Live data from Hacker News

WolfSSL sucks too, so now what?

blog.feld.me

61–70 of 136 posts

Re: WolfSSL sucks too, so now what?

#62

Earlier quoted context omitted.

The maintainer should just open a new issue for RFC compliance himself since that's a pretty big issue and he obviously thinks OP spams too much. This game of stalling / obfuscating via the issue tracker gets very old.

Why should that be the maintainer's burden?

If they're doing this and bothering to interact with tickets at all, presumably they've willingly taken on a duty to the software's quality and all that that entails.

Re: WolfSSL sucks too, so now what?

#63
post #27

Earlier quoted context omitted.

The maintainer should just open a new issue for RFC compliance himself since that's a pretty big issue and he obviously thinks OP spams too much. This game of stalling / obfuscating via the issue tracker gets very old.

> The maintainer should just Out of interest: which FOSS projects are you maintaining, and how many users do these have, approximately?

I maintain several FOSS projects, although none as popular as wolfssl and if I want to make a new issue to make it more clean, I usually do it myself, because then I can write it the way I want, and include the information, and only the information, that I think is important. If I ask someone else to do it, there's a pretty good chance they won't write it the way I would like, if they write it up at all.

Re: WolfSSL sucks too, so now what?

#64

Earlier quoted context omitted.

The maintainer should just open a new issue for RFC compliance himself since that's a pretty big issue and he obviously thinks OP spams too much. This game of stalling / obfuscating via the issue tracker gets very old.

Why should that be the maintainer's burden?

If the maintainer is trying to write something RFC-compliant, and someone reports a violation of the RFC, it sure seems reasonable for the maintainer to want to track that.

If they don't want to, that's certainly their right, but it also tells us something about that project.

Re: WolfSSL sucks too, so now what?

#65

Many people and projects have tried to ditch OpenSSL in favor of LibreSSL, WolfSSL, MbedTLS, etc, but by now many have returned to OpenSSL. The IQ curve meme with "just use OpenSSL" applies.

I have systematically and successfully banned OpenSSL across all of my Rust projects. Sure, RusTLS shares a few C crypto primitives with OpenSSL forks. But I've never been happier with the overall library.

Re: WolfSSL sucks too, so now what?

#66

Earlier quoted context omitted.

The maintainer should just open a new issue for RFC compliance himself since that's a pretty big issue and he obviously thinks OP spams too much. This game of stalling / obfuscating via the issue tracker gets very old.

Why should that be the maintainer's burden?

Presumably, the maintainer wants the best for the product and its users. So they have a definite interest in documenting a todo list.

Presumably, the user wants the best for the product and their ability to use the product. So they have a definite interest in documenting a todo list.

It doesn't make sense for the two to be at war with each other. It is no big deal for the maintainer to ask a favor. It's not too big of a deal for the user to decline. There's no need to attack.

I have often dropped a note to the maintainer of a project I bumped into. I'm sure they would prefer a bug report in their official forge. But I don't really use their software except for this one time. I'm not willing to jump through the hoops to create an account in yet another SaaS just to file this one report. Just dropping them an email was a courtesy. But often they don't interpret it that way. I'm perfectly un-insulted if they just delete my note and never "fix" the issue because it didn't come through proper channels.

No attacks. No war. Just well wishes. But I might very likely avoid the product if I'm ever back in those woods. Not out of anger or retribution. Just because I'll remember that the product had at least one sharp edge for my use case and the maintainer was a bit overwhelmed by the weight of supporting my niche use case. That doesn't make the maintainer a bad person or even a bad maintainer.

Re: WolfSSL sucks too, so now what?

#67

The blog author seems like a real piece of work. He ghosts the WolfSSL maintainer for over 160 days and when asked to open a new, more specific issue, he instead chooses to write a blog post denigrating the project. The WolfSSL maintainer was nothing but courteous and helpful throughout the entire exchange. >...they aren't really interested in RFC compliance. Yeah, well "feld" can't claim to be "interested in RFC com…

I don't think it's fair to judge the whole FreeBSD community by one person.

Where did I judge the FreeBSD community?

Re: WolfSSL sucks too, so now what?

#68

> Asking me to open a new issue to discuss this behavior instead of it being a high priority for them to open up a new issue internally to fix this is odd. I'm not here to do their homework for them. Why are people so entitled? How much is the author paying WolfSSL to make demands of them? > Currently I've only identified one victim of this decision, but there's bound to be more out there. Oh yes, he has become a vic…

Neither person is entitled to the work of the other and neither wants to do the work which seems to be how we ended up here. The author can't make demands of the project and so wrote a blog post warning others that it's not production ready and you'll have broken software if you use it. Their conclusion isn't that they must fix it but that you should use a more mature library.

Two adults both defected in the social prisoner's dilemma and so here we are. Both individuals believing to have done free labor for the other and that they should be grateful.

Re: WolfSSL sucks too, so now what?

#69

> Asking me to open a new issue to discuss this behavior instead of it being a high priority for them to open up a new issue internally to fix this is odd. I'm not here to do their homework for them. Why are people so entitled? How much is the author paying WolfSSL to make demands of them? > Currently I've only identified one victim of this decision, but there's bound to be more out there. Oh yes, he has become a vic…

> Oh yes, he has become a victim of using a FOSS library.

many such cases

Re: WolfSSL sucks too, so now what?

#70

Earlier quoted context omitted.

I don't think it's fair to judge the whole FreeBSD community by one person.

Where did I judge the FreeBSD community?

Probably where you said:

> If this is what the FreeBSD community is like, I want nothing to do with them.

Post reply on HN