Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Given the OpenSSL trackrecord [1], I recommend switching to LibreSSL [2] if possible. They tore through OpenSSL to pull out all the horrors they found and beat it into shape. OpenSSL's code was so unbelievably bad that there's certainly more problems lurking in there.

[1] http://www.openbsd.org/papers/bsdcan14-libressl/mgp00001.htm...

[2] http://www.libressl.org/releases.html




Has Google changed their stance on not wanting BoringSSL to be a replacement for OpenSSL as an open source project? https://www.imperialviolet.org/2014/06/20/boringssl.html


No, although I've been pinging Ben Laurie on having them slap version numbers on it periodically. I think that'd be nice.

The (perhaps obviously biased) TLS Under Siege talk by Google's Neel Mehta ranked BoringSSL #1 (of 2) when it came to OpenSSL forks, FWIW:

https://ruxconbreakpoint.com/assets/2014/slides/TLS%20Under%...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: