4 ms·
Throwing money at a problem without competent leadership just makes matters works. The leadership has to have a grasp of what's wrong for any of that money to
by midas007 12y ago
Throwing money at a problem without competent leadership just makes matters works. The leadership has to have a grasp of what's wrong for any of that money to be used effectively. If history were any measure, it seems as likely as a blizzard in the Sahara.
- richardwhiuk 12y agoThis outright hatred towards the developers of OpenSSL seems bizarre and unwarranted. Should the heartbleed bug have been caught in code review? Yes. Does the quality of the OpenSSL library leave something to be desired? Yes. Are there likely to be similar bugs in other SSL implementations? Yes. Is LibreSSL / OpenSSL Rampage / PolarSSL / GnuTLS a good alternative? Probably not, due to poor cross platform support, insufficient features, and way fewer eyeballs. Do other crypto libraries have test suites which would have caught this? No, not as far as I can tell - Apple's Security framework bug and the GnuTLS bug should be evidence enough of that. If you want to migrate, go ahead. The best option is probably NSS.
- mitchty 12y agoI'd argue LibreSSL is already doing a better job because they are doing things that should have happened ages ago. Files from 1998 that were supposed to be removed when 1.0 was released? Should've been gone years ago. Code interspersed with platform specific hacks say for VMS(!?!?!? why is this even supported still) that needs to go. Having a simple core that has platform shims on top is a good thing. Ripping out the openssl NIH memcpy/etc... is a good thing. Sometimes the only way forward is to step back and take a better path. Everyone here is annoyed that we likely are throwing good money after bad. If the openssl developers don't practice good software engineering as it is, money won't change that. This is the fundamental worry. I'm skeptical this will result in anything useful. If the years upon years of technical debt in this project aren't cleaned up like libressl has done, I don't see much chance of things improving substantially.
- midas007 12y agoYes, this is the core worry. OpenSSL needs a press release to commit to a 360-review, top-to-bottom and engage more to lead the tech / stds WG to reduce complexity.
- midas007 12y agoNot switching, not angry... just hold them accountable to simplify their code base AND get the TLS WG to cut back on features. Heartbleed AND LibreSSL will force their hand to make changes.