3 ms·
Given the attention OpenSSL just "received" wouldn't it make sense to start a mass audit effort? Why not counterbalance the "crypto software is hard, don't tou
by pointernil 13y ago
Given the attention OpenSSL just "received" wouldn't it make sense to start a mass audit effort?
Why not counterbalance the "crypto software is hard, don't touch it" idea with some simple tasks, like: check all allocs in openssl for bounds checks? "mark" missing ones? "mark" fishy ones etc.
Can a software security audit be crowd-sourced and be meaningful?