matrixssl security (Re: exit code trigger for STARTTLS)
Charlie Brady <[email protected]>
| Newsgroups | gmane.comp.misc.pape.general |
|---|---|
| Message-ID | <Pine.LNX.4.44.0501071831000.16068-100000@e-smith.charlieb.ott.istop.com> |
On Fri, 7 Jan 2005, Scott Gifford wrote: > Charlie Brady <[email protected]> writes: > > > On Fri, 7 Jan 2005, Scott Gifford wrote: > > [...] > > >> I don't really have any objections to OpenSSL ... > > > > Its record tells us that it hasn't been designed from ground up to be > > string/buffer safe. > > Do you think matrixssl has better security, or that it's just newer > and less popular, so fewer bugs have been found? The latter is certainly possible. I'm just guessing that we've all learnt enough that the former is also true. Gerrit, have you looked at the code much? --- Charlie