Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The appearance and track record† of the code in OpenSSL does the credibility of TLS no favors, and it is totally understandable why someone who had to deal with software security for a platform that ships and depends on OpenSSL would become allergic to it.

But, two responses to that:

* First, what Joel Spolsky says about rewrites. Sometimes code is ugly for a reason. Clean rewrites of OpenSSL will inevitably introduce bugs. Introducing bugs in SSL†† implementations is perilous.

* Second, there are mature alternatives to OpenSSL. For instance, most? browsers don't use it.

† In fairness, that's because OpenSSL dates back to a time when nobody was getting C software security even close to right.

†† I use TLS and SSL interchangeably, which is a foible I should work on correcting, but the difference doesn't matter much here.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: