6 ms·
OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative
"Network Time Protocol, OpenSSH and OpenSSL first projects to receive support; Open Crypto Audit Project to conduct security audit of OpenSSL"
- orik 12y agoIf OpenSSL software foundation is a for profit operation, why are tech companies funding it(1) instead of LibreSSL? 1: http://arstechnica.com/information-technology/2014/04/tech-g.. http://arstechnica.com/information-technology/2014/04/tech-g....
- tytso 12y agoThe CII is not funding the OpenSSL Foundation; it is directly funding two OpenSSL developers, so they can work on whatever is best for OpenSSL, instead of whatever feature improvements contracted by the OpenSSL Foundation. As a result, the people behind the OpenSSL Foundation are NOT taking a cut of the monies from the CII.
- pjscott 12y agoThe tech companies want OpenSSL to improve, and are willing to pay money; the OpenSSL guys will improve OpenSSL if paid money. What's the problem here?
- allendoerfer 12y agoWhen the missing funding of OpenSSL was discussed, it came up several times, that OpenSSH, while doing great, is quite underfunded, too. I am glad to see them getting some money. What i can't really comment on myself, but am reading from the OpenBSD guys is, that the OpenSSL team does quite well with FIPS consulting and has no increased interest in improving the library.[0] Even if those claims are not true, it would be nice to see several other TLS libraries (GnuTLS, LibreSSL etc.) getting sponsored to get some healthy competition. Maybe, they could even directly compete for shares of the funding by the Linux Foundation in some way. [0]: http://www.openbsd.org/papers/bsdcan14-libressl/mgp00008.html http://www.openbsd.org/papers/bsdcan14-libressl/mgp00008.htm...
- clarry 12y agoJust in case someone missed it, here's video of the libressl talk to go with the linked slide(s). https://www.youtube.com/watch?v=GnBbhXBDmwU https://www.youtube.com/watch?v=GnBbhXBDmwU
- awj 12y agoStraight from the horse's mouth[1] > Also, the income they earn though their paid consulting work supports their unpaid work on OpenSSL, so by hiring OpenSSL team members you are not only solving your own problems but also helping to ensure the long term viability of the OpenSSL product. They also on their website list hourly consulting starting at $250/hour. Neither of these describe how much they get out of this, but it seems reasonable to say that the "OpenSSL runs of $2k/year" line is disingenuous at best. [1] http://www.openssl.org/support/consulting.html http://www.openssl.org/support/consulting.html
- rgbrenner 12y ago"but it seems reasonable to say that the "OpenSSL runs of $2k/year" line is disingenuous at best." Is it? The last contract listed on that page is 4 years old. Maybe they don't regularly get contracts.
- kyledrake 12y agoJust give the money to the OpenBSD team. We saw with OpenSSH that they have a proven track record taking crappy security software and fixing it. Why does everyone have this aversion to giving the OpenBSD team the funding they deserve? And "Theo's a dick" doesn't qualify as a valid reason to not fund real security development. For the work those guys have done improving the security infrastructure of every operating system (they lead, others followed), the entire team deserves to be well-off dicks. It's to me the ultimate highlight of OSS's funding problem. People make millions/billions of dollars off of this software, and nobody ever contributes any of that back to the shoulders they stood on to make that happen.
- tedivm 12y agoPersonally I think two healthy forks of OpenSSL is far, far better than one. I also think that the OpenBSD team is going to take some time before it reaches it's goals, and more importantly before it's in a stable enough point where people can start working on porting their version to other platforms. I don't think it makes sense to leave OpenSSL to wither while that happens, especially since it's an actively used product. That being said I'm far, far more confident in the OpenBSD team than I am the OpenSSL one.
- Touche 12y agoActually if I'm giving someone a donation, charity, then whether they are or are not a dick is a perfectly valid part of the decision. And to me how you run a project is as important as the quality of the final result.
- pessimizer 12y agoYou don't have to have a reason to not donate to something, so the color of their shoes is also a perfectly valid part of the decision. The important question is whether it's a good reason. If you rank the style of his speech as a more important issue than having secure software (unless you think that the style of speech will negatively effect the software), I'd wonder how a single person's personality got so high on your list of priorities. It sounds a bit like voting for a president because he's the guy you feel you'd most enjoy having a beer with: short-sighted.
- mjibson 12y agoIt is possible the OpenSSH funding, since it is done through the OpenBSD Foundation, could, at the Foundation's discretion, go toward LibreSSL, since it's the same group.
- Alupis 12y agoNo it's not. Libressl is a different team; one that feels a fork was more appropriate than just fixing the problems in openssl. IMHO, libressl is a mistake. It's splitting resources over something that needs to be as air-tight as possible. I'd much rather have 1 really really good ssl library that everyone uses instead of 2 so-so ones.
- clarry 12y ago> No it's not. Libressl is a different team OpenSSH and LibreSSL are both a part of OpenBSD. So when you donate to the OpenBSD Foundation, you are very much donating to one project. > one that feels a fork was more appropriate than just fixing the problems in openssl You can't start fixing things in other peoples' source tree just like that. I'm pretty sure nothing useful would've come out of it if the OpenBSD folk had sent half a million lines in diffs to OpenSSL; http://www.openbsd.org/papers/bsdcan14-libressl/mgp00026.html http://www.openbsd.org/papers/bsdcan14-libressl/mgp00026.htm...
