5 ms·
I find it deeply worrying that Google controls letsencrypt and an increasing amount of "open" source software. I find it shameful that letsencrypt issues state
by ghandx 5y ago
I find it deeply worrying that Google controls letsencrypt and an increasing amount of "open" source software.
I find it shameful that letsencrypt issues statements like this one:
"we hope to replace the use of OpenSSL and other unsafe TLS libraries in use at Let’s Encrypt with Rustls."
OpenSSL has made companies billions (trillions?) of dollars, now they drop it like a hot potato.
- logicchains 5y agoGoogle priorities: 1. Making money. 2. Making backwards incompatible changes to products and services in the name of best practices.
- rtlpod 5y agoAnd the submission is now sinking after critical comments, as expected.
- Tuna-Fish 5y agoHave you not followed the discussion on the state of OpenSSL? It desperately needs to be replaced. Google pushing for it and providing funding for it is not somehow shameful, it's being a responsible participant that gives back to the community.
- cllg 5y agoGoogle had more than 20 years for auditing OpenSSL and submitting patches. It didn't. Instead NIH solutions are now popping up after having exploited OpenSSL for more than two decades.
- Tuna-Fish 5y agoWell, yes. It's still better to start doing the right thing late than never? > Instead NIH solutions are now popping up after having exploited OpenSSL for more than two decades. Building new crypto libraries to replace OpenSSL is not caused by NIH, it's caused by rationally examining the existing codebase and coming to the conclusion that sometimes starting from scratch is the sane choice. Google is doing the incremental fixing approach (in BoringSSL) too, but it's very clearly a stopgap.
- pizzazzaro 5y agoGoogle has been using their own "BoringSSL" for a while internally. But the fact is? OpenSSL has reached an age where we go about 12 months between severe vulnerabilities. The code itself is built on compromises that made sense in a different era, with major changes bolted on. And then more changes bolted on top of that. And then again, more bolted on top of that. Losing wide-scale Linux adoption of LibreSSL? Has left us more dangerously monocultured. GnuTLS exists. OpenSSH exists. But each finds itself most applicable in different circumstances. LibreSSL was a relatively drop in replacement, but the lack of TLS3 support? Later ended up killing serious Linux support. There was so much code to audit, overhaul, rewrite, or simply remove? That the team writing it still has their work cut out for them, before TLS 3 support can even be considered. https://www.libressl.org/goals.html https://www.libressl.org/goals.html So to see Google help put an auditable, open, safe-language alternative out there? It is a fascinating move. Im suspicious that google's involved, same as you. But so long as it is auditable? And someone more trustworthy is at the helm, keeping it honest? Im excited to see this exist.