Amazing! @reynir wrote an article about his discoveries of two CVE in OpenVPN while re-implementing the same protocol -- TL;DR: it's worth to spend time and money on re-developing network & security protocols. Read it at blog.robur.coop/articles/2024-

#openvpn #MirageOS #NGI #ngi_assure #OCaml #security

@hannesm @reynir nice stuff! Both bugs are cool, but the second one particularly so. It nicely highlights how small "oddities" can actually turn into issues.

Follow

@greg @hannesm @reynir I didn't read it, but isn't this the sort of thing TLA+ modelling is supposed to help with? I remember a blog post by @talex5 about modelling a Xen protocol that way.

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.