3 ms·
God damn it not again. Bring on boringssl/libressl. Although they'll be full of holes as well probably, and as things stand there's a lot of people looking at o
by n0body 12y ago
God damn it not again. Bring on boringssl/libressl. Although they'll be full of holes as well probably, and as things stand there's a lot of people looking at openssl at the moment. So maybe better the devil you know
- Karellen 12y agoThe forks might not be quite so full of holes. The LibReSSL folks removed the whole SRP module from their tree recently[0] because an embargo that prevented them from releasing just a bugfix in what they thought was a reasonable timeframe. I'm guessing that was for either CVE-2014-5139 or CVE-2014-3512. That does actually give me some confidence that some of the other non-OpenSSL dev teams might do measurably better. [0] https://news.ycombinator.com/item?id=8105373 https://news.ycombinator.com/item?id=8105373
- n0body 12y agoTrouble is, so much has changed that they need a whole separate audit. And who knows what problems removing code introduces. But then again, they might not b worse, but they'll still need auditing to find out