Question
In March 2022, Tavis Ormandy reported a vulnerability in this library arising from an infinite loop in a modular square root function. Marco Peereboom equated this library to “monkeys throwing feces at the wall” in a rant titled “[this library] is written by monkeys”. A critical vulnerability in this library on Debian (“DEB-ian”) was hilariously caused by a developer commenting out a line because it was causing debugger warnings. OpenBSD forked this library into a “Libre” version and Google forked it into a “Boring” version after a catastrophic 2014 (*) vulnerability that potentially affected 70 percent of Internet traffic. A missing bounds check in implementing the heartbeat protocol led to this library’s most notable vulnerability, called Heartbleed. For 10 points, name this cryptographic library that, as its name suggests, is a freely available implementation of a web security protocol and its successor TLS. ■END■
ANSWER: OpenSSL [prompt on “SSL” or “TLS” with “what library implements that protocol?”; reject “OpenSSH”]
<AW>
= Average correct buzz position
Conv. % | Power % | Average Buzz |
---|
80% | 20% | 113.75 |
Back to tossups