Live data from Hacker News

WolfSSL sucks too, so now what?

blog.feld.me

71–80 of 136 posts

Re: WolfSSL sucks too, so now what?

#71

This is the WolfSSL maintainer's response[1] > This ticket is rather long and has a lot of irrelevant content regarding this new topic. If I need to bring in a colleague I do not want them to have to wade through all the irrelevant context. If you would like, please open a new issue with regards to how we support middlebox compatibility. The author turns this into: > The GitHub issue comment left at the end leads me…

I was reading through the complete issue thread and I have to say I probably would side with the wolfSSL maintainers in part but they could have handled it in a nicer way.

"Anthu" only responded with this after "feld" asked why the issue was closed by them, and only then the response you mentioned was written.

"Anthu" could have simply asked before closing the issue and the reporter would have been fine. Like, say "So, this issue meanwhile evolved into RFC compliance and got a bit off track in my opinion. Can you please open up a separate issue for this so we can get this fixed in a more focused manner? That would be very helpful for our workflow. If not, I would open up an issue and reference this one if that's okay with you."

My point is that feld felt a little ignored in their problem, and the support role could have handled it a little nicer. I get that maintainer time is limited, but I would probably recommend an issue template for these matters where there's checkboxes in them like "keep it short, keep it reproducible" and maybe a separate issue template and tag for RFC matters.

On the other hand, "feld"'s blog post reaction was also quite trigger happy and in part in bad faith. They could've communicated the same things in a "non rage mode" after things have calmed down a bit.

Re: WolfSSL sucks too, so now what?

#72

Earlier quoted context omitted.

Where did I judge the FreeBSD community?

Probably where you said: > If this is what the FreeBSD community is like, I want nothing to do with them.

>If

“If you break the law, then you go to jail” is not “you broke the law, you are going to jail”. I didn’t judge the entire FreeBSD community based on this blog post.

Re: WolfSSL sucks too, so now what?

#73

Earlier quoted context omitted.

Out of interest, how is that relevant? Are we not able to criticize a FOSS maintainers response unless we run a project of scale ourselves? The maintainer is clearly engaging and knows what the problem is but stalls on the "last mile" which is issue creation. Do you agree? wolfSSL also sells commercial licenses so it's not like they're going uncompensated for their work. Regardless, we shouldn't put people on pedesta…

Unless you're paying you are not entitled to anything apart from forking and fixing it yourself. You are especially not entitled to bullying maintainers as has been unfortunately the standard in infosec. Open source is not about you. https://gist.github.com/richhickey/1563cddea1002958f96e7ba95... IMO more projects have to explicitly state this for example in a terms document, like https://github.com/mhoye/maintenance…

> Open source is not about you.

You know a social movement went full circle when a criticism that is so scathing, you couldn't have possibly come up with it and make it trend before, even if you gave it your all, is now a motto and a point of pride for those who follow it.

This is happening at the same time where hundreds of millions of regular variety consumers are being fed propaganda daily about how it's "finally time to switch to Linux", because it's so much better for them, the individual. If only they knew it's apparently not actually about them, never has been, and never will be.

Re: WolfSSL sucks too, so now what?

#74

Earlier quoted context omitted.

Probably where you said: > If this is what the FreeBSD community is like, I want nothing to do with them.

>If “If you break the law, then you go to jail” is not “you broke the law, you are going to jail”. I didn’t judge the entire FreeBSD community based on this blog post.

Fun game, let's keep playing.

Where did they say you did?

Re: WolfSSL sucks too, so now what?

#75

Earlier quoted context omitted.

Unless you're paying you are not entitled to anything apart from forking and fixing it yourself. You are especially not entitled to bullying maintainers as has been unfortunately the standard in infosec. Open source is not about you. https://gist.github.com/richhickey/1563cddea1002958f96e7ba95... IMO more projects have to explicitly state this for example in a terms document, like https://github.com/mhoye/maintenance…

> Open source is not about you. You know a social movement went full circle when a criticism that is so scathing, you couldn't have possibly come up with it and make it trend before, even if you gave it your all, is now a motto and a point of pride for those who follow it. This is happening at the same time where hundreds of millions of regular variety consumers are being fed propaganda daily about how it's "finally…

When exactly is 'before'? Before Github existed to put front and center your code and its issues? Before it became an expectation to have a a rich Github profile when you're considered for a job position?

Of course I wouldn't have been able to come up with this statement because the perverted view of OSS devs owing free work to the users of their software was not so pervaisive.

On your edit: a bit rich saying the calls for switching to Linux propaganda, especially with the downturn of UX of windows and macos... Also why just hundreds of millions.. Go for hundreds of billions if you're just going to pull out numbers. Apart from that - even if Linux is not about the users, it is in many cases better for them as-is. Funny how that works with no conflict.

