So what are the options then if OpenSSL isn’t fit for purpose? Is it possible to move wholesale to a different project? Are any of them trying to ease migration over from OpenSSL to themselves?
"OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
11–20 of 245 posts
Re: "OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
#12So what are the options then if OpenSSL isn’t fit for purpose? Is it possible to move wholesale to a different project? Are any of them trying to ease migration over from OpenSSL to themselves?
Re: "OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
#13Great analysis. Theo is always up front on this sort of stuff which is commendable.
Could have done without the final line though, but I guess it's his equivalent of a signature...
Re: "OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
#14So what are the options then if OpenSSL isn’t fit for purpose? Is it possible to move wholesale to a different project? Are any of them trying to ease migration over from OpenSSL to themselves?
Re: "OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
#15So what are the options then if OpenSSL isn’t fit for purpose? Is it possible to move wholesale to a different project? Are any of them trying to ease migration over from OpenSSL to themselves?
fedora is apparently trying to consolidate all crypto to NSS https://fedoraproject.org/wiki/FedoraCryptoConsolidation
Re: "OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
#16So what are the options then if OpenSSL isn’t fit for purpose? Is it possible to move wholesale to a different project? Are any of them trying to ease migration over from OpenSSL to themselves?
GnuTLS exists. And NSS in mozilla. Probably others too.
How much more fun/comfortable is NSS/GnuTLS to use in a typical C project in comparison to OpenSSL?
Great potential to learn for developers and users alike this heartbleed.
Re: "OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
#17Re: "OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
#18So what are the options then if OpenSSL isn’t fit for purpose? Is it possible to move wholesale to a different project? Are any of them trying to ease migration over from OpenSSL to themselves?
Not sure which one I'd pick; all of the main libraries seems to either have had very bad issues reported at one point or another or are maybe not used enough to inspire enough conficdence; anyway here is a list https://en.wikipedia.org/wiki/Comparison_of_TLS_Implementati...
Re: "OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
#19Im shocked, dismayed and disheartened.
OpenSSL if still maintained by these folks should be wholesale deprecated in all versions and forever more.
Over and out.
Re: "OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
#20What are we a bunch of pretentious fucking children who forgot how to code?
Untrusted input HELL fucking LO!