|
|
|
|
|
by jodiscr
4351 days ago
|
|
Given things like the Debian OpenSSL fiasco and Heartbleed, can we honestly put as much faith into open source crypto as it's well-funded proprietary counterparts? I honestly prefer open source and recognize the problem the author points out as clearly significant problem - as well as the benefits of LibreSSL, but I'm just not convinced there are enough eyeballs looking at open source crypto. |
|
Closed source proprietary crypto, you just don't know who wrote it, who audited it and who backdoored it and who knows of any flaws in it.
Open source crypto, it's there. Go read the source. Anyone can and it's open for audit.
There aren't enough eyeballs I agree but there are infinitely more trustworthy people looking at it than closed source.