3 ms·
If Huawei is incompetent at managing OpenSSL in their codebase to the point that there are nearly 100 copies sprinkled through, most of which are vulnerable to
by StudentStuff 8y ago
If Huawei is incompetent at managing OpenSSL in their codebase to the point that there are nearly 100 copies sprinkled through, most of which are vulnerable to exploitation, that seems like a perfectly reasonable basis to bar their products for a number of years, regardless their nationality or other actions.
F5 Networks should have been branded a black sheep for its various TLS implementation screw ups (they are the prime reason TLSv1 is considered insecure), yet they came out mostly unscathed. We need to stop giving a free pass to horrid development practices that create massively vulnerable software.
- carlmr 8y ago>If Huawei is incompetent at managing OpenSSL in their codebase to the point that there are nearly 100 copies sprinkled through, most of which are vulnerable to exploitation, that seems like a perfectly reasonable basis to bar their products for a number of years, regardless their nationality or other actions. Yes, and it also highlights that we need independent review of any code going into critical public infrastructure, no matter where it comes from.
- doktrin 8y agoFrankly I agree. There's a lot of ridiculous hand-wringing in every thread about Huawei on HN, but unless what's reported here is factually wrong I'm not going to lose sleep over them facing consequences for a shoddy product.
- BuildTheRobots 8y ago> F5 Networks should have been branded a black sheep for its various TLS implementation screw ups (they are the prime reason TLSv1 is considered insecure), yet they came out mostly unscathed. I'm failing to find more information (googling for ssl issues on ssl termination equipment doesn't work well,) though it sounds like it'd be a good read - if you have any more details to share, please...