LibreSSL is the fucking bane of my existence at work. So many issues caused by the keys it spits out vs others.
the Apple curl security incident 12604 | daniel.haxx.se
Submitted 8 months ago by mesamunefire@lemmy.world to technology@lemmy.world
https://daniel.haxx.se/blog/2024/03/08/the-apple-curl-security-incident-12604/
Comments
macgyver@federation.red 8 months ago
Illecors@lemmy.cafe 8 months ago
Never had the chance to seriously look into libressl. Do you think it would work fine if most of the world was running it rather than openssl?
macgyver@federation.red 8 months ago
Probably so, but Apple is the only one I’ve encountered actually using it. The whole point is it’s supposed to be backwards compatible and it’s just not
BrownianMotion@lemmy.world 8 months ago
Anyone still using LibreSSL and not OpenSSL, has only themselves to blame. Or their company or whoever is forcing it on them.
rottingleaf@lemmy.zip 8 months ago
Seems from the article that LibreSSL is fine, it’s about Apple patches to it.
0x0@programming.dev 8 months ago
OpenBSD forked OpenSSL due to HeartBleed. OpenBSD developers are generally regarded as quite on top of their game when it comes to security, so why the “still using LibreSSL” FUD?
0x0@programming.dev 8 months ago
You can follow curl’s lead developer on mastodon: @bagder@mastodon.social, seems like a very reasonable guy.
oDDmON@lemmy.world 8 months ago
TL;DR? > The problem is strictly speaking not even in curl code. It comes with the version of LibreSSL that Apple ships and builds curl to use on their platforms.
But because they’re Apple (right next to the Pope, for infallibility), they know best; same old story, rinse’n’repeat.
Really liked their stuff back in the day. Now? It’s another walled garden they scrabble to maintain.
sepi@piefed.social 8 months ago
You know, Steve Jobs used to be a huge jerk. Then he passed away.
Plague_Doctor@lemmy.world 8 months ago
Oh it’s so much worse than that. Part One Part Two
tsonfeir@lemm.ee 8 months ago
What day was it that you liked their stuff, and what made you stop?
smegforbrains@lemmy.ml 8 months ago
Apple adheres to the principle of form over function, instead of the old but still valid form follows function design principle. But TBH I never liked their stuff or their over the top big cheese attitude.