5 ms·
This is one of the better comments I have seen on OpenSSL in the past week. Well said. "This is why OpenSSL looks like a hodgepodge of hacks upon hacks in ord
by uuid_to_string 12y ago
This is one of the better comments I have seen on OpenSSL in the past week. Well said.
"This is why OpenSSL looks like a hodgepodge of hacks upon hacks in order to accomplish narrow goals with limited impact testing."
It doesn't just look like a hodgepodege of accumulated hacks, it is a hodgepodge of accumulated hacks. :)
"It should be no surprise to anyone else: clients are literally paying OpenSSL developers for this, and nothing else."
One could say this with respect to many popular open source projects, including ones with corporate sponsorship. The complexity just keeps building over time and there is no such thing as "finished, accepting bug fixes only".
"Who is paying OpenSSL for developers to clean up the code base and remove ancient #IFDEFs? Who is paying OpenSSL for developers to analyze code paths and do case analysis? Who is paying OpenSSL for developers to write unit tests or even have a test harness at all?"
Those are rhetorical questions. We know the answers. Alas, when the people who pay for (open source) software and consulting pay to have "features" removed instead of added, "pigs will fly".
Doug McIllroy is quoted as saying, "The hero is the negative coder".
(Just in case this need explanation:
Prof. McIllroy is the mind behind UNIX pipes and one of computer science's most prominant contributors.
"Negative coder" means someone who removes code instead of constantly adding, or "committing", new code.)
We could really use some more heros. And as we switch away from OpenSSL there will be a lot of links to libssl to remove.
Meanwhile some people have been writing and testing small, auditable and usable open source crypto, more or less for "free".
http://tweetnacl.cr.yp.to http://tweetnacl.cr.yp.to
My guess (and hope) is that pathological requests for "features" to be added would be met with heavy scrutiny. The authors already have day jobs in academia.
- dfc 12y ago> Meanwhile some people have been writing and testing small, auditable and usable open source crypto, more or less for "free". With all due respect that is complete bullshit. I do not care that you put quotes around free. Writing "free" will never be considered to include sums in the hundreds of thousands of dollars. More importantly blatant lies like this muddy the debate and set outrageous expectations. The Nacl project gives the following description of funding: NaCl was initiated by the CACE (Computer Aided Cryptography Engineering) project funded by the European Commission\'s Seventh Framework Programme (FP7), contract number ICT- 2008-216499. CACE activities were organized into several Work Packages (WPs). NaCl was the main task of CACE WP2, \"Accelerating Secure Networking,\" led by Tanja Lange (at Technische Universiteit Eindhoven) and Daniel J. Bernstein (at the University of Illinois at Chicago, currently visiting Eindhoven). CACE nished at the end of 2010 but NaCl is a continuing project. ...Many of the algorithms used in NaCl were developed as part of Daniel J. Bernstein\'s High-Speed Cryptography project funded by the U.S. National Science Foundation, grant number ITR-0716498. I found the funding information for ITR-0716498. djb is listed as the PI for the project.[^1] I could only find the high level funding of ICT-2008-216499.[^2] (wtf EU?) CACE WP2 is only one component of the project. I would love it if someone with better knowledge of EU funding can find the funding for the WP2 line item. The figures are: NSF ITR-0716498 funding: (USD) 400,000.00 EU 2008-216499 funding: (EUR) 4,733,078.00 ***NEED WP2 line item*** The tweetnacl implementation lists two more funding sources. As above it was easy to locate the NSF funding but I totally struck out for the nwo funding: NSF 1018836 funding: (USD) $436,203.00[^3] NWO grant 639.073.005 funding: ??????????? Don't get me wrong, I have a lot of respect for djb and I think he and his coworkers deserve every fractional euro/dollar of funding that they received but they did not work for free. Most importantly they should not be expected to work for free. [^1]: http://www.nsf.gov/awardsearch/showAward?AWD_ID=0716498 http://www.nsf.gov/awardsearch/showAward?AWD_ID=0716498 [^2]: http://cordis.europa.eu/projects/rcn/85344_en.html http://cordis.europa.eu/projects/rcn/85344_en.html [^3]: http://www.nsf.gov/awardsearch/showAward?AWD_ID=1018836 http://www.nsf.gov/awardsearch/showAward?AWD_ID=1018836 NB: This is the nwo funding site: http://www.nwo.nl/en/funding http://www.nwo.nl/en/funding I think the english version may have a reduced set of features. I can not find the this grant information on the site.
