Serious question: is it better to rewrite a library that's had a lot of implementation problems, or is it better to keep hardening OpenSSL?
13
15
5
Replying to @mtnygard
@mtnygard Well, you know about Things You Should Never Do (Part I): joelonsoftware.com/articles/…

Apr 7, 2014 · 9:42 PM UTC

1
1
Replying to @stilkov
@stilkov Yep. Except when you should.
1
@mtnygard Right. But a security lib especially strikes me as the sort of thing that gets a lot of value from a decade or two of bug fixes
2