3 ms·
I'd much rather see Firefox use miTLS[0]. They already use HACL[1] (miTLS and HACL are part of Project Everest[2]) in NSS[3], so I don't think it would be too b
by PyroLagus 7y ago
I'd much rather see Firefox use miTLS[0]. They already use HACL[1] (miTLS and HACL are part of Project Everest[2]) in NSS[3], so I don't think it would be too big of a leap. Rust is really cool, but if you want to ensure that the implementation adheres to the spec, a language with formal verification is much better. That said, miTLS isn't finished yet, so of course it's going to take a while until anyone can actually use it.
[0] https://mitls.org/ https://mitls.org/
[1] https://github.com/project-everest/hacl-star https://github.com/project-everest/hacl-star
[2] https://project-everest.github.io/ https://project-everest.github.io/
[3] https://blog.mozilla.org/security/2017/09/13/verified-cryptography-firefox-57/ https://blog.mozilla.org/security/2017/09/13/verified-crypto...
- earenndil 7y agoIt looks like it's written in F#; that would make it harder to integrate with mozilla's c++/rust codebase. Not impossible surely, but possibly not worth it since in general an attacker has far more interesting avenues of attack than the ssl implementation; especially since it hasn't AFAIK had any high-profile vulnerabilities.
- forty 7y agoF* not F# https://en.m.wikipedia.org/wiki/F*_(programming_language) https://en.m.wikipedia.org/wiki/F*_(programming_language). It compiles to C.
- kitd 7y agoFrom the linked project page: The stable version of miTLS including the new 0.9 release are written in F# and specified in F7. Excuse my confusion.