OpenSSL vs LibreSSL

Discussions criticize OpenSSL's poor code quality, security issues, and track record, while advocating for switching to LibreSSL or other alternatives like BoringSSL.

πŸ“‰ Falling 0.3x Security
3,912
Comments
19
Years Active
5
Top Authors
#3034
Topic ID

Activity Over Time

2008
11
2009
17
2010
40
2011
39
2012
74
2013
68
2014
964
2015
454
2016
350
2017
235
2018
152
2019
199
2020
246
2021
268
2022
300
2023
203
2024
118
2025
143
2026
31

Keywords

EVK IOS OSS OK openssl.org openssl.html openbsd.org SRP marc.info SEED openssl ssl code unit testing library security tls debian project testing

Sample Comments

colejohnson66 β€’ May 9, 2020 β€’ View on HN

Is there a reason people still use OpenSSL? Aren’t there better forks?

iio7 β€’ Oct 30, 2022 β€’ View on HN

Can we not just dump OpenSSL for once and move over to LibreSSL already!?

richardwhiuk β€’ Oct 19, 2015 β€’ View on HN

So much for LibreSSL being a better choice than OpenSSL.

nickpsecurity β€’ Jul 7, 2015 β€’ View on HN

Given the OpenSSL trackrecord [1], I recommend switching to LibreSSL [2] if possible. They tore through OpenSSL to pull out all the horrors they found and beat it into shape. OpenSSL's code was so unbelievably bad that there's certainly more problems lurking in there.[1] http://www.openbsd.org/papers/bsdcan14-libressl/mgp00001.htm...[2] <a h

baby β€’ Jun 21, 2017 β€’ View on HN

Does it make sense to stop recommending OpenSSL and start recommending LibreSSL now?

ksec β€’ Jan 5, 2016 β€’ View on HN

So to OpenSSL and not to LibreSSL?

jamiesonbecker β€’ Mar 18, 2015 β€’ View on HN

Just because OpenSSL is very hard to replace doesn't mean it's not very bad.

KennyBlanken β€’ Feb 7, 2023 β€’ View on HN

A reminder that LibreSSL exists and has a fraction of the problems OpenSSL does.https://www.libressl.org/

n0body β€’ Aug 7, 2014 β€’ View on HN

God damn it not again. Bring on boringssl/libressl. Although they'll be full of holes as well probably, and as things stand there's a lot of people looking at openssl at the moment. So maybe better the devil you know

chris_wot β€’ Mar 18, 2015 β€’ View on HN

OpenSSL is free to do that, but given the issues in their code it would probably backfire.