Hacker News new | ask | show | jobs
by qwertyuiop924 3620 days ago
OpenSSL is pretty bad. After reading about some of the stuff that lead the the libressl fork, I wouldn't trust it with my lunch money. Sure, the algorithms are good, but as far as the code's concerned, Heartbleed was the tip of the iceberg.
1 comments

There's a saying, "don't roll your own crypto," and it's good advice.

In the case of openssl, you might be better off rolling your own. At least the vulnerabilities you end up with are different than the ones that the rest of the world has.

the deeper and deeper ive gotten into breaking crypto. the more and more ive come to the conclusion that saying is positively poisen.

"dont try and do it all on your own but trust no one else to do it for you" probably better.

An open, modular project with a wide choice of options would be a godsend and wipe out most digital crime almost overnight.

Of course, then, they couldnt use the likes of yahoo and google to read drug dealers emails.