3 ms·
Didn't say that. Just take a look at a "security comparison" between LibreSSL and OpenSSL: https://en.wikipedia.org/wiki/LibreSSL#Security_and_vulnerabilities
by peterle 11y ago
Didn't say that.
Just take a look at a "security comparison" between LibreSSL and OpenSSL: https://en.wikipedia.org/wiki/LibreSSL#Security_and_vulnerabilities https://en.wikipedia.org/wiki/LibreSSL#Security_and_vulnerab...
Severity LibreSSL OpenSSL
High 0 5
Medium 15 28
Low 7 10
Total 22 43
LibreSSL has had no "high" vulnerabilities, whereas OpenSSL had 5. Decide for yourself which way to go.
EDIT:
Sorry, can't format that table nicely here..
- bch 11y ago> The "severity" is often not accurate. OpenSSL recently marked an issue as lowly severe, but in fact its severity was high. ... > LibreSSL has had no "high" vulnerabilities, whereas OpenSSL had 5. Decide for yourself which way to go. I'm not defending or apologizing for OpenSSL (or any project), but your rationale isn't consistent, seemingly only trying to evoke an emotional response. Since heartbleed, lots of new SSL implementations have sprung up (Libre, Boring, etc), and hard lights have shone on OpenSSL as well. The scrutiny and competition will come to be win for all consumers of SSL. It's not clear to me (as a consumer) that any project has a huge leg-up over another (though Libre's wholesale dump of a tremendous amount of legacy code sounds like a step in the right direction). Do we even know this won't show up in other (Boring, Libre) implementations as well ? Edit: formatting
- neerdowell 11y ago> I'm not defending or apologizing for OpenSSL (or any project), but your rationale isn't consistent, seemingly only trying to evoke an emotional response. The GP is pointing out that LibreSSL has avoided the 5 vulnerabilities that OpenSSL marked sev:high since the fork. There isn't any inconsistency about that, it's a pure apples-with-apples comparison. > It's not clear to me (as a consumer) that any project has a huge leg-up over another LibreSSL has avoided almost half of the OpenSSL vulnerabilities found since the work. What more do you want?
- deleted 11y ago[deleted]
- peterwwillis 11y agoFormat tip: prefix a block of lines with two spaces (on each line) and a newline before and after the block to turn it into a fixed-width font, then format ASCII-style.