3 ms·
Considering: * Golang's TLS stack is far less complex in comparison to other projects. * Golang's TLS stack is written in a "safe" language. * Golang's TLS s
by kkl 10y ago
Considering:
* Golang's TLS stack is far less complex in comparison to other projects.
* Golang's TLS stack is written in a "safe" language.
* Golang's TLS stack is written by individuals with lots of experience in SSL/TLS (and its flaws!).
* Contributions to the project are held to very high standards.
Why do you believe the inverse is true?
- baby 10y ago> Golang's TLS stack is far less complex in comparison to other projects. TLS is the definition of complex =) > Golang's TLS stack is written in a "safe" language. Not all bugs are memory corruption bugs. > Golang's TLS stack is written by individuals with lots of experience in SSL/TLS (and its flaws!) > Contributions to the project are held to very high standards True, I would expect the code to be of high quality and the bugs to be sparse. But even knowing this, you always want to have other pair of eyes looking at your code. An audit done by other experts brings a lot to the table. PS: also, I think an audit would cost a negligible cost to Google =)