---
title: "16 years of CVE-2008-0166 - Debian OpenSSL Bug"
url: https://daily.dev/posts/16-years-of-cve-2008-0166---debian-openssl-bug-rdhbficok
source_url: https://16years.secvuln.info/
type: article
source: "Lobsters"
published: 2024-05-12T11:19:50.541Z
updated: 2024-05-12T11:19:48.805Z
tags: ["security", "vulnerability", "cryptography"]
reading_time: 7
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# 16 years of CVE-2008-0166 - Debian OpenSSL Bug

**[Lobsters](https://daily.dev/sources/lobsters)** · 7 min read · 0 upvotes · 0 comments

## Summary

In 2008, Debian Linux announced a severe security vulnerability in its OpenSSL package, limiting the possible keys. In 2024, many DKIM setups still use vulnerable keys. DKIM allows signing emails with a cryptographic key, but a large number of hosts were found to be vulnerable to the Debian OpenSSL bug. Companies configured DKIM keys in 2007 and never changed them, leading to potential email forging. The DKIM ecosystem lacks proper cryptographic security and uses substandard RSA key sizes. A tool called badkeys can be used to scan DKIM keys and identify vulnerabilities.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://16years.secvuln.info/>

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 0 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#vulnerability](https://daily.dev/tags/vulnerability), [#cryptography](https://daily.dev/tags/cryptography)

[View this post on daily.dev](https://daily.dev/posts/16-years-of-cve-2008-0166---debian-openssl-bug-rdhbficok)
