3 ms·
I'm sure they have all the best intentions for sharing the wisdom they learn here. But right now OpenSSL is a VERY VERY messy and dangerous library. The OpenB
by xarball 12y ago
I'm sure they have all the best intentions for sharing the wisdom they learn here.
But right now OpenSSL is a VERY VERY messy and dangerous library.
The OpenBSD devs need to get a working implementation, that catches up on 15 years of refactoring and clarity in (optimistically) 2 months -- or risk the bulk of the world's sensitive information leaking yet again (perhaps even sooner, depending on what is discovered!)
It seems that with the kind of things they're finding, there are a lot lesser understood vulnerabilities in the code.
With the kind of standardization they're working on, a Windows port will be a LOT easier and a LOT simpler after they're finished. Best let them make haste, tear out everything that's leaky, unclear, or dangerous -- and with that will come a lot of simplification and fixes for the entire implementation.
Once it's clean, focus on a Ports. The code is too bloated to even consider ports right now. Quite frankly you might even be safer using Microsoft's SSL/TLS and other crypto implementation for the time being... (Only time will tell!)