5 ms·
> I'm not defending or apologizing for OpenSSL (or any project), but your rationale isn't consistent, seemingly only trying to evoke an emotional response. The
by neerdowell 11y ago
> I'm not defending or apologizing for OpenSSL (or any project), but your rationale isn't consistent, seemingly only trying to evoke an emotional response.
The GP is pointing out that LibreSSL has avoided the 5 vulnerabilities that OpenSSL marked sev:high since the fork. There isn't any inconsistency about that, it's a pure apples-with-apples comparison.
> It's not clear to me (as a consumer) that any project has a huge leg-up over another
LibreSSL has avoided almost half of the OpenSSL vulnerabilities found since the work. What more do you want?