/tools/debian-openssl/"&gt;&lt;font size="2"&gt;tool to exploit it&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;.&amp;#160; Nate McFeters has a &lt;/font&gt;&lt;a href="http://blogs.zdnet.com/security/?p=1102"&gt;&lt;font size="2"&gt;good write up here&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt; on this matter.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font size="2"&gt;This means that any asymmetric crypto keys generated between September 2006 and 5/13/2008 a</description>
      <link>http://www.formortals.com/Home/tabid/36/EntryID/43/Default.aspx</link>
      <author>george_ou@lanarchitect.net</author>
      <comments>http://www.formortals.com/Home/tabid/36/EntryID/43/Default.aspx#Comments</comments>
      <guid isPermaLink="true">http://www.formortals.com/Default.aspx?tabid=36&amp;EntryID=43</guid>
      <pubDate>Thu, 15 May 2008 15:00:00 GMT</pubDate>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.formortals.com/DesktopModules/Blog/Trackback.aspx?id=43</trackback:ping>
    </item>
  </channel>
</rss>