Earlier quoted context omitted.
OpenBSD is not auditing OpenSSL. They're substantially rewriting it. The net effect is hopefully similar, but it's a very different path to get there. Further, the refactor might introduce new bugs, and it can easily miss subtle bugs (we're talking about cryptography, which is not as easy to spot or to fix "accidentally" [which is part of OpenBSD's M.O.] as memory corruption). "Theo's a dick" has nothing to do with w…
I would trust Theo's team over the OpenSSL team any day of the week.
OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative
51–60 of 94 posts
Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative
#52Earlier quoted context omitted.
OpenBSD is not auditing OpenSSL. They're substantially rewriting it. The net effect is hopefully similar, but it's a very different path to get there. Further, the refactor might introduce new bugs, and it can easily miss subtle bugs (we're talking about cryptography, which is not as easy to spot or to fix "accidentally" [which is part of OpenBSD's M.O.] as memory corruption). "Theo's a dick" has nothing to do with w…
I would trust Theo's team over the OpenSSL team any day of the week.
Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative
#53Earlier quoted context omitted.
OpenBSD is not auditing OpenSSL. They're substantially rewriting it. The net effect is hopefully similar, but it's a very different path to get there. Further, the refactor might introduce new bugs, and it can easily miss subtle bugs (we're talking about cryptography, which is not as easy to spot or to fix "accidentally" [which is part of OpenBSD's M.O.] as memory corruption). "Theo's a dick" has nothing to do with w…
A security audit may also miss subtle bugs, and the proposed corrections may introduce new bugs. A rewrite has the benefit that it will lead to manageable code, instead of the current mess. Clean code has less places where subtle bug can hide, that does not change just because you are doing cryptography. Anyway, they should send money to both. Both are important, and those companies make so much money using free soft…
I am not in the least bit interested in the Theo vs. Whoever drama subtext. This whole subthread strikes me as similar to any other thread about a charitable donation, where people come out of the woodwork to cast aspersions that money wasn't given to some worthier cause.
Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative
#54Just give the money to the OpenBSD team. We saw with OpenSSH that they have a proven track record taking crappy security software and fixing it. Why does everyone have this aversion to giving the OpenBSD team the funding they deserve? And "Theo's a dick" doesn't qualify as a valid reason to not fund real security development. For the work those guys have done improving the security infrastructure of every operating s…
Is it possible to give them more granular donations? I want to support OpenSSH and LibreSSL, but I don't cae about OpenBSD. The reason I don't donate to them is that I feel like most of my donation will be going towards something I don't care about.
Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative
#55Earlier quoted context omitted.
"just fixing the problems in openssl." That's what libressl is about. If you're in any doubt, please see this talk: https://www.youtube.com/watch?v=GnBbhXBDmwU
There is no doubt that is the intention. The doubt is whether or not it is a good call to fork openssl instead of attempting to get changes into upstream that fix it and make it better, safer, more reliable.
http://www.openbsd.org/papers/bsdcan14-libressl/mgp00008.htm...
Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative
#56Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative
#57Just give the money to the OpenBSD team. We saw with OpenSSH that they have a proven track record taking crappy security software and fixing it. Why does everyone have this aversion to giving the OpenBSD team the funding they deserve? And "Theo's a dick" doesn't qualify as a valid reason to not fund real security development. For the work those guys have done improving the security infrastructure of every operating s…
> And "Theo's a dick" doesn't qualify as a valid reason to not fund real security development. Yeah, but people who give money usually tend to see that as a valid reason.
Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative
#58Earlier quoted context omitted.
> Yes, you can. It's called contributing to a project. If the "half million lines of diffs" were actually things needing fixing, then the upstream team would accept them. If they are not necessary changes (such as ripping out all windows compatibility), then no, they would reject such changes. I take it you've never dealt with an inactive/apathetic upstream before? Just because someone is the steward of a project doe…
Then you become the steward of the project and continue forward. Forking will introduce an untold number of new bugs, some of which may be worse than imagined. Right now, native libressl only works on bsd's, when openssl codebase works on many os's. There are ports being made, which will introduce more bugs. Bugs being in a tracker for years is not uncommon. Here's OpenSSH's tracker: https://bugzilla.mindrot.org/bugl…
But that is what the fork is, OpenSSL with new stewards. What is your objection? That they are using a different name? That they decided to remove certain platforms which were a maintenance burden? That FIPS is broken by design and therefore isn't a priority? I imagine the OpenSSL team disagrees with the LibreSSL team on all of these issues. The only option was a fork.
> Right now, native libressl only works on bsd's, when openssl codebase works on many os's. There are ports being made, which will introduce more bugs.
One step backwards, two steps forward.
Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative
#59Earlier quoted context omitted.
There is no doubt that is the intention. The doubt is whether or not it is a good call to fork openssl instead of attempting to get changes into upstream that fix it and make it better, safer, more reliable.
Are we talking about OpenSSL that had bugs languishing for years? Yeah, good luck with that one. LibreSSL was the way to go and the OpenBSD folks are the ones I trust to do it.
https://bugzilla.mindrot.org/buglist.cgi?bug_status=__open__...
Fork it now!
~~~
Seriously, stop buying into all the hype generated by heartbleed. Things will simmer down, and it's doubtful libressl will replace openssl anytime in the next 5 years as the standard default ssl lib for many things.
I do not buy into OpenSSL devs not wanting bugfixes.
Where are the public rejections/closures of submitted fixes? There aren't any. There are just assumptions that they wont take certain patches, or submitted patches waiting for review (how about you jump in and help review?).
Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative
#60https://duckduckgo.com/?kh=1&q=Huawei&sites=www.schneier.com...