HN2new | past | comments | ask | show | jobs | submitlogin

I would love to know the price tags, ballpark informed guesstimates, for the following:

  * Audit of openssl
  * Audit of openssl + remediation work
  * Brand new implementation of ssl library  (100% feature parity not required)


> Brand new implementation of ssl library

Which will take some years to reach the security level of the current OpenSSL implementation (if at all).


Getting an idea of the effort/resources that have gone into openssl is a large part of why I asked the question.


What is all this rewrite talk about? Just use NSS. Done.


Not done. Would it surprise you to learn that "all this rewrite talk"--which was merely one question--was simple curiosity? I did not realize that asking a question would be such a problem for you. I have seen different suggestions of crowdfunding an audit/rewrite and I have have no concept of the price tag for such complex projects.


lern_too_spel has a point. Why write an entirely new SSL library when you can switch to an existing one that may already be mostly what you want?

https://xkcd.com/927/

Whether or not NSS is the one you prefer, that's up to you.

http://en.wikipedia.org/wiki/Comparison_of_TLS_implementatio...


What is so difficult to understand about someone being curious about the price tag for large crypto audits/development projects? I am sorry I do not have an xkcd comic to link to, hopefully I can explain this to you without pretty pictures: I am not asking about the price tag because of any specific software development project. I am asking because I am merely curious what the price tag would be. I have seen various discussions mentioning audits and rewrites as if everyone knew what the cost would be. I do not know what the price tag would be, and given the lack of genuine responses it seems a lot of people do not have any idea what the price tag would be.


Ok, I understand why you proposed this. But what's hard to understand is why you are taking a discussion of rational alternatives to your proposal with such... angst? negativity? Not sure what you're feeling.

Consider the converse situation. You are proposing a rational alternative to continuing with OpenSSL as it is. That's a reasonable contribution to a discussion and it is not taken as an attack against OpenSSL.

This is just a philosopher's discussion on a place called Hacker News in the middle of a work day. :)


By "all this rewrite talk," I meant the article, your comment, and several other comments in this thread together. What about my comment indicated that your question was a problem for me?

"Done," answered your question. $0.


How about this: I would love to know the price tags, ballpark informed guesstimates, for the following:

  * Audit of nss
  * Audit of nss + remediation work
For reference I think the truecrypt audit fund was $48k and the LAFS audit of spideroak came in at $10k.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: