Hacker News new | past | comments | ask | show | jobs | submit login

It sounds about the same, with differences being that it would affect anything that uses kernel randomness (Debian's problem "only" affected code that used OpenSSL's CSPRNG) and it didn't make it into a release (Debian's was out in the wild for a couple of years before being discovered).

In short, I think it's a bit worse if you're actually vulnerable, but vulnerable systems will be much more rare.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: