OpenSSL Valhalla Rampage

Posted on April 18th, 2014


Do not feed RSA private key information to the random subsystem as entropy. It might be fed to a pluggable random subsystem…. What were they thinking?!

Wow. The entire concept of it is so bad that if you can’t avoid it, it’s literally better to call exit() than go through with it.

