How I discovered CCS Injection Vulnerability (CVE-2014-0224)
ccsinjection.lepidum.co.jp
ccsinjection.lepidum.co.jp
(PS. Reading the above tome ~1999, I actually discovered numerous specification flaws in the RFCs ... eg. for ARP and ICMP, that could be used for remote OS detection.)
A C implementation seems inevitable, but an easy-to-link Rust implementation would be very nice to have.
From what I read the Coq specification itself wasn't complete or used to discover the vulnerability.
Would be great if the author shed some light here.
For fun, I just duckduckwent 'make a game of it' and got some amusing responses in the context of this suggestion.
Kids can make a game out of almost anything! See more about gross motor activities, outdoor play and pool noodles.
Whatever you'd like to improve about your life, try making it into a game. Challenge yourself. Make up your own rules. Then play it to win.
When the family gets so big that you no longer can buy holiday gifts for everyone, you have to find an alternative. For many, that turns the gift exchange into a rousing game. "We used to buy for everyone and I enjoyed that, but in the last couple of years, we had to face the fact ...
I decided to put together my own Iron Rations and make a game of it. You are welcome to play. I hope you have some helpful ideas to add to the stash. The rules are: Everything must be shelf safe with an expiration date or best by date of at least two years.
Principal Skinner: Oh, licking envelopes can be fun! All you have to do is make a game of it. Bart: What kind of game? Principal Skinner: Well, for example, you could see how many you could lick in an hour, then try to break that record.
Most old and large codebases will have a mix of coding styles, etc... even at big companies (take a gander at the recently posted Windows 2000 source code for example, or the leaked Half Life 2 codebase, etc).
Does it make testing more difficult with preferred tool X? Maybe... but perhaps tool X isn't the best fit for the codebase? Or perhaps minor changes could be made to make it work well.
In any event... part of being a developer is being able to read and understand a variety of coding styles... since, coding styles have zero effect on the code's purpose/execution.
Not trying to detract... but we should remember the people who complained about the coding styles and difficultly in reading/understanding the codebase were new to the codebase, and the codebase was not in their expected format... which is normal when you sit down to any new codebase. Also... this is a crypto codebase... so there will be an element that is always difficult for an outsider to read and understand.
If you actually look into these "ridiculous engineering decisions" you will find very good reasons why they did things the way they did.
With that said, of course it may be able to be done better. All code can be done better. Remember the OpenSSL team was severely underfunded, and severely understaffed. So it's not fair to label them as "incompetent" one bit.
It's very easy to be an armchair quarterback.