• @[email protected]
    link
    fedilink
    English
    404 months ago

    TL;DR? > The problem is strictly speaking not even in curl code. It comes with the version of LibreSSL that Apple ships and builds curl to use on their platforms.

    But because they’re Apple (right next to the Pope, for infallibility), they know best; same old story, rinse’n’repeat.

    Really liked their stuff back in the day. Now? It’s another walled garden they scrabble to maintain.

    • sepi
      link
      fedilink
      104 months ago

      You know, Steve Jobs used to be a huge jerk. Then he passed away.

      • @[email protected]
        link
        fedilink
        English
        0
        edit-2
        4 months ago

        Apple adheres to the principle of form over function, instead of the old but still valid form follows function design principle. But TBH I never liked their stuff or their over the top big cheese attitude. So it’s not a disgruntled apple user writing this.

  • Mac
    link
    fedilink
    English
    144 months ago

    LibreSSL is the fucking bane of my existence at work. So many issues caused by the keys it spits out vs others.

    • Illecors
      link
      fedilink
      English
      34 months ago

      Never had the chance to seriously look into libressl. Do you think it would work fine if most of the world was running it rather than openssl?

      • Mac
        link
        fedilink
        English
        44 months ago

        Probably so, but Apple is the only one I’ve encountered actually using it. The whole point is it’s supposed to be backwards compatible and it’s just not

        • @[email protected]
          link
          fedilink
          English
          33 months ago

          If you meant that they’ve dropped plenty of openssl functionality - well, the whole purpose of the fork was to refactor it into something less scary. And since it was done by OpenBSD people - they have their own approach, not always culturally compatible with enterprise usage.

  • Brownian Motion
    link
    fedilink
    English
    94 months ago

    Anyone still using LibreSSL and not OpenSSL, has only themselves to blame. Or their company or whoever is forcing it on them.

    • @0x0
      link
      English
      23 months ago

      OpenBSD forked OpenSSL due to HeartBleed. OpenBSD developers are generally regarded as quite on top of their game when it comes to security, so why the “still using LibreSSL” FUD?

  • @0x0
    link
    English
    43 months ago

    You can follow curl’s lead developer on mastodon: @[email protected], seems like a very reasonable guy.