OSTIF is working with the Open Source Security Foundation on Symfony

  • Post category:NewsSecurity

OSTIF has been working with the Open Source Security Foundation's Securing Critical Projects working group to help identify critical pieces of infrastructure that require focused security attention. Symfony, a widely used PHP framework has consistently been near the top of multiple reports, underscoring the criticality of the project to the…

Continue ReadingOSTIF is working with the Open Source Security Foundation on Symfony

Google is partnering with Open Source Technology Improvement Fund, Inc to sponsor security reviews of critical open source software

Announcement:  Google is partnering with Open Source Technology Improvement Fund, Inc to sponsor security reviews of critical open source software.  OSTIF is elated to announce that we are planning to improve security of eight open-source projects thanks to support from the Google Open Source Security Team. This marks a major…

Continue ReadingGoogle is partnering with Open Source Technology Improvement Fund, Inc to sponsor security reviews of critical open source software

A Review of the Linux Kernel’s Vulnerability Reporting and Remediation

The Linux Foundation has sponsored a review of the Linux Kernel's practices and policies around how security vulnerabilities are reported to the kernel team, how those reports are processed and addressed, and how those vulnerabilities are disclosed to the public. OSTIF, working with the team at Atredis Partners and a…

Continue ReadingA Review of the Linux Kernel’s Vulnerability Reporting and Remediation

The Linux Foundation Public Health Initiative Sponsored the Audit of COVID Exposure Notification Apps. Here Are The Results!

The Linux Foundation's Public Health (LFPH) initiative has sponsored audits of two COVID-19 exposure notification apps, COVID Shield and COVID Green. As part of their stewardship of these projects, the Linux Foundation decided that it would be prudent to perform due diligence by reviewing the design and code of the…

Continue ReadingThe Linux Foundation Public Health Initiative Sponsored the Audit of COVID Exposure Notification Apps. Here Are The Results!

We are Working with the Monero Community for Multiple Audits of RandomX

The Open Source Technology Improvement Fund is working with the Monero community to fund at least two (and probably three) audits of Monero RandomX. What is RandomX? RandomX is a project that implements a dynamic proof of work algorithm. The aim of an algorithm that changes is to make it…

Continue ReadingWe are Working with the Monero Community for Multiple Audits of RandomX
Read more about the article The OSTIF and QuarksLab Audit of Monero Bulletproofs is Complete – Critical Bug Patched
Monero cryptocurrency security theme with businessman on blurred blue light background

The OSTIF and QuarksLab Audit of Monero Bulletproofs is Complete – Critical Bug Patched

Bulletproofs are a specific type of range proof based on new cryptography by Benedikt Bunz et al. Bulletproofs are a trustless proofs setup that are substantially smaller than the current Borromean style range proofs that were previously used, which reduces the size of Monero transactions by 80-90%. Monero’s latest network update,…

Continue ReadingThe OSTIF and QuarksLab Audit of Monero Bulletproofs is Complete – Critical Bug Patched

The QuarksLab and Kudelski Security audits of Monero Bulletproofs are Complete

Kudelski Security has done a review of Monero Bulletproofs, a specific type of range proof based on new cryptography by Benedikt Bunz et al. Bulletproofs is a trustless proofs setup that is substantially smaller than the current Borromean style range proofs that are currently used, promising to make Monero transactions 10-20%…

Continue ReadingThe QuarksLab and Kudelski Security audits of Monero Bulletproofs are Complete
Read more about the article OpenSSL and Monero Bulletproofs Audits are Underway!
Monero cryptocurrency security theme with businessman on blurred blue light background

OpenSSL and Monero Bulletproofs Audits are Underway!

  • Post category:Security

OpenSSL and Monero Bulletproofs Audits are Underway! We have confirmed that QuarksLab has began the work of reviewing OpenSSL 1.1.1 (the current beta version that implements TLS 1.3, a huge cryptography update.) They are currently working on TLS 1.3 and the updated random number generator to search for biases or…

Continue ReadingOpenSSL and Monero Bulletproofs Audits are Underway!

The OpenVPN 2.4.0 Audit by OSTIF and QuarksLab Results

OpenVPN 2.4.0, the NDIS6 TAP Driver for Windows, the Windows GUI, and Linux versions were evaluated. This release included a number of new features including control channel encryption. QuarksLab found: 1 Critical/High Vulnerability CVE-2017-7478 1 Medium Vulnerability CVE-2017-7479 5 Low or Informational Vulnerabilities / Concerns This public disclosure of these vulnerabilities coincides with the release of OpenVPN 2.4.2 which fixes…

Continue ReadingThe OpenVPN 2.4.0 Audit by OSTIF and QuarksLab Results