3 ms·
Everybody who is dropping OpenSSL in favor for alternative library X is going to bet on the wrong horse here. A big leak has just been fixed in OpenSSL and ever
by subbz 13y ago
Everybody who is dropping OpenSSL in favor for alternative library X is going to bet on the wrong horse here. A big leak has just been fixed in OpenSSL and every commit will be checked now by more critical eyeballs than before imho.
- stronglikedan 13y agoI don't believe that the presence of the vulnerability is the reason people are looking to migrate. I believe that the discovery of this vulnerability shed light on the code quality of OpenSSL, and that is what is turning people away. Some people have only recently learned of the quality issues, and have lost trust in the project. Others have known about them, but have been begrudgingly dealing with them, and this was the straw that broke the camels back. There's always someone looking to migrate to a different implementation, and all they need is a good reason to justify the effort.
- laumars 13y agoThat maybe true, but you're also making the assumption that other SSL/TLS implementations are not already better. The recent OpenSSL bug is a great reminder that we shouldn't just used OpenSSL because it's what everyone else uses. It's an excuse for use to investigate alternatives and then make a rational decision about which implementation to use. If that investigation leads us back to OpenSSL, then so be it. But without looking into competing libraries, any talk about OpenSSL being the better stack is pure speculation.
- rodgerd 13y agoThis sounds dangerously close to a variation on the sunk costs fallacy. "Why abandon this code base when we're putting so much effort into it?"
- mst 13y agoMonocultures have their own risks.