4 ms·
> People just aren't auditing random code on github for fun No, just the important code that everyone is running.
by _pmf_ 6y ago
> People just aren't auditing random code on github for fun
No, just the important code that everyone is running.
- deleted 6y ago[deleted]
- josefx 6y agoAfaik it had the opposite effect for OpenSSL. Not only was the code so bad that it would crash if ran with a secure malloc implementation. Due to being free and open source nobody felt the need to donate[1], with only one developer employed to work on it full time. [1] https://arstechnica.com/information-technology/2014/04/tech-giants-chastened-by-heartbleed-finally-agree-to-fund-openssl/ https://arstechnica.com/information-technology/2014/04/tech-...
- _pmf_ 6y agoWell. eventually someone looked at it. And probably Heartbleed has been used a long time before it was published.
- fnord123 6y agoI have to confess that I have run afl on random code on github.
- iforgotpassword 6y agoYou don't have to audit that. It's so popular, someone else must have done a thorough review already!