Giter Club home page Giter Club logo

Comments (11)

oniGino avatar oniGino commented on June 29, 2024

Yeah its too bad, but pretty sure this is dead, since most modern TLS servers no longer send time but instead send random numbers..

Here is a quick blurb that sums it up well
https://security.stackexchange.com/questions/71364/tls-reliance-on-system-time

from tlsdate.

therealmarv avatar therealmarv commented on June 29, 2024

ok, thanks a lot for the info and link!

from tlsdate.

vapier avatar vapier commented on June 29, 2024

@ioerror: CrOS uses this project quite a bit and continues to maintain it. would you be OK with having some of us help out with maintenance here ?

obviously we wouldn't turn this into some CrOS-only project, but merge fixes/general improvements that make sense everywhere.

from tlsdate.

ioerror avatar ioerror commented on June 29, 2024

from tlsdate.

vapier avatar vapier commented on June 29, 2024

i was thinking you'd add a few of us (security minded peeps) as Members and then we'd be able to review/merge changes directly in this particular repo

from tlsdate.

ioerror avatar ioerror commented on June 29, 2024

from tlsdate.

asarubbo avatar asarubbo commented on June 29, 2024

I just want to let you know that since there is no activity, the package was masked and will be removed on the gentoo repository unless there will be activities again..
@ioerror since the package is maintained for chrome os, what's the progress to add the CrOS people to this repository?
TIA

from tlsdate.

ioerror avatar ioerror commented on June 29, 2024

from tlsdate.

asarubbo avatar asarubbo commented on June 29, 2024

Is Gentoo carrying any patches that need to be merged?
In our case, atm the tlsdated daemon crashes (because of glibc changes), so we have two ways:

  • find patches around the world
  • find patches in the official repo and/or make a snapshot which contains the patch and/or obtain a new release.

Usually we prefer the latest.

@ioerror since the package is maintained for chrome os, what's the progress to add the CrOS people to this repository?
I haven't received an email from them yet.
@vapier any news?

from tlsdate.

dkriegner avatar dkriegner commented on June 29, 2024

Is Gentoo carrying any patches that need to be merged?

In 2015 I opened a pull request with a gentoo patch: #171
There was no feedback whatsoever since then!

from tlsdate.

orent avatar orent commented on June 29, 2024

Note to anyone who comes here:

There is an active fork by the ChromiumOS project here:

https://chromium.googlesource.com/chromiumos/third_party/tlsdate

In general, it appears to be a bad idea to rely on TLS handshake using the timestamp, rather than some random data.

But since the Chromium project is by Google there is probably some long term commitment that at least TLS services on google.com continue supporting it.

from tlsdate.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.