But since it's have lot of DEAD code that left there for compatibility reasons. Just like SSL2/SSL3 and their "encryptions".
Google also start fork project - BoringSSL in order to separate their patches between mainline OpenSSL.
But since it's have lot of DEAD code that left there for compatibility reasons. Just like SSL2/SSL3 and their "encryptions".
Google also start fork project - BoringSSL in order to separate their patches between mainline OpenSSL.
If anything IMHO it's significantly cleaner today than it used to be ~10 years ago. It still feel like the code quality is not up to the standard I'd hope for in such a critical piece of software but I don't think it's really worse now.
Unsurprisingly, the childish attention faded into nothing because it's much harder to write good code than it is to tear apart someone else's. But the smear on the OpenSSL volunteers' reputation remains, as seen by GP's comment.
[1] https://opensslrampage.org/page/49
[2] https://opensslrampage.org/post/83555615721/the-future-or-la...
Compare the Go crypto reaction when somebody wants to add ECB mode: https://github.com/golang/go/issues/5597
OpenSSL is better now than it was then, it might even be the least worst option for a lot of people in low-level languages who want to spin up a TLS client or server. But that is deliberately faint praise.