On the “HollowByte” denial-of-service report

Over the past week a denial-of-service (DoS) report against OpenSSL, named
“HollowByte” by the Okta Red Team
who reported it, has received a good deal of press attention. A number of the
articles ask reasonable questions about how we assessed the report and why we
handled the fix the way we did. This post sets out our analysis and the
reasoning behind our decisions.

We are grateful to the Okta Red Team for the report and for the detail they put
into it. The behaviour they describe is real, and we have changed OpenSSL in
response to it. But the report combines two quite different things under a single
headline, and separating them is the key to understanding our response.

This article has been indexed from Blog on OpenSSL Library

Read the original article: