Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Just woke up to 5 vulnerability alerts (4 high severity) of the openSSL Rust crate.

Just woke up to 5 vulnerability alerts (4 high severity) of the openSSL Rust crate.

Scheduled Pinned Locked Moved Uncategorized
rustopensslrustls
2 Posts 1 Posters 5 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • thomas_zahner@mastodon.socialT This user is from outside of this forum
    thomas_zahner@mastodon.socialT This user is from outside of this forum
    thomas_zahner@mastodon.social
    wrote last edited by
    #1

    Just woke up to 5 vulnerability alerts (4 high severity) of the openSSL Rust crate. Now I'm even more thankful we've made the switch to rustls in lychee. I've only seen advantages so far. The transition was totally smooth, and now we have faster, more stable and apparently more secure TLS.

    Thank you @djc, @ctz et al. for this amazing piece of software!

    #rust #openssl #rustls

    Link Preview Image
    thomas_zahner@mastodon.socialT 1 Reply Last reply
    1
    0
    • thomas_zahner@mastodon.socialT thomas_zahner@mastodon.social

      Just woke up to 5 vulnerability alerts (4 high severity) of the openSSL Rust crate. Now I'm even more thankful we've made the switch to rustls in lychee. I've only seen advantages so far. The transition was totally smooth, and now we have faster, more stable and apparently more secure TLS.

      Thank you @djc, @ctz et al. for this amazing piece of software!

      #rust #openssl #rustls

      Link Preview Image
      thomas_zahner@mastodon.socialT This user is from outside of this forum
      thomas_zahner@mastodon.socialT This user is from outside of this forum
      thomas_zahner@mastodon.social
      wrote last edited by
      #2

      Here we switched before the last release in February: https://github.com/lycheeverse/lychee/pull/1928

      It resolved multiple inconsistencies as lychee behaved differently on each target platform as the target platform's openSSL implementation was used. Switching to rustls has resolved multiple long-standing issues and we haven't received any related bug reports since.

      1 Reply Last reply
      0
      • R relay@relay.infosec.exchange shared this topic
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups