GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Untitled attachment

Download link

Notices where this attachment appears

  1. Embed this notice
    feld (feld@friedcheese.us)'s status on Wednesday, 08-Jul-2026 02:19:03 JST feld feld
    > seriously, OpenSSL 3.0+ is really REALLY badly performing compared to 1.x

    do you have AI bots pounding your servers? Your server is falling over faster thjan it should because of OpenSSL. It could probably handle more traffic if you switched to WolfSSL or AWS-LC

    https://www.haproxy.com/blog/state-of-ssl-stacks


    > OpenSSL 3.1 tried to partially address the [locking abuse] problem by placing a few atomic operations instead of locks where it appeared possible. The problem remains that the architecture was probably designed to be way more dynamic than necessary, making it unfit for performance-critical workloads, and this was clearly visible in the performance reports of the issues above.

    > After everything imaginable was done, the performance of OpenSSL 3.x remains highly inferior to that of OpenSSL 1.1.1. The ratio is hard to predict, as it depends heavily on the workload, but losses from 10% to 99% were reported.


    STOP 👏 USING 👏 OPENSSL 👏 FOR 👏 TLS 👏
    In conversation about 3 months ago from friedcheese.us permalink
  2. Embed this notice
    LaF0rge (laf0rge@chaos.social)'s status on Thursday, 15-May-2025 02:46:41 JST LaF0rge LaF0rge

    In case you haven't seen it yet, check out the analysis of the devastating state of [mostly] modern #OpenSSL by members of haproxy at https://www.haproxy.com/blog/state-of-ssl-stacks - hard to imagine such massive performance regressions getting into mainline linux distributions unnoticed by the distributors. #linux #ssl

    In conversation Thursday, 15-May-2025 02:46:41 JST from chaos.social permalink
  3. Embed this notice
    abadidea (0xabad1dea@infosec.exchange)'s status on Wednesday, 07-May-2025 19:35:04 JST abadidea abadidea

    After heartbleed in 2014, there were a lot of calls to abandon OpenSSL and support alternative libraries because it had written itself into a corner full of holes. I didn’t anticipate that 11 years later, there’d be a call to abandon OpenSSL because it’s written itself into a corner of running at 1% the performance of those very same alternative libraries https://www.haproxy.com/blog/state-of-ssl-stacks

    In conversation Wednesday, 07-May-2025 19:35:04 JST from infosec.exchange permalink
  4. Embed this notice
    hanno (hanno@mastodon.social)'s status on Wednesday, 07-May-2025 19:02:44 JST hanno hanno

    This is a gruelling summary of all the things wrong with OpenSSL https://www.haproxy.com/blog/state-of-ssl-stacks I've mostly watched this whole thing from the sidelines, but was also affected noting that private key parsing suddenly became 70 times slower. I think they've now improved it to "only" be 10-20 times slower, and there does not seem any effort to work on it any more.

    In conversation Wednesday, 07-May-2025 19:02:44 JST from mastodon.social permalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.