Serious question: is it better to rewrite a library that's had a lot of implementation problems, or is it better to keep hardening OpenSSL?
13
15
5
@mtnygard Well, you know about Things You Should Never Do (Part I): joelonsoftware.com/articles/…
1
1
@stilkov Yep. Except when you should.
1
@mtnygard Right. But a security lib especially strikes me as the sort of thing that gets a lot of value from a decade or two of bug fixes
2
@stilkov I'm not qualified to evaluate it myself.
1
Replying to @mtnygard
@mtnygard I can’t either, but it’s probably true that a security lib is a particularly bad place for too much legacy-related complexity

Apr 7, 2014 · 9:48 PM UTC

1