Hello,

I was discussing with steils since he asked my opinion about this
subject.

I did ask on #libressl channel on Freenode about recent security
vulnerability between OpenSSL and LibreSSL. They told me[1] that in the
3 security vulnerabilities discovered in 2020 in LibreSSL, only 1 have
affected LibreSSL. Maybe that it is still more secure than OpenSSL.

steils suggested me to maintain LibreSSL overlay. I would be happy to
help on this. I  already did some contributions on this overlay.

Sincerely,

Quentin RETORNAZ.

[1]2021-01-01 02:08 <busterbcook> Late answer I know, but 3.3.1
released with the fix for CVE-2020-1971 (backported to 3.2.x and 3.1.x
as well).
2020-01-01 02:15 <busterbcook> Case_Of AFAIK, that's the only one in
2020 that was shared between the libraries, but it was fairly minimal
in real-world impact IIRC. The number of security bug reports for
either has been pretty minimal for both in the last year. 
https://www.openssl.org/news/secadv/20200421.txt and 
https://www.openssl.org/news/secadv/20200909.txt didn't affect LibreSSL
I believe.

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to