home.social

#wolfssl — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #wolfssl, aggregated by home.social.

fetched live
  1. wolfSSL: 57 CVEs, 4 critical, max CVSS 9.8. 64% unpatched. Trust Score: C. IoT and embedded systems at risk—CWE-295 flaws in TLS can break trust. Patch now. #wolfSSL #infosec #cybersecurity

    valtersit.com/vendors/wolfssl/

  2. wolfSSL: 54 CVEs, 68% unpatched. 15 critical/high flaws, max CVSS 9.8. Trust Score: C. Top weakness: CWE-295 (certificate validation). IoT security at risk. #wolfSSL #cybersecurity #infosec

    valtersit.com/vendors/wolfssl/

  3. 🐺🔒 Ah, another day, another #wolfSSL creation—now with the thrilling #zero-alloc #COSE stack nobody asked for! 🤯 Enjoy deciphering their alphabet soup of acronyms while pretending you understand what on earth FIPS 1403 or MISRA C actually mean. 🧩💥
    github.com/wolfSSL/wolfCOSE #FIPS1403 #MISRA_C #cybersecurity #HackerNews #ngated

  4. 🦾 Why C Remains the Gold Standard for Cryptographic Software - wolfSSL

    「 While memory-safe languages like Rust offer real benefits, serious cryptographic implementations inevitably rely on unsafe code, assembly, and low-level control, eroding those guarantees. At that point, the added abstraction often increases complexity without meaningfully reducing risk 」

    wolfssl.com/why-c-remains-the-

    #c #rust #wolfssl

  5. Critical wolfSSL flaw (CVE-2026-5194) allows digital ID forgery across billions of devices. Update to version 5.9.1 to fix the issue and reduce risk

    Read: hackread.com/wolfssl-vulnerabi

    #CyberSecurity #Vulnerability #wolfSSL #IoT

  6. wolfSSL library vulnerability undermines ECDSA signature verification

    A single misstep in a crucial cryptographic check can have far-reaching consequences, rendering digital certificates unreliable and putting security at risk. The recently discovered wolfSSL library vulnerability compromises ECDSA signature verification, allowing for potentially forged certificates and weakened…

    osintsights.com/wolfssl-librar

    #EllipticCurveDigitalSignatureAlgorithm #Ecdsa #Wolfssl #Ssltls #CryptographicLibrary

  7. Long, but great read from #HAProxy on the state of #TLS libraries. Includes some scathing remarks about the #OpenSSL project.

    “The development team has degraded their project’s quality, failed to address ongoing issues, and consistently dismissed widespread community requests for even minor improvements.”

    “This unfortunate situation considerably hurts QUIC protocol adoption. It even makes it difficult to develop or build test tools to monitor a QUIC server.”

    “When some of the project members considered a 32% performance regression ‘pretty near’ the original performance, it signaled to our development team that any meaningful improvement was unlikely.”

    “In blunt terms: running OpenSSL 3.0.2 as shipped with Ubuntu 22.04 results in 1/100 of #WolfSSL’s performance on identical hardware! To put this into perspective, you would have to deploy 100 times the number of machines to handle the same traffic, solely because of the underlying SSL library.”

    infosec.exchange/@0xabad1dea/1

  8. “AWS-LC looks like a very active project with a strong community. […] Even the recently reported performance issue was quickly fixed and released with the next version. […] This is definitely a library that anyone interested in the topic should monitor.”

    #OpenSSL #BoringSSL #WolfSSL #AWSLC #HAProxy #OpenSource #FreeSoftware #FOSS #OSS #TLS #QUIC
    haproxy.com/blog/state-of-ssl-

  9. I'll be speaking at CYSAT Conference in Paris next month!

    Let me know if you are going! Stop by and say hi. I'll be at the #wolfSSL booth, too.

  10. At this year's #FOSDEM my team at #wolfSSL got no booth space so my large volume #curl sticker distribution (LVCSD) has to be done using other means.

    The LVCSD will most likely happen in the cafeteria area, but feel free to ping me if you can't get your fix as planned.

    I will bring thousands of curl stickers and hundreds of coasters. There will be a few mugs and maybe some tshirts.

    Buying myself friends, like a boss.

  11. That moment where I finally figure out workarounds for the crypto HAL bugs in a new microcontroller board to get AES GCM working 🕺
    #wolfSSL

  12. The encryption libraries worked in a project; however, this update lets components in the ESP-IDF such as the esp-tls and http libraries leverage the power and flexibility of #wolfSSL #wolfcrypt #TLS 1.3 #PQ and more.

  13. #wolfSSL 5.7.2 update now available on #platformio

    Commercial Grade, NIST FIPS 140-3 Certified Cryptographic libraries. All open source ❤️

    registry.platformio.org/librar

  14. @sindarina @deirdresm

    @orc

    linuxmafia.com is my site.

    I really don't care about SSL (on my site), because there's no compelling use-case for https for anything the site does. (I could remove the current self-signed cert with no functional loss.)

    The whole CA thing is notorious security theatre as implemented. (See Schneier's entire chapter on that in Secrets and Lies.)

    Yes, I'll probably eventually upgrade to a serious SSL implementation using something less hopeless than OpenSSL (looking at wolfSSL and MatrixSSL in addition to the obvious LibreSSL [edit: add Rustls and possibly others; would have to check my records]), and I'll probably accomodate the unthinking masses with a Let's Encrypt cert the way MIchael Orlitzky eventually did, but think it's a well-meaning solution (from excellent and righteous people who are cherished friends) to the wrong problem, for the same reason MIchael Orlitzky does.

    michael.orlitzky.com/articles/

    #LetsEncrypt
    #EFF
    #LibreSSL
    #wolfSSL
    #MatrixSSL
    #indyweb

    #geezer

  15. I've been working on Official #wolfSSL cryptography support for #Arduino. It's there! Check it out, let me know how it goes. Please open issues for any boards that might need extra attention. See my blog:

    wolfssl.com/getting-started-wi

  16. #curl comes post-quantum prepared. All you need is a TLS library setup for it (for example #wolfSSL). I explained this already in 2021:

    daniel.haxx.se/blog/2021/10/04

  17. Today at #FOSDEM I talk in k1.105 at 10:00 "you too could have made #curl" . After that, find me in the #wolfSSL booth to get stickers. If I have any left...

  18. > typically 10 times faster than OpenSSL 3.0.8 on a large system, using 1 lock per connection vs 691 for OpenSSL

    yikes 😬

    #openssl #wolfssl

  19. Which SSL library should you chose? This is a nice review of the many options available today. It was written for HAProxy but most of the information is valid for any server. github.com/haproxy/wiki/wiki/S

    OpenSSL is clearly not an option anymore for production servers.

    #ssl #openssl #wolfssl #performance #linux #unix

  20. "QUIC and HTTP/3 with #curl and #wolfSSL" is the webinar @icing and me did back in April. Check it out!

    youtu.be/SouvkGW0UZQ?t=43

  21. April 6 at 10:00 PST (19:00 CEST) @icing and me run a webinar titled "All Things QUIC" about HTTP/3 and #QUIC with #curl and #wolfSSL. Sign up here: us02web.zoom.us/webinar/regist - I will also live-stream the event on twitch.tv/curlhacker