- uuid_to_string 12y agoWow. I guess "more or less" was not strong enough wording for you? The point is that using something like NaCl costs you, the developer/user, nothing more than if you are using OpenSSL. Do you agree?
- dfc 12y agoNo, "more or less for free" is not close to hundreds of thousands of dollars plus whatever funds came from the EU and NWO. I have to say I am confused about your reply in the first sentence you seem to acknowledge that the wordingwas related to the cost of "writing and testing" crypto software. However in the second sentence you seem to indicate that your thesis was about the switching costs users face. Which is it? You did not say I get to use nacl "more or less for free" you said that "people have been writing and testing small, auditable and usable open source crypto, more or less for 'free'." That quote seems to be about the cost of creation not the switching costs. Do you think djb et al produced nacl "more or less for free?"
- uuid_to_string 12y agoI think you misunderstood what I meant. I mentioned "free" only to point out that there is no financial cost to switching to it. I guess I did not type the sentence with enough care; words are missing. My apologies. I imagine people would be willing (and are accustomed) to paying for software of similar quality. But I'm also wondering why this bothered you so much. Does it make a difference that grants were received? Is the funding not transparent enough? The blog article on OpenSSL mentions payments for consulting and "features" to be added to OpenSSL. Should I be concerned about what those features are, and who is paying for them? Are you concerned? I'm just nterested in cleaner code than OpenSSL's. NaCl looks cleaner to me. Maybe I'm wrong. But I'd rather be compiling programs that use libnacl or some other simpler alternative than ones that use libssl. We all have to make decisions about what software we choose to use, even if we are not cryptographers. I see nothing wrong with discussing alternatives to OpenSSL. This bug has been a real PITA.
- jmspring 12y ago> "This is why OpenSSL looks like a hodgepodge of hacks upon hacks in order to accomplish narrow goals with limited impact testing." Can you point out specific examples that you view as hacks upon hacks? Maybe I've spent too many years in the code base, but I've also seen worse. OpenSSL does a lot. Maybe smaller modules would be better and more testing certainly. Organizations using it should also be contributing back more. Hacks upon hacks seems like a stretch to me.
- jmspring 12y agoAs a side note, the NaCL library you mention does only a fraction of the things OpenSSL does. OpenSSL could certainly stand to be broken into smaller components, but trying to compare it with a very small library that does mostly primitive operations is...an improper comparison. I like Dan's work and have used in in projects, I just think your comparison and analysis are quite off base.
- wbl 12y agoIt takes 500 extra lines of C to write a secure channel abstraction with a server and client on top of NaCl. This is the curvecp implementation.
- jmspring 12y agoAnd something capable of doing an SSL/TLS connection with cipher sweet negotiation and client certificate validation? Maybe throw in hardware token/PKCS11 support?
- uuid_to_string 12y agoYou are entitled to your opinion and your preferences. As I am to mine. From the tweetnacl.cr.yp.to paper: "OpenSSL is the space shuttle of crypto libraries. It will get you to space, provided you have a team of people to push the ten thousand buttons required to do so. NaCL is more like an elevator -- you just press a button and it takes you there. No frills or options. I like elevators." - Matthew D. Green, 2012 Yes, it is improper to compare a space shuttle to an elevator. It's also absurd to use a space shuttle when all you need is an elevator. Use whatever you want. Not everyone's needs are the same. I like small components that are independent. The OpenSSL binary is feature for feature one fo the most complex I have ever used. I prefer simplicity. That's just me. Not for everybody. But some might desire it. You have my sincere apologies for daring to mention an OpenSSL alternative. The fact that this NaCl is so small and limited is the whole point. I guess that point was missed.