Reply to post:

LibreSSL RNG bug fix: What's all the forking fuss about, ask devs

Pet Peeve

haha, no.

Maybe if openssl was designed properly to extract platform support from the code, you could easily filter out out the dross. But that's the problem - openssl is an unholy mess in a lot of ways, and it is very likely that libressl will run into these problems over and over trying to figure out what's really junk (like support for platforms noboby's tried to deploy on in a decade and probably don't work if they did) and what isn't.

The scary part is that this was an obvious problem. How long is it going to take to find all the broken edge cases that you don't know are broken until they happen? My understanding is that a lot of the openssl versions of libc calls had additional functionality, or returned not QUITE the same things the libc call did, or handled errors differently. All of those are going to bite libressl in the ass, eventually.

I heard someone say the other day that if you see any linux distro with libressl in their stable branch, that is a distro to stay away from, for years at least, and possibly forever. Security is never proven, only demonstrated over time, and libressl's clock starts from zero. All of that said, the best of luck to them!

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon