4 ms·
Another angle is that a compromised security protocol used by a 100,000 developers is far more fruitful than having to assign a human specialist to crack & reve
by mrschwabe 9y ago
Another angle is that a compromised security protocol used by a 100,000 developers is far more fruitful than having to assign a human specialist to crack & reverse engineer 100,000 uniquely thought-out implementations.
- wolco 9y agoThis is the point people miss. Same as wordpress vs creating your own blog. The more popular the software the larger the interest and the bigger exploit if successful.
- arcticbull 9y agoIt is less likely, though, and more likely to get fixed everywhere fast. 100,000 easy to crack implementations with obvious errors isn't really more secure than 1 super difficult, super well optimized/secured implementation, is it?
- wolco 9y agoIt is more difficult to crack 100,000 different interfaces because the time required to learn each one is a fixed cost. Having one central implementation makes it much easier to expliot because if an issue is discovered it can be immediately used everywhere. Don't put all your eggs in one basket.
- calafrax 9y ago> more likely to get fixed everywhere fast openssl bugs were around for a very long time
- calafrax 9y agoexactly. a very shitty unique implementation is much less likely to be hacked than a near bulletproof implementation used by millions with a single flaw.