5 ms·
My logic is that you probably want a proven, up-to-date crypto/TLS library with a 'standard' API whatever the application.
by entity345 8y ago
My logic is that you probably want a proven, up-to-date crypto/TLS library with a 'standard' API whatever the application.
- jeremycw 8y agoI thought heartbleed proved this appeal to authority wrong causing liressl to exist in the first place.
- entity345 8y agoOpenSSL is continuously scrutinised and has resources and pressure to fix issues. A less ubiquitous library is not as scrutinised (so who knows what vulnerabilities lie within?) and has probably not the same resources/pressure to fix. Forks are often political before anything else. Fragmentation is not a good thing.
- koolba 8y agoI’m not suggesting you fork it yourself, write your own, or use Joe Schmoe’s SSL library. There are other major implementations such as Amazon’s s2n that have many eyeballs on them daily. Diversity of infrastructure components confers similar resistance as DNA diversity in the wild. https://github.com/awslabs/s2n https://github.com/awslabs/s2n
- nwmcsween 8y agoGo use OpenSSL, see the absolutely horrendous API and then come back and see if you recommend it.