Hacker News new | ask | show | jobs
by morgante 4453 days ago
I think the saddest thing is how incredibly short the list of OpenSSL sponsors is.[1] Every major internet company should be on there—throwing thousands of dollars at this is far less than they lose from responding to the vulnerabilities. As a critical piece of internet infrastructure, everyone with a large (monetary) stake in the integrity of that infrastructure should chip in some.

1: https://www.openssl.org/support/acknowledgments.html

1 comments

Absolutely. I was really surprised to hear this. I'm sadly getting the impression that the only large entities who have thrown funding into audits are the intelligence agencies.