Can we downvote submissions or something? Because this is absolute rubbish.
There may be an average of 1 error per 1000 lines of code, but saying that there are 299 remaining bugs in OpenSSL is like saying there are sixteen thousand vulnerabilities in the Linux kernel. All software is backdoored if you go by this standard. There would be no such thing as security anymore. So the rule is flawed.
Then another third of the post goes on to complain about the excessive list of CAs in our browser. How does this have anything to do with OpenSSL? What cryptographic breakthrough do you propose we use instead?
Until then, I suppose you just shut up and try to work on the OpenSSL code, or an alternative library, instead of writing blogposts.
Though I really appreciate the shut up and hack mentality, sometimes people have to pick their battles. It might still be appropriate to send a message to the community to draw attention to the issue, in the hope that somebody else has the time to do the hard work. In this case it seems like OpenBSD might be doing that work.
The bug estimates phk gives might not be hard science, but having spent the past few days looking at the OpenSSL code, I think his critique is spot on.
Comments
Can we downvote submissions or something? Because this is absolute rubbish.
There may be an average of 1 error per 1000 lines of code, but saying that there are 299 remaining bugs in OpenSSL is like saying there are sixteen thousand vulnerabilities in the Linux kernel. All software is backdoored if you go by this standard. There would be no such thing as security anymore. So the rule is flawed.
Then another third of the post goes on to complain about the excessive list of CAs in our browser. How does this have anything to do with OpenSSL? What cryptographic breakthrough do you propose we use instead?
Until then, I suppose you just shut up and try to work on the OpenSSL code, or an alternative library, instead of writing blogposts.
Though I really appreciate the shut up and hack mentality, sometimes people have to pick their battles. It might still be appropriate to send a message to the community to draw attention to the issue, in the hope that somebody else has the time to do the hard work. In this case it seems like OpenBSD might be doing that work.
The bug estimates phk gives might not be hard science, but having spent the past few days looking at the OpenSSL code, I think his critique is spot on.
There's a flag link under the article title here. If you dislike something that's the closest you get to downvoting it.
Also, this is a repost:
https://news.ycombinator.com/item?id=7586705