4 ms·
But, in reality, OpenSSL had only one full-time developer and three “core” volunteer programmers in Europe, and operated on a budget of $2,000 in annual donatio
by was_hellbanned 12y ago
But, in reality, OpenSSL had only one full-time developer and three “core” volunteer programmers in Europe, and operated on a budget of $2,000 in annual donations. This, despite the fact that OpenSSL is used to encrypt the majority of the world’s web servers and widely used by technology companies such as Amazon and Cisco.
There's an interesting statement from our times.
- x0x0 12y agoin the sense that it is utterly wrong, I suppose so... in reality, openssl appears to be a $1mm+/year for-profit fips consulting business [1] that appears to not care much about security, letting serious security issues sit in their bug tracker for years on end [1] http://www.youtube.com/watch?v=GnBbhXBDmwU#t=559 http://www.youtube.com/watch?v=GnBbhXBDmwU#t=559
- justizin 12y agothey only get paid for implementing fips-related security features, which is an important job. they would love to spend more time on core security and have already tooled up to. they went into the consulting biz to pay for the maintenance of openssl, but it hasn't panned out well until recently. it's petty to take something done with great dedication and provided for free, with freedom, and demonize them. where are YOUR commits?
- jurjenh 12y agoI'm pretty sure the implication is that the big corporates don't care a hoot about open source, the ethics or the model - they'll just take it, the cheaper the better. The principle and supposed ethic is to share and have some reciprocity - the reality is somewhat different. And we all suffer. Tragedy of the commons, I guess...
- lupin_sansei 12y agoI'd like to see a campaign and a web page to encourage big companies to donate to open source projects, and to display their donations publicly.
- danudey 12y ago> where are YOUR commits? The 'it's open source, fix it yourself' concept breaks down significantly when you're dealing with other people's complex projects. OpenSSL in particular is a convoluted and horrific codebase, due to a significant number of reasonably awful and insecure decisions, making submitting your own patches a nightmare. Consider yesterday's MITM flaw, where a patch to OpenSSL 1.0.1 provided the opportunity to exploit a bug that OpenSSL has had for over 15 years. There's also the issue of many open-source projects won't accept patches from outside people, or for features they don't care to implement/support. In the case of OpenSSL, that might actually be a good policy, but it still makes the 'why don't you fix it yourself' argument a weak one.
- ternaryoperator 12y agoDr. Dobb's did a write-up on just this aspect [1], which seems under-discussed for all the discussions of Heartbleed. [1] http://www.drdobbs.com/open-source/the-conflict-at-the-heart-of-open-source/240168123 http://www.drdobbs.com/open-source/the-conflict-at-the-heart...