Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hindsight bias? We should audit libnss and all the other cryptography libraries too then. And don't forget how much of the world relies on closed-source solutions like Microsoft's Bitlocker. Better shun those because they had no public audits and for all we know they're even more spaghetti code.


No, it's not hindsight bias. I have posted (and so have others) on many public forums for years about the need for an audit of OpenSSL and OpenSSH and there have been many discussions about the sad state of the codebase in OpenSSL.

I can think of a particular discussion on the cryptography mailing list at randombit from ... two years ago ?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: