TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative

181 pointsby ryanwealalmost 11 years ago
"Network Time Protocol, OpenSSH and OpenSSL first projects to receive support; Open Crypto Audit Project to conduct security audit of OpenSSL"

11 comments

kyledrakealmost 11 years ago
Just give the money to the OpenBSD team. We saw with OpenSSH that they have a proven track record taking crappy security software and fixing it. Why does everyone have this aversion to giving the OpenBSD team the funding they deserve?<p>And &quot;Theo&#x27;s a dick&quot; doesn&#x27;t qualify as a valid reason to not fund real security development. For the work those guys have done improving the security infrastructure of every operating system (they lead, others followed), the entire team deserves to be well-off dicks. It&#x27;s to me the ultimate highlight of OSS&#x27;s funding problem. People make millions&#x2F;billions of dollars off of this software, and nobody ever contributes any of that back to the shoulders they stood on to make that happen.
评论 #7818461 未加载
评论 #7818082 未加载
评论 #7818280 未加载
评论 #7818111 未加载
评论 #7818149 未加载
评论 #7818201 未加载
评论 #7818667 未加载
评论 #7819424 未加载
评论 #7818380 未加载
评论 #7818192 未加载
allendoerferalmost 11 years ago
When the missing funding of OpenSSL was discussed, it came up several times, that OpenSSH, while doing great, is quite underfunded, too. I am glad to see them getting some money.<p>What i can&#x27;t really comment on myself, but am reading from the OpenBSD guys is, that the OpenSSL team does quite well with FIPS consulting and has no increased interest in improving the library.[0]<p>Even if those claims are not true, it would be nice to see several other TLS libraries (GnuTLS, LibreSSL etc.) getting sponsored to get some healthy competition. Maybe, they could even directly compete for shares of the funding by the Linux Foundation in some way.<p>[0]: <a href="http://www.openbsd.org/papers/bsdcan14-libressl/mgp00008.html" rel="nofollow">http:&#x2F;&#x2F;www.openbsd.org&#x2F;papers&#x2F;bsdcan14-libressl&#x2F;mgp00008.htm...</a>
评论 #7818355 未加载
评论 #7818041 未加载
mrweaselalmost 11 years ago
I&#x27;m actually looking forward to seeing how the OpenSSL problem will deal with their own legacy code, compared to how the OpenBSD developers have handled it.<p>It seems that own of the only ways of dealing with the OpenSSL code is to strip out the code for a large number of, should we say &quot;less used platforms&quot;. Is the OpenSSL developers willing to drop support for 16 bit Windows or OpenVMS?
评论 #7818690 未加载
评论 #7818285 未加载
adventureloopalmost 11 years ago
I skimmed, but cannot seem to see which project is being supported when they say NTP.<p>When you support the OpenBSD Foundation you support:<p>- OpenBSD - OpenSSH - OpenBGPD - OpenNTPD - OpenSMTPD - LibreSSL<p>The wording makes me think that the initiative will be supporting something other than OpenNTPD
评论 #7818638 未加载
评论 #7818688 未加载
评论 #7818714 未加载
orikalmost 11 years ago
If OpenSSL software foundation is a for profit operation, why are tech companies funding it(1) instead of LibreSSL?<p>1: <a href="http://arstechnica.com/information-technology/2014/04/tech-g.." rel="nofollow">http:&#x2F;&#x2F;arstechnica.com&#x2F;information-technology&#x2F;2014&#x2F;04&#x2F;tech-g...</a>.
评论 #7820252 未加载
评论 #7819851 未加载
dfcalmost 11 years ago
This is great news. NTP is one of the least appreciated OSS projects. Harlan and the rest of the ntp dev team are very helpful and deserve a lot of respect for keeping the clocks on time. I can only hope that increased ntp funding&#x2F;awareness&#x2F;development means that <i>BitKeeper</i> (not a typo) is finally replaced by git&#x2F;mercurial.
dmixalmost 11 years ago
How do code security audits actually work? Are various well-experienced people just combing through the code and trying to break it? Or is there a more formal process?
评论 #7818670 未加载
mjibsonalmost 11 years ago
It is possible the OpenSSH funding, since it is done through the OpenBSD Foundation, could, at the Foundation&#x27;s discretion, go toward LibreSSL, since it&#x27;s the same group.
评论 #7818262 未加载
joealbaalmost 11 years ago
What about BIND for DNS?
评论 #7818909 未加载
评论 #7818459 未加载
davidgerardalmost 11 years ago
Just LibreSSL. Let OpenSSL die its deserved death. Portable LibreSSL will do wonders.
tuxalmost 11 years ago
Having &quot;Huawei&quot; as one of the backers does not create confidance. Recent news shows that they had there hardware backdoored.<p><a href="https://duckduckgo.com/?kh=1&amp;q=Huawei&amp;sites=www.schneier.com%2Fblog" rel="nofollow">https:&#x2F;&#x2F;duckduckgo.com&#x2F;?kh=1&amp;q=Huawei&amp;sites=www.schneier.com...</a>
评论 #7821514 未加载