Live data from Hacker News

OpenSSL Project Roadmap

openssl.org

1–10 of 31 posts

Re: OpenSSL Project Roadmap

#3
post #2

So now we have a third refactor?

It looks mostly like they've taken on-board the criticisms from the OpenBSD developers and have decided to get their house in order.

It will be interesting to see whether this turns out to be just words or if they'll stick it through. If the actually implement what they're planning the future for OpenSSL will be a lot better.

Re: OpenSSL Project Roadmap

#4
This is great news indeed. At least now we know the OpenSSL developers recognize the problems they have and that they are actively working on fixing them.

This definitely increases my confidence in them.

Re: OpenSSL Project Roadmap

#6
post #2

So now we have a third refactor?

Eh, it shouldn't be that bad. The Google and OpenBSD teams certainly can operate only independently and they have both pledged to cooperate with The OpenSSL Project (as well as with each-other).

Things are looking up, IMO.

Re: OpenSSL Project Roadmap

#7
While I would not necessarily prioritize this above any of their other concerns mentioned in the roadmap, I would love to see openssl use a more standard build process instead of generating code through perl as part of their build

Re: OpenSSL Project Roadmap

#8
I don't expect much to come from rewarding failure. Throwing money away at OpenSSL isn't suddenly gonna make its developers good.

I'll be running LibReSSL, and I expect most Linux distributions to do the same by default once the Linux port is released.

Re: OpenSSL Project Roadmap

#9
post #8

I don't expect much to come from rewarding failure. Throwing money away at OpenSSL isn't suddenly gonna make its developers good. I'll be running LibReSSL, and I expect most Linux distributions to do the same by default once the Linux port is released.

Yes. It's also funny that if you look at each of the 8 points identified in the posted link, they're like all have already been identified and many have already been fixed in LibReSSL.

Why use OpenSSL, if LibReSSL already has had a head start on each issue? And OpenSSL probably doesn't even intend to address some of these, like removal of FIPS support.

Post reply on HN