|
|
|
|
|
by Freak_NL
3819 days ago
|
|
The money going to OpenSSL might be related to the issue the Dutch government ran into in 2011 with the Diginotar (a certificate authority) hack; the TLS certificates for Dutch government websites were compromised at that time. While this hack was not related to weaknesses in OpenSSL (as far as I know), this did put the spotlight on the vulnerability and dependence on of the certificate chain. Supporting the software that provides this crucial layer of security makes a lot of sense for a government that has been bitten once. |
|
For example in June has asked questions [1] about "the news that American intelligence agencies used vulnerabilities in encryption software" (specifically weak DH / Logjam).
If anything, this proposal has more to do with Logjam than with Diginotar. Not all too incidently, improving OpenSSL would do nothing to prevent another Diginotar from happening.
[1] http://www.tweedekamer.nl/downloads/document?id=97a9bc20-eca...