3 ms·
Official TLS 1.2 support? Oh yes please. Increases in JSON speed? Oh hell yes. I'm loving how Go, as a package in the standard lib, now supports better TLS tha
by Everlag 13y ago
Official TLS 1.2 support? Oh yes please.
Increases in JSON speed? Oh hell yes.
I'm loving how Go, as a package in the standard lib, now supports better TLS than most servers.
- scott_karana 13y agoIt seems kinda strange to me, honestly. All the big SSL libraries have had (and fixed) very subtle side-channel, timing, etc attacks... so why open ourselves to known exploits, if the fixes weren't re-implemented in Go?
- vanderZwan 13y agoIt's an open source language - surely critical security fixes are easily patched in?
- Everlag 13y agoThat is a big potential issue, but really, you can deploy a standalone binary written in go within 2 minutes that supports the state of the art(minus perhaps some subtle but important fixes) in TLS. If not anything else, that is pretty damn cool. Like the other fellow said, it's not as though fixes to attacks will not be accepted into the language.
- ominous_prime 13y agoThey're implementing the reference so that the library can be improved over time. If you want a native implementation, you have to start somewhere. The go TLS stack does need to be seriously audited, but that's expected, and it's going to take time for that to happen.
- lloeki 13y ago> re-implemented in Go Conversely, this enables a host of features (e.g cross-compiling) unavailable or disabled were you to link against C-land using cgo.