Devs Working To Stop Go Math Error Bugging Crypto Software (theregister.co.uk)
Richard Chirgwin, writing for The Register: Consider this an item for the watch-list, rather than a reason to hit the panic button: a math error in the Go language could potentially affect cryptographic libraries. Security researcher Guido Vranken (who earlier this year fuzzed up some bugs in OpenVPN) found an exponentiation error in the Go math/big package. Big numbers -- particularly big primes -- are the foundation of cryptography. Vranken posted to the oss-sec mailing list that he found the potential issue during testing of a fuzzer he wrote that "compares the results of mathematical operations (addition, subtraction, multiplication, ...) across multiple bignum libraries." Vranken and Go developer Russ Cox agreed that the bug needs specific conditions to be manifest: "it only affects the case e = 1 with m != nil and a pre-allocated non-zero receiver."
The possibility of this manifesting in any meaningful way is about the same as Trump being elected to another term. In other words... move on, nothin' to see here.
They will never guess my prime now!!!!
Fuck you old people don't know your shit. Young rockstar coders need to reinvent your dinosaur wheels because you fucking suck.
Lol whut r codez iz bugged?!!
You have composed what may be the world's most incomprehensible headline!
General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
I AM SPARTICUS
So why is this a Go only problem and not one across all languages?
Will someone pull Slashdot out of the Dark Ages?
There was a time when it made (commercial) sense to capitalize every word in a headline. Yes, it made money for the hawkers of early newspapers. Big noisy obnoxious headlines made the news sound exciting and motivated people to spend a penny or a nickel.
How does this mess of a headline make money for Slashdot. How does it make the headline readable? Exactly what are the benefits of this abuse of the language in the age of the internet?
Wake up Slashdot. Look around- many publishers aren't living in the Dark Ages any more.
...omphaloskepsis often...
Actually, python is much more consistent and documented than go :(
Avantgarde Hebrew science fiction
Wish I had mod points some days.
Why guess when you can know? Measure!
It behooves them to look deeper, because it's always unclear whether those bugs are intentional or not. The more preconditions there are the more likely the issue wasn't organic.
Sounds like a security problem and Rust is good for two things: 1) fixing security problems, 2) transsexuals.
Will Rust fix people that think Rust will fix everything?
I hope so.
I was in desperate need of a great pro hacker until i met a pro hacker and now i can apply for any kind of loan and purchase stuffs, change school grades.. ....visit www.darkwebsolutions.co for more info
He delivered when I tried him out..I didn't believe my eyes I am excited, and I urge anyone who needs help to try him out..He's the right man