Serious question: is it better to rewrite a library that's had a lot of implementation problems, or is it better to keep hardening OpenSSL?
13
15
5
@mtnygard Well, you know about Things You Should Never Do (Part I): joelonsoftware.com/articles/…
1
1
@stilkov Yep. Except when you should.
1
Replying to @mtnygard
@mtnygard Right. But a security lib especially strikes me as the sort of thing that gets a lot of value from a decade or two of bug fixes

Apr 7, 2014 · 9:45 PM UTC

2
Replying to @stilkov
@stilkov I would _almost_ always agree, but for some opinions from people I respect who say OpenSSL is unsalvageable.
2
Replying to @stilkov
@stilkov I'm not qualified to evaluate it myself.
1
@mtnygard I can’t either, but it’s probably true that a security lib is a particularly bad place for too much legacy-related complexity
1