4 ms·
It was interesting to hear how impenetrable the code for OpenSSL was even for experienced studs like the OpenBSD team that have handled openssh. OpenSSL has be
by stormqloud 12y ago
It was interesting to hear how impenetrable the code for OpenSSL was even for experienced studs like the OpenBSD team that have handled openssh.
OpenSSL has been dragging around EBSDIC support that the killed off. 90% of people under 50 will never even have heard of it, and 99.9% of people would agree that support should have been dropped ages ago, once explained.
DOS support is another Bob mentioned.
DOS support for a program that all about TCP/IP. Y, for anyone that had to live through it DOS with a bunch of drives and HIMEM crap would get ping, telnet and a couple other TCP/IP programs.
Possibly somebody even wrote http server for DOS after it was already dead for 10 years.
- TazeTSchnitzel 12y agoThere's a graphical web browser that runs on DOS, and some other platforms without needing a windowing system: https://en.wikipedia.org/wiki/Arachne_%28web_browser%29 https://en.wikipedia.org/wiki/Arachne_%28web_browser%29 Not sure if it's for that, though. Maybe it's for a DOS port of Lynx, which actually supports SSL.
- stormqloud 12y agoIt's amazing that the OpenSSL Foundation seems to do so little work on their actual code base give that they actually seem to take donations and have developers. OpenBSD by comparison gets things done with 10% of the OpenSSL budget? The current maintainers of OpenSSL have been doing a shitty job. It's not that heartbleed itself was the problem. OpenSSL scares people away, the code is such a mess. I've looked at it for 5 minutes years ago. You hope to compile it, let alone understand it. Finally people had to take a look at it, and what they found was a scary unmaintained mess vs other open source projects. Specifically considering the importance of OpenSSL the maintainers seem to do a terrible job. As people have mentioned. OpenSSL is basically a "FIPS" consultancy. http://en.wikipedia.org/wiki/Federal_Information_Processing_Standards http://en.wikipedia.org/wiki/Federal_Information_Processing_... FIPS is real world useless to 99% of the population that doesn;t live in the US and do business with the US govt. They are worried more about maintaining the FIPS then patching or improving the code base for something that has become so universal. That's fine for them, but a couple million a year in consulting fee's is messing with a much larger audience. OpenSSL will be able to keep its outdated code base and FIPS, while the rest of the world moves on. Key takeaway from Bob, is they need to raise money to pay some super knowledgable developers to get some of the more lengthly parts done.
- __david__ 12y agoI recently (2011ish) got SSH installed and working on DOS. I was writing a DOS utility for a client (who makes high end network cards)—all their manufacturing is done via DOS. I got frustrated at the slow turn around time of sneakernetting my code to the test machine via USB thumb drives and managed to get SSH up enough so that could scp from the network. You might think DOS is dead (I did), but it still exists (thrives?) at certain places.