Comment by captain_coffee

13 days ago

I had no idea that OpenSSL is in such a bad state.

I was surprised it is still in such bad state even after "rewrite" for 3.0.

  • I am not surprised at all, because instead of throwing their support behind the LibreSSL folks who audited the OpenSSL codebase after Heartbleed and found deep design and implementation issues, Linux Foundation and member orgs including most of Silicon Valley decided that OpenSSL just needed more funding.

    Felt like good money after bad on day 1.