I think it is pretty foolhardy to assume that just because security issues haven't been found means they don't exist.
I think it is pretty foolhardy to assume that just because security issues haven't been found means they don't exist.
https://www.openssl.org/news/secadv/20160926.txt
<sigh>
No one can reasonably say that the practices of the OpenSSL programmers result in secure code. No one can reasonably say that lots of people examining it later for defects is a good idea.
We have lots of legacy code in C. The only sane way to maintain it is tests: unit tests, functional tests, and static code analysis.
> a lot of OpenSSL's issues are due to legacy code
i.e. the OpenSSL people don't care to actively maintain / clean up their software.
What a depressing statement to make.
a) one which has tests, no build warnings, and is run through 3 different static analysis tools?
b) one which has none of those things?
2) Also, which of these products is more likely to be secure?
a) one which has a lot of third-party analysis?
b) one which has some third-party analysis?
3) Are these two questions the same?
My answer to (3) is "no".
While best combination of answers would be 1(a) and 2(a), OpenSSL is at 1(b) and 2(a). I'd bet they still have more security issues than FreeRADIUS, which is at 1(a) and 2(b).
That's all I meant.