3 ms·
In fairness, after heartbleed - there was quite a push to move away from openSSL - like Google's boring ssl, openbsd libressl and Mozilla/nss or gnutls - but th
by e12e 5mo ago
In fairness, after heartbleed - there was quite a push to move away from openSSL - like Google's boring ssl, openbsd libressl and Mozilla/nss or gnutls - but the alternative here would be moving to a different kernel, like freebsd or open Solaris/Illumos ...
- PunchyHamster 5mo agothat's just moving to kernel that had 1000x less eyes on it. Yeah sure it will have less exploits but purely because nobody bothers to look when there are much juicer targets on Linux. But I am disappointed that we still don't have clear OpenSSL successor, there is nothing to be salvaged from this mess of a project
- DarkUranium 5mo ago1000x less eyes is true, but also: Linux, even in the kernel, has a long history of "move fast and break things". Yes, the syscall API is (famously) stable, but the drivers, for example, are such a mess that many non-Linux projects prefer to take BSD drivers for e.g. WiFi despite them supporting far fewer devices (even if the Linux ones would be license compatible).
- PunchyHamster 5mo agodriver attitude in Linux could be summed up to "we'd rather have the hardware driver working than absent". > but the drivers, for example, are such a mess that many non-Linux projects prefer to take BSD drivers for e.g. WiFi despite them supporting far fewer devices (even if the Linux ones would be license compatible). or vote with your wallet and get device that has well supported card.
- steve1977 5mo agoLess eyes but also less problems like "it's been fixed in the kernel but not in distro XYZ"