TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

OpenSSL code beyond repair, claims creator of LibreSSL fork

12 点作者 tjaerv大约 11 年前

2 条评论

tjaerv大约 11 年前
"'Our group removed half of the OpenSSL source tree in a week. It was discarded leftovers,' de Raadt told Ars in an e-mail. […] De Raadt told ZDNet that his team has removed 90,000 lines of C code. 'Even after all those changes, the codebase is still API compatible,' he said. 'Our entire ports tree (8,700 applications) continue to compile and work after all these changes.' The OpenBSD team started working on LibreSSL about a week ago, he told Ars."
guiambros大约 11 年前
<i>&quot;As for Heartbleed, &#x27;the mystery is not that a few overworked volunteers missed this bug&#x27;, Marquess wrote. &#x27;The mystery is why it hasn’t happened more often.&#x27;&quot;</i><p>Couldn&#x27;t agree more. I&#x27;m sure there&#x27;s lots of folks now combing through every line of OpenSSL, trying to find some new 0-day.<p>A hard fork seems a good option. Fresh start, with no cruft or a bunch of legacy code. Painful, but positive.