PHK: OpenSSL must die, for it will never get any better.
queue.acm.org
queue.acm.org
[1]: https://developer.apple.com/library/mac/documentation/securi...
[2]: http://opensource.apple.com/source/libsecurity_ssl/libsecuri...
But I think the major problem with OpenSSL is that it never had anything resembling architectural leadership: Things just got bolted on to the side and hung from any convenient nail people could find.
PS: Yes, I wrote that piece.
Easier said than done. Writing test-suites for a codebase which never had a test-suite is a million times harder than writing a test-suite for new, fresh code.
In fact it's probably easier to start over than re-factoring the code to be testable in the first place, but some people might argue that would be a wee bit drastic. So not saying it can't be done, just that it does take a very significant effort.
If anyone should still feel like doing something like this, I can very much recommend the following book for advice and morale boost:
http://www.amazon.com/gp/product/0131177052/ref=as_li_ss_tl?...
(Discalimer: Affiliate link)