- Alupis 12y ago> You can't start fixing things in other peoples' source tree just like that. Yes, you can. It's called contributing to a project. If the "half million lines of diffs" were actually things needing fixing, then the upstream team would accept them. If they are not necessary changes (such as ripping out all windows compatibility), then no, they would reject such changes. It will take years, maybe a decade before a new ssl library becomes the "default". OpenSSL has a lot of ground covered and a lot of history. Yes, it's common knowledge that libressl started before heartbleed, but the reasons for the project being started are mostly along the lines of: 1) We don't think upstream would take these changes 2) We don't like some aspects of the design philosophy 3) We can do it better. All 3 reasons can be collapsed into a more focused effort to fix the already existing and very good ssl library; openssl.
- mrweasel 12y agoI'm actually looking forward to seeing how the OpenSSL problem will deal with their own legacy code, compared to how the OpenBSD developers have handled it. It seems that own of the only ways of dealing with the OpenSSL code is to strip out the code for a large number of, should we say "less used platforms". Is the OpenSSL developers willing to drop support for 16 bit Windows or OpenVMS?
- wmf 12y agoIs the OpenSSL developers willing to drop support for 16 bit Windows or OpenVMS? They either need to properly maintain it or drop it, and they don't have enough money to maintain it.
- jimktrains2 12y agoI just want to know who's still compiling against 16bit windows or OpenVMS. I know my world view isn't infinite, but those systems seem a bit out there.
- daxelrod 12y agoPart of my job involves writing software on OpenVMS. We actually just recently ported something that needed OpenSSL and were happy to find an up-to-date version.
- tribaal 12y agoOut of curiosity (sorry if that's offtopic), but what kind of workload are you running? Is there anything except resources that prevent you from moving to a more modern platform? Of course, "it works" is a valid argument there, too. But you seem to be writing new code, too.
- daxelrod 12y agoNo, nothing except resources is in the way of completion of a move to a more modern platform. It's coming gradually, but we can't drop everything for a year or two to devote all of our engineering resources to getting us there. OpenVMS has some really good ideas baked into the OS that we've had to reimplement or find off-the-shelf solutions for our new platform (for example a distributed key-value store (called "logicals"), a job queue system, and a clustered filesystem) but nothing so earth-shattering that it would keep us on VMS. The biggest downsides are expensive hardware (OpenVMS is designed around clusters of a few beefy boxes, rather than many commodity boxes), lack of community knowledge, and lack of new software available for the platform. (End of life is also looming: http://h71000.www7.hp.com/openvms/openvms_supportchart.html http://h71000.www7.hp.com/openvms/openvms_supportchart.html .)
- joealba 12y agoWhat about BIND for DNS?
- noselasd 12y agobind has had ok funding over the years. Though, bind 10 hasn't gone as well as planned - that's been other issues than funding though - https://ripe68.ripe.net/presentations/208-The_Decline_and_Fall_of_BIND_10.pdf https://ripe68.ripe.net/presentations/208-The_Decline_and_Fa...
- mprovost 12y agoThe DNS ecosystem is much more diverse. djbdns is considered to be the most secure, and there are a few other quality implementations. The root servers, for example, run a mixture of BIND and NSD, so no single bug can affect all of them.
- adventureloop 12y agoI skimmed, but cannot seem to see which project is being supported when they say NTP. When you support the OpenBSD Foundation you support: - OpenBSD - OpenSSH - OpenBGPD - OpenNTPD - OpenSMTPD - LibreSSL The wording makes me think that the initiative will be supporting something other than OpenNTPD
- dankohn1 12y agoThey're supporting 4 projects so far: OpenSSL, OpenSSH, NTPd, and an Open Crypto Audit Project (OCAP) audit of OpenSSL. The Network Time Protocol project is here: http://ntp.org/ http://ntp.org/
- greglindahl 12y agontp has an open-source reference implementation that many Linux distros use. See http://www.ntp.org/ http://www.ntp.org/
- skreuzer 12y agoDon't forget OpenCVS
- dmix 12y agoHow do code security audits actually work? Are various well-experienced people just combing through the code and trying to break it? Or is there a more formal process?
- chrisrohlf 12y agoThis depends on a couple of different things. The most important of which is "at what stage of development is the application? (i.e. how mature and well tested is this code)". Software Development Life Cycle (SDLC) processes are great when followed from the start. When they are applied long after the first 100k+ lines of code are written then its harder. A typical code audit for us (I do this professionally at http://leafsr.com http://leafsr.com) involves some threat modeling, attack surface enumeration, manual data-flow and taint analysis ("where does untrusted data come into this application and how is it handled") and finally just reading the code. Timing and scope will heavily influence how deep you can go. 1 week on OpenSSH will probably get you nothing, 6 weeks on OpenSSL will definitely get you something. (edit: expanded on what is most important)
- dfc 12y agoThis is great news. NTP is one of the least appreciated OSS projects. Harlan and the rest of the ntp dev team are very helpful and deserve a lot of respect for keeping the clocks on time. I can only hope that increased ntp funding/awareness/development means that BitKeeper (not a typo) is finally replaced by git/mercurial.
- deleted 12y ago[deleted]
- davidgerard 12y agoJust LibreSSL. Let OpenSSL die its deserved death. Portable LibreSSL will do wonders.
- tux 12y agoHaving "Huawei" as one of the backers does not create confidance. Recent news shows that they had there hardware backdoored. https://duckduckgo.com/?kh=1&q=Huawei&sites=www.schneier.com%2Fblog https://duckduckgo.com/?kh=1&q=Huawei&sites=www.schneier.com...
- vidarh 12y agoHow is the NSA's ability to backdoor Huawei hardware relevant for Huawei's ability to provide money to help fund audits? Presumably, the NSA hacking is a reason for Huawei to start caring a great deal more about investing in security.