A Summary of the Recent Open Source Security News

Subject: General Tech | June 1, 2014 - 04:04 AM |
Tagged: TrueCrypt, security, openssl, openssh, heartbleed

This week has been most notable for security, as previous news suggests. TrueCrypt, the popular file encryption suite, lost its developers when they wanted to call it quits -- right in the middle of its audit. While on that topic, OpenSSL is being given money and full-time developers, in response to the recent Heartbleed fiasco. OpenSSH and Network Time Protocol, and others in the future, are also being given love.

Yes, these are two separate pieces of news that are combined into a single article.

View Full Size

Earlier, we reported on TrueCrypt's mysterious implosion. The developers' alleged last advice, use closed source solutions or whatever comes up on a random package manager search, I considered too terrible to have been from them. Seriously, from "Trust No-One" to "Trust Who Knows". Just does not seem right...

Since the article, they have apparently been contacted and confirmed that the project is being shut down. That said, it seems like basically every source cites the third-party auditors and no-one else seemed to have direct contact with them -- so who knows. Regardless, the audit is apparently still going on and might lead to a usable fork maintained by someone else.

As for the second piece of news -- several other libraries are getting serious security audits. Apparently, The Linux Foundation has arranged for a long list of companies to commit $5.4 million, over three years, to audit and maintain these projects. As mentioned, OpenSSL, OpenSSH, and Network Time Protocol are the first three mentioned, but others will be included later. Also, that budget can increase as other companies and donors step up.

Currently, the donors are: Adobe, Amazon, Bloomberg, Cisco, Dell, Facebook, Fujitsu, Google, HP, Huawei, IBM, Intel, Microsoft, NetApp, Qualcomm, Rackspace, Salesforce, and VMware. Eighteen companies, each pledging $100,000 per year for three years.

All in all, it seems like the world is on the path to righting itself, somewhat.

Source: Ars Technica
June 2, 2014 | 08:10 PM - Posted by zicoz (not verified)

I love how they link it to NSA.

"Using TrueCrypt is not secure as it may contain unfixed security issues" »»» "uti nsa im cu si" »»» "If I wish to use the NSA"

June 3, 2014 | 02:17 PM - Posted by Scott Michaud

... seriously? An acrostic poem in Latin? o_O

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Lines and paragraphs break automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote><p><br>
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

By submitting this form, you accept the Mollom privacy policy.