1/27/2026 at 8:14:56 PM
I'd encourage folks to read the recently-published statement [1] about the state of OpenSSL from Python's cryptography project.by ofek
1/28/2026 at 12:20:10 AM
We're recording a Security Cryptography & Whatever with them in an hour or so, if anyone's got questions they want us asking Alex and Paul.True facts: Paul co-created Frinkiac.
by tptacek
1/28/2026 at 4:43:55 AM
Instead of everybody switching to LibreSSL, we had the Linux Foundation reward OpenSSL's incompetence with funding.We are still suffering from that mistake, and LibreSSL is well-maintained and easier to migrate to than it ever was.
What the hell are we waiting for?
Is nobody at Debian, Fedora or Ubuntu able to step forward and set the direction?
by snvzz
1/28/2026 at 5:58:15 PM
How about standardizing on an API, then switching backends can be up to the administrator of the machine.by seg_lol
1/29/2026 at 12:45:52 AM
LibreSSL has put serious effort into making itself interchangeable with openssl.OpenSSL as the incumbent has no incentive to do the same.
by snvzz