Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> But libressl breaks ABI compatibility

Who cares? Compatibility with insecurity is not a goal.



Are you volunteering to patch every program which uses OpenSSL? If not, you have the answer: it’s been widespread for decades and so many things use it that compatibility is a big concern. Think about a distribution like Debian with thousands of packages, some of which update frequently and others which haven’t been updated in years. If it’s compatible, you can ship one shared library update but if it’s not you’re either not upgrading or maintaining a ton of patches.


Debian is a bad example; they compile everything from scratch, they don't need ABI compatibility.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: