Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This seems like what a sensible person would do.

On the other hand, placing evergreen confidence in "TLS", believing that it is "good enough" or concluding "it's all we've got" are lines of thinking that not make sense to me. The vulnerabilities just keep coming, one after another.

High speed crypto not part of TLS that, as another commenter put it, is "considered safe". Does it exist?

Useful software that is written from the start with such care that it does not need to be continously patched ad inifitum. Nonexistant? (No need to answer. I know the truth.)

Getting something added to TLS seems difficult enough, but getting something removed seems impossible. Like all bad software, TLS has numerous "features" I do not need and will never use. OpenSSL is like a museum of cryptography, preserving the obsolete for posterity.

Long live TLS. May it forever waste my time and energy.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: