Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
quasque
11y ago
0 comments
Share
> Linux security was significantly reduced at one point because somebody changed
int i
to
int i=0
Could you please elaborate on this one?
0 comments
default
newest
oldest
SoftwareMaven
11y ago
It's been a while. I should have restricted it to Debian:
http://jblevins.org/log/ssh-vulnkey
nikbackm
11y ago
Seems to me they relied on the uninitialized memory of a stack variable as a partial source of randomness for key generation.
Initializing the variable with 0 removed that part.
quasque
OP
11y ago
Your explanation makes sense. Though I'm still curious as to when this happened and what the impact was.
j
/
k
navigate · click thread line to collapse