Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Presumably the "do one thing and one thing well" principle (assuming hitch actually does it well). Your attack surface is reduced by orders of magnitude if you're worried about future OpenSSL vulnerabilities.


Wonder why LibreSSL wasn't used... :/


The reason is pretty simple: LibreSSL isn't available/packaged on the distributions we care about, and we don't have the will, money or knowledge to do it ourselves. (with my VS hat on)

We are positive to merging any code changes necessary to get it running with libressl though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: