7 ms·
Look at it this way. If it was closed source, the fix would take longer, and the realization may have never come. Honestly, seems like we are forgetting our ro
by bbwharris 12y ago
Look at it this way. If it was closed source, the fix would take longer, and the realization may have never come.
Honestly, seems like we are forgetting our roots on this. Dump it? Yeah and throw out years of stability and bug fixes. No thanks!
- sp332 12y agoBeing widely used is a problem. Monoculture leads to exactly this kind of mass vulnerability.
- JetSpiegel 12y ago"But crypto is hard! Don't roll your own", say everyone, ever.
- jussij 12y agoBy coincidence, I remembered someone pointing this out to the Go developers no too long ago, after he found out they did in fact roll their own: https://groups.google.com/forum/#!searchin/golang-nuts/openssl/golang-nuts/0za-R3wVaeQ/dOWHSpZK7-cJ https://groups.google.com/forum/#!searchin/golang-nuts/opens... In light of the current issue I looks like the D guys did the right thing.
- bbwharris 12y agoStandards are important. For all practical purposes OpenSSL has become a standard. TCP can be exploited, it doesn't mean we ditch TCP for another differently exploitable solution. I see your point but I don't think of OpenSSL as monoculture the same way that Windows or OSX are.
- sp332 12y agoOpenSSL isn't a standard any more than winsock. And fortunately, OpenSSL isn't the only library that implements SSL.