3 ms·
Are you volunteering? Good luck and be sure not to repeat the various vulnerabilities that weren't related to memory safety.
by OrpheanBeholder 10y ago
Are you volunteering? Good luck and be sure not to repeat the various vulnerabilities that weren't related to memory safety.
- eis 10y agoI am not volunteering because while being fluent in C, I am not very knowledgeable in the realm of crypto. I'd be stupid to do otherwise. I can still point out that there is a big need for such a project. This is a piece of software that is so core to our computer ecosystem that I am sure plenty of companies would contribute financially and with developer time. Heck, if this couldn't get enough funding for at least 5 fulltime devs plus external audits then we're in a sad state of an ecosystem. IMHO this actually should receive public funding. It would be more useful than many other things that get public funds.
- OrpheanBeholder 10y agoOh, so you were just blowing a bunch of hot air on the internet, while not offering to do any work and while shitting on the LibreSSL developers who are doing work to make things better.
- eis 10y agoSigh. Please improve your reading comprehension. I didn't "shit on the LibreSSL developers". Anyways, you sound not like someone one can have a sensible conversation with. So I wont be replying further.
- omginternets 10y agoDon't worry, the rest of us get it.
- OrpheanBeholder 10y agoOkay, let's have a sensible conversation about your completely idle suggestion to create a new library in some other language, that would have to maintain compatibility with the OpenSSL API otherwise no one will use it, or rewrite everything that currently uses OpenSSL. To me your "LibreSSL is no such thing" came across as dismissing the efforts of LibreSSL, even though it's not vunerable to this latest one, because it doesn't use Erlang.