TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

IBM, Microsoft, Facebook, Google, others pledge $3.6 million to fund OpenSSL

107 点作者 0cool大约 11 年前

9 条评论

computer大约 11 年前
&gt; &quot;IBM, Microsoft, Facebook, Google, others pledge $3.6 million to fund OpenSSL (arstechnica.com)&quot;<p>The title of this submission is incorrect. The funding goes to the general fund, not specifically to OpenSSL.<p>Here&#x27;s the press release this article is based on:<p><a href="http://www.linuxfoundation.org/news-media/announcements/2014/04/amazon-web-services-cisco-dell-facebook-fujitsu-google-ibm-intel" rel="nofollow">http:&#x2F;&#x2F;www.linuxfoundation.org&#x2F;news-media&#x2F;announcements&#x2F;2014...</a><p>And here&#x27;s the actual initiative:<p><a href="http://www.linuxfoundation.org/programs/core-infrastructure-initiative" rel="nofollow">http:&#x2F;&#x2F;www.linuxfoundation.org&#x2F;programs&#x2F;core-infrastructure-...</a><p>Discussed here:<p><a href="https://news.ycombinator.com/item?id=7639835" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=7639835</a>
评论 #7641100 未加载
评论 #7641098 未加载
zdw大约 11 年前
If they funded OpenBSD&#x27;s project portfolio (including LibreSSL), they&#x27;d get a heck of a lot more out of it for their money.
评论 #7640009 未加载
评论 #7640179 未加载
romanovcode大约 11 年前
OpenSSL source code is a disaster. It&#x27;s spaghetti that doesn&#x27;t do what you think it does with horrible documentation. People submit patches from people they don&#x27;t even know and then you have it: An SSL library that is flawed but everyone is using it. An spying agency and hackers dream.<p>We don&#x27;t need OpenSSL, we need another library built from scratch with very clean code and documentation.<p>Everyone who has more interest on why OpenSSL is a catastrophe should watch operation ORCHESTRA[0].<p>[0] <a href="https://www.youtube.com/watch?v=fwcl17Q0bpk" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=fwcl17Q0bpk</a>
评论 #7640662 未加载
评论 #7640862 未加载
midas007大约 11 年前
This comes off as a few companies trying to throw money at a rotten crypto lib, when only leadership like Theo&#x27;s way (minimalism, dropping features) would have a prayer of rescuing it. So giving OpenSSL more money doesn&#x27;t make sense, it&#x27;s like rewarding failure because they&#x27;ve shown an inability to produce good code or maintain it well... More money won&#x27;t help that, likely the opposite. Instead, TLS WG needs to get their act together and reduce their addiction to feature creep, release a reference library and comprehensive test suite. Then OpenSSL might have a chance after picking up a compass and a map and get back to some semblance of being a decent crypto lib, but more money is unlikely to solve this issue.
mikecb大约 11 年前
This, along with Google and others devoting employees like Neel Mehta to it should go a long way.
Nanzikambe大约 11 年前
They&#x27;re throwing good money after bad pretty much. IMO they should fund LibreSSL + OpenBSD + OpenSSH, bound to get more bang for buck.
prohor大约 11 年前
WOW! Never thought there is just one person devoted to a library that we rely to bring security to us all. Community is great but still some more dedication is needed in parts which are essential for security. Glad to see that some took it seriously.
pyvpx大约 11 年前
how about they each chip in $10K each year for OpenSSH?
评论 #7640521 未加载
leccine大约 11 年前
Wow, with this money they could just rewrite that thing and get the source audited and tested.