the Apple curl security incident 12604 | daniel.haxx.se

mesamune@lemmy.world to Technology@lemmy.world – 156 points –
daniel.haxx.se
14

You are viewing a single comment

LibreSSL is the fucking bane of my existence at work. So many issues caused by the keys it spits out vs others.

Never had the chance to seriously look into libressl. Do you think it would work fine if most of the world was running it rather than openssl?

Probably so, but Apple is the only one I’ve encountered actually using it. The whole point is it’s supposed to be backwards compatible and it’s just not

If you meant that they've dropped plenty of openssl functionality - well, the whole purpose of the fork was to refactor it into something less scary. And since it was done by OpenBSD people - they have their own approach, not always culturally compatible with enterprise usage.