Re: WolfSSL sucks too, so now what?

#76
post #23
post #12

Earlier quoted context omitted.

Again: the maintainer does not say there is no bug. He says: please open a new issue, with a proper title and description for the actual underlying problem. Is that seriously too much to ask? Instead, the guy writes a whole blog post shitting on the project. Does anyone still wonder why people burn out on maintaining FOSS projects?

Not great behavior I agree, but what else is there to say other than "it does not match the spec at point 1.2.3"?

Exactly, that's all his PR had to be. The history of finding the issue could be an interesting story (I bet it involves Elixir!), but in places it reads as almost malicious. If I received a PR anything like that on something I maintained, it would be received very poorly. The author comes off as overly aggressive toward the maintainers and far too sensitive to their response.

Re: WolfSSL sucks too, so now what?

#77

Earlier quoted context omitted.

>If “If you break the law, then you go to jail” is not “you broke the law, you are going to jail”. I didn’t judge the entire FreeBSD community based on this blog post.

Fun game, let's keep playing. Where did they say you did?

I'm not "playing a game". "Feld" purports to be a FreeBSD ports committer. Someone with commit rights on a major project would know how to properly file issues and work with other maintainers. But "feld" doesn't seem to know how to do that. Perhaps "feld" had a bad day, or maybe him and the rest of the FreeBSD ports contributors/maintainers just operate in this way, I don't know.

>Where did they say you did?

They said it in the part where you got all confused and responded to me.

Re: WolfSSL sucks too, so now what?

#78

Earlier quoted context omitted.

Fun game, let's keep playing. Where did they say you did?

I'm not "playing a game". "Feld" purports to be a FreeBSD ports committer. Someone with commit rights on a major project would know how to properly file issues and work with other maintainers. But "feld" doesn't seem to know how to do that. Perhaps "feld" had a bad day, or maybe him and the rest of the FreeBSD ports contributors/maintainers just operate in this way, I don't know. >Where did they say you did? They sai…

You're not playing a game? Could have fooled me.

What you originally responded to above:

> I don't think it's fair to judge the whole FreeBSD community by one person.

So they just like, gave us a fun fact, right?

Conversely, I was also apparently just speculating:

> Probably where you said

So many things are possible when we don't want to be found wrong. Including pretending that figurative speech only exists when it's convenient.

Otherwise, I really don't see what would be so hard in understanding why throwing an "if" at the start would still lead to people taking what you said the way they did.

For the record, contrary to your assertion, even your example is affected by this:

> If you break the law, then you go to jail

If you posted this (and even only just this) under a random thread, people would think you're accusing someone (whoever the given thread is most about) to be somehow guilty of some untold crimes and/or that some chatbot got loose. I hope you can appreciate how people would be absolutely correct to think that way.

Re: WolfSSL sucks too, so now what?

#79

Earlier quoted context omitted.

> Open source is not about you. You know a social movement went full circle when a criticism that is so scathing, you couldn't have possibly come up with it and make it trend before, even if you gave it your all, is now a motto and a point of pride for those who follow it. This is happening at the same time where hundreds of millions of regular variety consumers are being fed propaganda daily about how it's "finally…

When exactly is 'before'? Before Github existed to put front and center your code and its issues? Before it became an expectation to have a a rich Github profile when you're considered for a job position? Of course I wouldn't have been able to come up with this statement because the perverted view of OSS devs owing free work to the users of their software was not so pervaisive. On your edit: a bit rich saying the cal…

> When exactly is 'before'?

"Exactly"? I'm afraid that's not a very physically sound request. But let's say, prior to 2026-02-14T03:46:03Z then. I hope that suffices.

> Of course I wouldn't have been able to come up with this statement

That would make sense, because you specifically I never expected to: https://en.wikipedia.org/wiki/Generic_you

> Also why just hundreds of millions.. Go for hundreds of billions if you're just going to pull out numbers

You see, that would be because I did not just pull out an arbitrary number. "How many Windows users there are" is a reported fact you can just search for, and even the total is not "billions" (plural). I know, I was surprised too. From the horse's mouth: https://blogs.windows.com/windowsexperience/2025/06/24/stay-...

Re: WolfSSL sucks too, so now what?

#80

Earlier quoted context omitted.

The maintainer should just open a new issue for RFC compliance himself since that's a pretty big issue and he obviously thinks OP spams too much. This game of stalling / obfuscating via the issue tracker gets very old.

Why should that be the maintainer's burden?

Because they're the ones asking for the administrative burden of refiling a basic RFC violation bug?
Post reply on HN