Live data from Hacker News

LibreSSL

libressl.org

81–90 of 262 posts

Re: LibreSSL

#81
post #45

Earlier quoted context omitted.

Well I disagree. Whilst it's a natural choice for portability, when you port to a proprietary platform such as windows you lose a lot of the support and portability guarantees that POSIX gives you and the calling conventions and standards of many libraries. At this point it's advisable to pick a holistic 3rd party abstraction over this such as something right from APR to Qt that will abstract the platform specific im…

This is all great, but the fact remains that OpenSSL is very widely used on Windows and yanking it out without providing a drop-in replacement option is a bad idea. We can debate finer nuances of proper abstraction to the death, but it doesn't move a needle for people who already have OpenSSL dependencies in their code.

For right now, it does not matter. Their goal is to fix the project from a security point of view, and it would be impossible if they tied their hands with that during the course of development.

In the future, you can expect the same deal as OpenSSH, OpenNTPD and all the other OpenBSD software that _eventually_ gets ported to other architectures when it reaches a point of stability and safety that it makes sense to do so.

Re: LibreSSL

#83

Comic sans?? lol! This page scientifically designed to annoy web hipsters. Donate now to stop the Comic Sans and Blink Tags

Ah yes, the kind of professionalism I've come to expect from OpenBSD. They make decent software, but boy could they use some work in the PR department.

Re: LibreSSL

#84
post #19

I understand the point but this comes across as immature. OpenSSL has provided years of free software, supporting thousands of sites and applications. Of course it has its problems, and there is nothing wrong with adding more competition in this space. But what this space needs now, more than ever, is professionalism and pride in craft (by which I mean demonstrable unit test coverage, regression testing, fuzz testing…

Agreed. This is a bit scary. I feel the resources would be better off focusing on merging with the official OpenSSL project rather than forking and _then_ asking for funding, essentially taking any potential funding from the official OpenSSL project.

I get your point, but let's face it, the OpenBSD developers have done more to fix OpenSSL in the last two weeks that the OpenSSL developers done the last two years.

Some of the bug fixes have been pull from OpenSSLs bugtracker, they've just sat there for one or two years. This should make you think about what motivates the OpenSSL developers, my guess would be new crypto algorithms and the math, rather than maintaining a modern and secure crypto library.

Honestly the better solution might be to have the OpenSSL developers commit new code to the OpenBSD fork. For my understanding no one doubts that the OpenSSL developer understand the math and crypto in SSL and TLS, but they aren't the sharpest C programmers. There's no point in ostracising the OpenSSL developers, but maybe they should just focus on the parts that they do really well and let others, like the OpenBSD developer, productize their work.

Re: LibreSSL

#86
post #43

Earlier quoted context omitted.

I'd hope that I speak for the majority here when I say that OpenSSL has had its chance. This is the beauty of open source, nothing more. We can take this and make it better.

Count the number of vulnerabilities in OpenSSL over the last few years, relative to the size of its code base. A single vulnerability, albeit bad this year, results in a fork and the attitude of "it had its chance." LibreSSL inherits all of the undiscovered vulnerabilities in its huge code base. I hope your harsh criticism carries over to its code base once these flaws are discovered here too. That's the beauty of op…

number ok known vulnerabilities you mean ?

The problem is that a security software brick is not satisfactory when it works, but when you can be sure there are no problems.

Given the very low quality of the code and the high amount of bloat, few people actually trust it. They have to trust third-parties and external certifications and the word on the street, and this is not enough for that kind of dependency.

Re: LibreSSL

#87

I'm assuming it is a parody (because of the font)? In any case forking OpenSSL seems like a knee jerk reaction?

"This page scientifically designed to annoy web hipsters. Donate now to stop the Comic Sans and Blink Tags"

Re: LibreSSL

#88
post #30

OpenBSD folks, what is your obsession with CVS????

Why are people so obsessed with getting the OpenBSD developers to move from CVS? If it works for them and do what they need there's no need to move.

Because people might be interested to review their changes, and CVS makes that very difficult.

Re: LibreSSL

#89
post #19

I understand the point but this comes across as immature. OpenSSL has provided years of free software, supporting thousands of sites and applications. Of course it has its problems, and there is nothing wrong with adding more competition in this space. But what this space needs now, more than ever, is professionalism and pride in craft (by which I mean demonstrable unit test coverage, regression testing, fuzz testing…

Agreed, the tone of the page and the footer prevents me from taking these guys seriously, especially in this area (even more so with recent events).

Which goes to show that you're not the intended end-consumer of this product and don't know their credentials. They are not newcomers to this space. If their tone is off-putting, maybe you should stop relying on OpenSSH too.

Re: LibreSSL

#90
post #69
post #43

Earlier quoted context omitted.

I'd hope that I speak for the majority here when I say that OpenSSL has had its chance. This is the beauty of open source, nothing more. We can take this and make it better.

Quite frankly unless LibreSSL manages to raise more than 2000$ a year (what the OpenSSL fundation makes, apparently) I fail to see how they hope to avoid encountering the same kind of problems OpenSSL did (and still does). And given that the OpenBSD projects had to beg for donations to reach a 150k$ goal, if memory serves, I doubt they'll be able to sink a tremendous amount of money into LibreSSL. If you can't pay pe…

>the OpenBSD projects had to beg for donations to reach a 150k$ goal

Well, true, but I don't think that anyone know how badly they needed the money and the $150.000 was collected in three month.

OpenSSH have been around for a long time, without much funding really. OpenCVS was a bit of a dud though.

Post reply on HN