Live data from Hacker News

OpenSSL Security Advisory

openssl.org

111–112 of 112 posts

Re: OpenSSL Security Advisory

#111
post #54

Earlier quoted context omitted.

I maintain a project ( http://freeradius.org ) which a similar amount of code, and (arguably) similar complexity. While we've had issues, they aren't as numerous as OpenSSL. And, the issues in the latest major version are negligible. Why? We have a requirement for code quality. The code can't just work, it has to make sense. The OpenSSL people don't seem to care about badly formatted and/or non-understandable code. A…

>Why? We have a requirement for code quality. With all respect to your project, I bet wider adoption of OpenSSL and consequently more interest from "interested" parties plays a bigger part here.

So "many eyes find bugs" is better than using good engineering practices?

What an utterly ridiculous thing to say.

Re: OpenSSL Security Advisory

#112

Earlier quoted context omitted.

> Use a language that makes a bunch of security flaws impossible The implicit assumption here is that the language isn't at the same time introducing a number of other vulnerabilities. Is there a language you would like to suggest?

"Actually, more static analysis makes things less secure" That is a preposterous argument.

Come again?
Post reply on HN