LibreSSL at BSDCan
blather.michaelwlucas.com
blather.michaelwlucas.com
This could lead to some fun arguments, since the Ulrich Drepper rejects the idea of strl{cat,cpy}: http://www.sourceware.org/ml/libc-alpha/2000-08/msg00053.htm...
http://www.linkedin.com/in/ulrichdrepper not Red Hat anymore, apparently.
Maybe it's worth reheating the debate?
At least he's consistent.
This doesn't surprise me; I've had to do runtime detection of socklen_t before. There have been 64-bit platforms (old HP/UX I think?) where different versions of the system libraries had differing opinions about sizeof(socklen_t) when you called accept(). On a little-endian platform this would be ignorable (just always reserve 64 bits and pre-zero it) but on big endian you had to do something like:
uint64_t addrlen = 0;
rv = accept(sock, &addr, (socklen_t *) &addrlen);
if ((addrlen & 0xFFFFFFFF) == 0)
addrlen >>= 32;
...in order for your binary to run on all systems. Fun times.That's kind of one of the problems with OpenSSL: The paid work they do may help most of the OpenSSL developers pay their bills, but spending their time writing weird one-off features for enterprise clients is the opposite of conducive to doing important work to maintain the quality of the library.
OpenSSL has been dragging around EBSDIC support that the killed off. 90% of people under 50 will never even have heard of it, and 99.9% of people would agree that support should have been dropped ages ago, once explained.
DOS support is another Bob mentioned.
DOS support for a program that all about TCP/IP. Y, for anyone that had to live through it DOS with a bunch of drives and HIMEM crap would get ping, telnet and a couple other TCP/IP programs.
Possibly somebody even wrote http server for DOS after it was already dead for 10 years.
https://en.wikipedia.org/wiki/Arachne_%28web_browser%29
Not sure if it's for that, though. Maybe it's for a DOS port of Lynx, which actually supports SSL.
OpenBSD by comparison gets things done with 10% of the OpenSSL budget?
The current maintainers of OpenSSL have been doing a shitty job. It's not that heartbleed itself was the problem.
OpenSSL scares people away, the code is such a mess. I've looked at it for 5 minutes years ago. You hope to compile it, let alone understand it.
Finally people had to take a look at it, and what they found was a scary unmaintained mess vs other open source projects.
Specifically considering the importance of OpenSSL the maintainers seem to do a terrible job.
As people have mentioned. OpenSSL is basically a "FIPS" consultancy.
http://en.wikipedia.org/wiki/Federal_Information_Processing_...
FIPS is real world useless to 99% of the population that doesn;t live in the US and do business with the US govt.
They are worried more about maintaining the FIPS then patching or improving the code base for something that has become so universal.
That's fine for them, but a couple million a year in consulting fee's is messing with a much larger audience.
OpenSSL will be able to keep its outdated code base and FIPS, while the rest of the world moves on.
Key takeaway from Bob, is they need to raise money to pay some super knowledgable developers to get some of the more lengthly parts done.
You might think DOS is dead (I did), but it still exists (thrives?) at certain places.
Good work though all round.
If not, this project would certainly benefit both *BSD and the Linux community. Although the LibreSSL team is currently concentrated on just targetting OpenBSD, the cleaner code base should make porting easy enough that the work in exchange for a cleaner, more secure and easier to debug code base will be worth it.
It would serve the Linux foundation to keep with a more secure implementation than OpenSSL.
The Linux Foundation is supporting the OpenSSL project with funding.
If they do, then this could definitely be an issue.
If they don't then I can see there benefit for the Linux Foundation in funding both. LibreSSL has the benefits I previously mentioned, and OpenSSL benefits from having all the features that are being cut out by LibreSSL (FIPS probably being the biggest one).
But I can see where the possible conflict could occur. Thanks for clearing things up.
Why? Are we kids?
Perhaps you have to wait a couple days for it be processed and uploaded.
Good talk Bob.
tx