Hello, I was discussing with steils since he asked my opinion about this subject.
I did ask on #libressl channel on Freenode about recent security vulnerability between OpenSSL and LibreSSL. They told me[1] that in the 3 security vulnerabilities discovered in 2020 in LibreSSL, only 1 have affected LibreSSL. Maybe that it is still more secure than OpenSSL. steils suggested me to maintain LibreSSL overlay. I would be happy to help on this. I already did some contributions on this overlay. Sincerely, Quentin RETORNAZ. [1]2021-01-01 02:08 <busterbcook> Late answer I know, but 3.3.1 released with the fix for CVE-2020-1971 (backported to 3.2.x and 3.1.x as well). 2020-01-01 02:15 <busterbcook> Case_Of AFAIK, that's the only one in 2020 that was shared between the libraries, but it was fairly minimal in real-world impact IIRC. The number of security bug reports for either has been pretty minimal for both in the last year. https://www.openssl.org/news/secadv/20200421.txt and https://www.openssl.org/news/secadv/20200909.txt didn't affect LibreSSL I believe.
signature.asc
Description: This is a digitally signed message part
