Over 300.000 LoC:
~/tmp/openssl-1.0.1g $ find . -name "*.c" | xargs wc -l | tail -n1
349834 total
This is too much by at least one order of magnitude.
What's the going price for a crypto-level code review
(I'm not even saying audit) these days?Is all this code necessary for state-of-the art encryption or isn't it rather backwards compatibility baggage? If the latter: how much could be gained by splitting the project into '-current' and '-not'?