TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

All SSL distros are now suspect

1 点作者 proovit大约 11 年前
In crypto, the &quot;crypto&quot; is the hard part. But now in the space of two weeks we see that folks maintaining the crypto in C can&#x27;t handle return values.<p>As an industry we have accepted that these libraries are the standard plumbing of security for many years.<p>And they are obviously <i>based</i> on standards.<p>Some <i>other</i> standards are continuous and automated testing to ensure broken code does not make it to production.<p>The last two weeks of Apple and now GNU not being able to competently handle return values in C shows that:<p>They don&#x27;t have automated testing in place for critical security code. (Anything?)<p>They don&#x27;t have maintainers in place who understand their own c code.<p>Consumers of SSL code believe in acronym security which does not exist.<p>As an industry since we cannot control the shoddy practices of distributors of security code we must minimally require proof of open transparent automated tests which can be verified by a third party before using any vendors encryption.<p>Goodnight. And may the force &quot;goto&quot; you.

暂无评论

暂无评论