3 ms·
Why is Apple using BoringSSL on their OS?
by maallooc 6y ago
Why is Apple using BoringSSL on their OS?
- pilif 6y agoseems to be an ok choice. It's maintained by a very capable team that has a strong security focus, it's in use on the largest mobile platform (Android) and the motivations and focus behind its maintenance align well with Apple's. What would you have chosen? And why?
- ytch 6y agoIt seems like they use it after iOS 11[1], Maybe they want to prevent another possible goto fail[2] bug? [1] https://twitter.com/steipete/status/979725476364242944 https://twitter.com/steipete/status/979725476364242944 [2] https://gotofail.com/ https://gotofail.com/
- prdonahue 6y agoWe switched to BoringSSL at Cloudflare (from OpenSSL) about 3 years ago. A few reasons why can be found here: https://blog.cloudflare.com/make-ssl-boring-again/ https://blog.cloudflare.com/make-ssl-boring-again/.
- tenebrisalietum 6y agoThere was the Heartbleed vulnerability which affected just about everything that used OpenSSL, which was a lot of things. There were some efforts to fork this codebase and simplify it. BoringSSL is one of those, LibreSSL another. Summary I recall from looking into LibreSSL website some time ago: OpenSSL has a lot of cruft and does weird things like implements its own memory allocator. Most of this is because it supports an extremely wide variety of platforms (I think things like VAX and Amiga). This makes tools that try to detect things like buffer overflows not work properly, which is what Heartbleed was. There have been many minor versions of OpenSSL released to update security vulnerabilities since Heartbleed.
- colejohnson66 6y agoWhy are those platforms still supported?