HN2new | past | comments | ask | show | jobs | submitlogin

There is OpenSSL, nss, and GnuTLS. That's 3. Two of those have had major breaches this year.

How many more libraries do you think will provide adequate security?



If each of those where equally used, and same with different key handling system, security by diversity would help. For example, the gnutls vulnerability only effected x509 resolving of the certificate chain, so those handful of people who use the pgp model were not effected.

Sadly, even if those options are available, gnutls is not common on the web, and https with pgp is even less common. Worse, some propose that we should use such options less in favor of one and only one library in the name of security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: