Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> you really do need to go spelunking into the source to figure out how things work

What are the chances that this is how a lot of the vulnerabilities were discovered (including heartbleed)? The more people forced to look through the source, the better? (That is, unless they keep that discovery to themselves.)

Edit: maybe they've improved it since the article was written; around 2 years ago I wrote an SSL MITM'ing HTTP(S) proxy, complete with CA certificate generation + signing, in a little over 24h of work.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: