This is a must-read.
https://cryptography.io/en/latest/statements/state-of-openssl/
This is a must-read.
https://cryptography.io/en/latest/statements/state-of-openssl/
@soatok Holy crap on a cracker, I knew things at OpenSSL were bad, but *this* bad? 🤔
@soatok I've neither been a fan of the python cryptography library nor OpenSSL, but this was an extremely refreshing read. I'm happy someone else has caught up on the substantial problems with OpenSSL. Thank you for sharing!
@soatok I've read it multiple times now and each time baffled at the OSSL_PARAM thing. The given reason (having the same ABI for different algorithms) is not a great reason for adding this much complexity, and any other reason I can think of (ABI compatibility between versions) can be done in less complex and error prone ways. It feels like the kind of solution someone comes up with who wants to show just how clever they are.
@soatok Good read.
"We do not fully understand the motivations that led to the public APIs and internal complexity we’ve described here. We’ve done our best to reverse engineer them by asking “what would motivate someone to do this” and often we’ve found ourselves coming up short."
The purpose of the system is what it does. Cui bono?
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.