7 ms·
Just how bad is OpenSSL? (2012)
- qwertyuiop924 10y agoOpenSSL is pretty bad. After reading about some of the stuff that lead the the libressl fork, I wouldn't trust it with my lunch money. Sure, the algorithms are good, but as far as the code's concerned, Heartbleed was the tip of the iceberg.
- ktRolster 10y agoThere's a saying, "don't roll your own crypto," and it's good advice. In the case of openssl, you might be better off rolling your own. At least the vulnerabilities you end up with are different than the ones that the rest of the world has.
- mSparks 10y agothe deeper and deeper ive gotten into breaking crypto. the more and more ive come to the conclusion that saying is positively poisen. "dont try and do it all on your own but trust no one else to do it for you" probably better. An open, modular project with a wide choice of options would be a godsend and wipe out most digital crime almost overnight. Of course, then, they couldnt use the likes of yahoo and google to read drug dealers emails.
- aerovistae 10y agoFrankly I've never liked man pages. To me they always screamed "This is how documentation was done in the 90s." The examples are often very unclear or incomplete, and the explanations often assume prior knowledge without providing links in case such knowledge is absent. Modern documentation has gotten way better, as seen in the Stripe docs and many others, and I wish the man pages could be updated accordingly.
- microcolonel 10y agoThe quality of manpages can vary significantly, however many of them are excellent. The Git manpages stand out; most of the system manpages for OpenBSD are excellent as well. One other nice thing is integration with an editor. I view manpages in emacs, and can yank the snippets directly into my other buffers for extra convenience.
- beachstartup 10y agoi use the curl and rsync man pages weekly, if not daily for a stretch, and they're great.
- geggam 10y agoWhat is your better solution ? Instead of being derogatory about a technology which works how about creating your ideal and seeing if the Internet likes it ?
- headShrinker 10y agoIt's a good ideal but it also helps to recognize the problem. Not everyone that recognizes the problem is apt or interested in offering a solution. Also I don't believe parent comment was intended to be derogatory
- aerovistae 10y agoIndeed. When you do user testing and they tell you a certain component of your application is confusing or hard-to-use, do you castigate them for being derogatory and tell them to fix it?
- krirken 10y agoIf not derogatory, I have never found the "This is how ... was done in the 90s/80s/70s" sentiment to contribute much to a conversation.
- 10y ago
- ori_b 10y agoAfter the string of vulnerabilities, I know that OpenSSL got a wave of investment. I'm curious how much of this still stands today.
- anonbanker 10y agolook at the list of CVE's since[0], as well as tedunangst's commentary on his blog[1]. they pair up nicely. 0. http://www.cvedetails.com/product/383/Openssl-Openssl.html?vendor_id=217 http://www.cvedetails.com/product/383/Openssl-Openssl.html?v... 1. http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reuse http://www.tedunangst.com/flak/post/analysis-of-openssl-free...
- ktRolster 10y ago20 vulnerabilities found so far in 2016 in openSSL, that's basically saying that the codebase is still not secure.
- ctz 10y agoI got a few thousand dollars of that money as a security bug bounty. OpenSSL fixed the problem quickly, but one year on still haven't accepted the regression test for the issue. It would be amusing if it wasn't so horrifying.
- nickpsecurity 10y agoThe experts writting it for themselves part seemed inaccurate given what I read in LibreSSL commits. It was one atrocity after another. Still love Ted Unganst's observation about them making surd endianess of CPU doesnt change while protocol is running. Just cant remember how often that check was performed. "Experts"... lol...
- stefs 10y agoi interpreted this as: this was written by security experts (cryptographers), not expert programmers. this means the algorithms are generally ok, but the implementation is wacky (and issue prone).
- nickpsecurity 10y agoThat's a fair interpretation.
- red_admiral 10y agoIt was also written by cryptographers who for years asked for support, and got barely enough to keep the server running let alone live off it. Meanwhile the world and his wife joined in with feature requests and complaints about things they didn't like, but mostly without offering to help. So it doesn't surprise me that unit testing, documentation, code review etc. weren't a top priority for spending more unpaid hours on - people literally got what they paid for.
- nickpsecurity 10y agoI'll partly agree with that. Mostly even. I draw the line at expecting a security-critical library intending widespread adoption at least follow secure coding guidelines if nothing else. It really doesnt take much effort vs what was already done. Tiny fraction of it. That plus the larger trend of developers ignoring basic, good practices is why I critique the project a bit. Plus, LibreSSL team illustrated my point nicely by doing 10x what I expected in a very short time with no pay.
- red_admiral 10y agoIf you think OpenSSL is bad, try MIRACL (only documentation I could find is a word file that's basically a list of function signatures). And OpenSSL at least generally builds fine on a vanilla Ubuntu machine. In contrast, libsodium deserves praise for writing documentation like they want people to actually use their library.
- __b__ 10y ago"For instance it doesn't have everything you need to validate certificates..." Yet it has all the CA crap thrown in, via the overloaded openssl binary. As "examples". And according to the documentation, not even "correct" illustrations of how libssl should be used. Encryption and authentication are two separate problems. Just because you figured out a way to encrypt a message does not mean you have also figured out how to a way to send it to only the correct recipient... over an insecure network. (Insecure not only in the sense of "plaintext" but in the sense you are not in control of much of anything - routing, PKI infrastructure, etc.) It seems to me that one would want to solve the authentication problem first, and then move on to encryption. This comment shows that for proponents of using SSL on the public web, it's been the other way around. Authentication was never sorted out. When it comes to authentication, all due respect to the OpenSSL authors, SSH has provided a better attempt at a solution than any implementation of PKI using SSL/TLS. And one more thing, how many ciphers does a user really need? As we've heard time and again, many of them are not even "safe" to use. Some of the alternative SSL libraries have wisely removed them. But I guess OpenSSL is append only?
- mSparks 10y agoopenSSL dates from a time when security was mostly of low importance. (not that things have really changed that much. iot I'm looking at you). shock horror it shows. i find it really quite painful that no one seems to be taking this as seriously as it deserves. cost must be literally hundreds of billions a year now of electronic crime simply because we have been denied secure communications from day 1.