• e8d79@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    9
    ·
    4 days ago

    […] Debian maintainer had inadvertently reduced the number of possible keys that could be generated by a given user from “bazillions” to a little over 32,000.

    That’s really bad. It also seems like they patched OpenSSL without ever intending to upstream the changes.

    • dondelelcaro@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      4 days ago

      The openssl change was communicated with upstream at the time, but no one from upstream pointed out the issue (not surprisingly, because the change seemed like an innocuous fix to an unassigned variable.)

      We (Debian) fix bugs and send upstream the changes all the time, so this kind of thing happens. (Upstreams introduce these kind of bugs too; it’s the nature of software development.)