Please Put OpenSSL Out of Its Misery
queue.acm.org
queue.acm.org
Haskell comes to mind. If we want to avoid a runtime, let's go for a language like Rust, which also has strong safety guarantees and lots of Haskell/ML-inspired features that help improve both safety and readability (advanced pattern matching, Options, immutability guarantees, etc.)
Both of these languages are sufficiently fast to develop high-performance crypto frameworks, and both have good FFIs for calling optimized C code if necessary.
When a bug like this hits the news all around the world, it is a good time to make sure everybody knows it is not just some once-in-a-century instance of the inevitable shit happens in an otherwise good project. Getting everybody to realize it is possible to do better is one step towards making it happen.
Also, this complaint is a bit like the one earlier about the Wired article saying everything should be encrypted being sent over http and not https. The authors are calling for change, the publication's medium is managed by someone else. Your little gripe would be far more appropriate if it were a blog author on their own platform calling for some change but not applying it to their own platform.
There may be an average of 1 error per 1000 lines of code, but saying that there are 299 remaining bugs in OpenSSL is like saying there are sixteen thousand vulnerabilities in the Linux kernel. All software is backdoored if you go by this standard. There would be no such thing as security anymore. So the rule is flawed.
Then another third of the post goes on to complain about the excessive list of CAs in our browser. How does this have anything to do with OpenSSL? What cryptographic breakthrough do you propose we use instead?
Until then, I suppose you just shut up and try to work on the OpenSSL code, or an alternative library, instead of writing blogposts.
Also, this is a repost:
The bug estimates phk gives might not be hard science, but having spent the past few days looking at the OpenSSL code, I think his critique is spot on.