Earlier quoted context omitted.
> Since it is not in fact possible to wave a magic wand and get everyone to run LibreSSL You say that, but it's not as though this is a fundamentally hard problem. How many servers are running nginx today vs. even a few years ago? Moreover, the biggest problem sits with the biggest, and often most capable, internet companies. So having a reasonable path for them to a more secure TLS implementation, even if it meant h…
> You say that, but it's not as though this is a fundamentally hard problem. How many servers are running nginx today vs. even a few years ago? How many years did it take to get there? How many servers are still running apache? > And, of course, eventually switching from openssl to libressl will become as easy as spending a couple minutes with a package manager. Eventually, maybe. That's no reason not to audit openss…
As for auditing OpenSSL, the OpenBSD team has found so many problems, misdesigns, misfeatures, idiotic decisions, and bugs, that it seems a shame to repeat that work again. If I had to choose, I'd say give the OpenSSL name to the OpenBSD guys, let them take over the project officially, and let the folks behind the OpenSSL foundation handle things like platform-dependent code, FIPS compliance patches, etc.