Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That seems to be a non-argument to me: you shouldn't implement TLS yourself anyways. And given that spiped is a younger project than say OpenSSL will mean less eyeballs applied to finding bugs. And the cryptographic primitives spiped uses are available in TLS as well.

TLS and spiped are simply two different tools, for two different purposes. Control only one of the endpoints? You'll have to use TLS. Want to secure communication between infrastructure you control? Check out spiped.



Even if you're just implementing TLS using an existing TLS library it's easy to get that wrong. TLS is a pain.


Ironic - the timing of your comment, " And given that spiped is a younger project than say OpenSSL will mean less eyeballs applied to finding bugs. " given todays announcement regarding the absolutely epic OpenSSL bug.

What are your thoughts now on not exposing yourself to all of the complexity of OpenSLL?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: