New Bug Found in Widely Used OpenSSL Encryption
bits.blogs.nytimes.com
bits.blogs.nytimes.com
There's an interesting statement from our times.
in reality, openssl appears to be a $1mm+/year for-profit fips consulting business [1] that appears to not care much about security, letting serious security issues sit in their bug tracker for years on end
they went into the consulting biz to pay for the maintenance of openssl, but it hasn't panned out well until recently.
it's petty to take something done with great dedication and provided for free, with freedom, and demonize them. where are YOUR commits?
The principle and supposed ethic is to share and have some reciprocity - the reality is somewhat different. And we all suffer. Tragedy of the commons, I guess...
The 'it's open source, fix it yourself' concept breaks down significantly when you're dealing with other people's complex projects.
OpenSSL in particular is a convoluted and horrific codebase, due to a significant number of reasonably awful and insecure decisions, making submitting your own patches a nightmare. Consider yesterday's MITM flaw, where a patch to OpenSSL 1.0.1 provided the opportunity to exploit a bug that OpenSSL has had for over 15 years.
There's also the issue of many open-source projects won't accept patches from outside people, or for features they don't care to implement/support. In the case of OpenSSL, that might actually be a good policy, but it still makes the 'why don't you fix it yourself' argument a weak one.
[1] http://www.drdobbs.com/open-source/the-conflict-at-the-heart...
I think it's good news.
I'm certainly interested in hearing further analysis on this.
the number of people in the world who give a fuck if your stakeholders like free crypto software is exactly you plus the number of stakeholders. ;)
Of course, black hats could have already known about these exploits for years..