3 ms·
I think it's reasonable to wait for the community to audit it, and to trust that. Popularity tends to include a certain amount of vetting by people who do have
by code_duck 8y ago
I think it's reasonable to wait for the community to audit it, and to trust that. Popularity tends to include a certain amount of vetting by people who do have time, resources or knowledge.
- raesene9 8y agoThat could happen, but if it did it would very much be the exception rather than the rule :) Heartbleed and shellshock (and others of course but those two have memorable names) very much laid the general case of "many eyes make all bugs shallow" to rest. The unfortunately truth is that a tiny percentage of source code gets reviewed by a competent reviewer. In this case my feeling is that it being crypto+rust the chances are even smaller than usual..
- floatboth 8y ago> crypto+rust Well, security_protocol+rust. The actual crypto comes from https://github.com/briansmith/ring https://github.com/briansmith/ring which just calls hand-written assembly crypto code copied from BoringSSL.
- paulie_a 8y agoThat worked really well for openssl