The OpenSSL maintainers seem to be doing something other than all that. The historical defence for this was that they had minimal funding (which is no longer true), and that the funding they did have was for adding new features.
That's just not an acceptable excuse. And it never was an acceptable excuse.
Cleaning up code should be part of normal software development. Re-factoring code, adding unit tests, etc. Adding static analysis builds (clang is free, and Coverity is free for open source projects).
It's 2016. Why are some people still using software practices from 1992?
Being binary compatible with libssl.so is just insane (too many symbols), but obviously doable. Volunteers welcome
https://www.cl.cam.ac.uk/%7Ejdy22/papers/ocaml-inside-a-drop...
I guess it would pop up there: https://www.youtube.com/channel/UCwRL68qZFfub1Ep1EScfmBw/vid...
Eventually we get the safety we had in the 90's back and improved.
[0] - https://www.infoq.com/presentations/csharp-systems-programmi...
[1] - https://swift.org/about/
[0] - https://github.com/duneroadrunner/SaferCPlusPlus (Note: shameless plug.)
Removing the dependency on OpenSSL is going to be a challenging, messy job. OpenBSD has mostly transitioned over to their LibTLS API but even they had difficulty moving some projects over.
If SSL/TLS is a kitchen-sink, OpenSSL is Home Depot.
- Type safe enumerations
- Strings with guaranteed size (not missing '\0')
- No implicit conversions
- No undefined behaviour
- Validation of null pointers on access
- ...
Also, couldn't distros just provide a version of the library built with the AddressSanitizer[0] enabled as well? It would be slower, but should be much safer. Let the user choose? Not the ultimate solution, but for the short term.
[0] https://github.com/google/sanitizers/wiki/AddressSanitizer
[1] http://www.cs.rutgers.edu/~santosh.nagarakatte/softbound/
[1] https://blog.torproject.org/blog/tor-browser-55a4-hardened-r...
http://caml.inria.fr/pub/docs/manual-ocaml/intfc.html
I'm not sure at a glance how easy it will be to use F star programs in C applications via Ocaml. We'd be better off if there was a compiler from F star to annotated/safe C, Ada/SPARK, or Rust. All of these can integrate more easily into the legacy apps.
This is a piece of software that is so core to our computer ecosystem that I am sure plenty of companies would contribute financially and with developer time. Heck, if this couldn't get enough funding for at least 5 fulltime devs plus external audits then we're in a sad state of an ecosystem. IMHO this actually should receive public funding. It would be more useful than many other things that get public funds.