Earlier quoted context omitted.
And how long is LibreSSL on the market? A year? It's hard to call it proof . It's easy to point intervals longer than whole LibreSSL lifetime with no security bugs in OpenSSL.
LibreSSL is a cleanup of the OpenSSL base. They started with OpenSSL and worked from there. They have mostly deleted code, not added it, so they shouldn't be adding many new vulerabilities. On top of this, it is being written by the OpenBSD/OpenSSH people, who have a good history with writing secure software.
Re: OpenSSL Security Advisory
#141Still, a sole year is hardly an evidence of quality.