OpenSSL is a free, open-source cryptographic library that provides secure communications over computer networks. It’s widely used to implement the secure socket layer (SSL) and transport layer security (TLS) protocols, which are the basis for secure, encrypted connections on the internet.
On Oct 25th, the OpenSSL project informed its users of a critical vulnerability that affects the 3.0 and later versions of the OpenSSL component. In a twist to the usual formula, the project gave the world a week’s advance notice of the upcoming update, and various stakeholders prepared for this accordingly. In this episode, we sat down with Ilkka Turunen, Sonatype’s Field CTO; we discussed a wide range of topics, including the OpenSSL vulnerability, Shodan, SBOMs, Software Supply Chain and others.
Show Host – Jeff Hemmen
Sponsorship inquiries: sponsor@softwareengineeringdaily.com
The post OpenSSL Vulnerability with Ilkka Turunen appeared first on Software Engineering Daily.