OpenSSL should disable or remove heartbeat

2014-04-15 Thread Hanno Böck
Hi, I think this question needs to be asked. We have a TLS extension here that - as far as I can see - nobody uses. I have asked in different contexts recently if anyone is aware of real software that makes use of the heartbeat extension. I got often answerts like it could be used for X, but not

Re: OpenSSL should disable or remove heartbeat

2014-04-15 Thread Fedor Indutny
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello Hanno! Despite not a being an active community member, I'd like to share my thoughts on it, if you don't mind. I certainly agree that this extension has a quite faulty specification and very questionable use. But perhaps, instead of just

Re: OpenSSL should disable or remove heartbeat

2014-04-15 Thread Michael Tuexen
On 15 Apr 2014, at 14:26, Fedor Indutny fe...@indutny.com wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello Hanno! Despite not a being an active community member, I'd like to share my thoughts on it, if you don't mind. I certainly agree that this extension has a quite faulty

Re: OpenSSL should disable or remove heartbeat

2014-04-15 Thread Hanno Böck
On Tue, 15 Apr 2014 14:35:36 +0200 Michael Tuexen michael.tue...@lurchi.franken.de wrote: On 15 Apr 2014, at 14:26, Fedor Indutny fe...@indutny.com wrote: I certainly agree that this extension has a quite faulty specification and very questionable use. But perhaps, instead of just

Re: OpenSSL should disable or remove heartbeat

2014-04-15 Thread Richard Könning
Am 15.04.2014 14:35, schrieb Michael Tuexen: On 15 Apr 2014, at 14:26, Fedor Indutny fe...@indutny.com wrote: Hello Hanno! Despite not a being an active community member, I'd like to share my thoughts on it, if you don't mind. I certainly agree that this extension has a quite faulty

Re: OpenSSL should disable or remove heartbeat

2014-04-15 Thread Michael Tuexen
On 15 Apr 2014, at 16:43, Hanno Böck ha...@hboeck.de wrote: On Tue, 15 Apr 2014 14:35:36 +0200 Michael Tuexen michael.tue...@lurchi.franken.de wrote: On 15 Apr 2014, at 14:26, Fedor Indutny fe...@indutny.com wrote: I certainly agree that this extension has a quite faulty specification

Re: OpenSSL should disable or remove heartbeat

2014-04-15 Thread Michael Tuexen
On 15 Apr 2014, at 18:23, Richard Könning richard.koenn...@ts.fujitsu.com wrote: Am 15.04.2014 14:35, schrieb Michael Tuexen: On 15 Apr 2014, at 14:26, Fedor Indutny fe...@indutny.com wrote: Hello Hanno! Despite not a being an active community member, I'd like to share my thoughts