OpenSSL will release a HIGH severity issue fix on 25th

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
  • rustls

    A modern TLS library in Rust

  • I am a maintainer for rustls (https://github.com/ctz/rustls).

    What would your team need to be able to migrate to a different TLS stack that so far has proven to be safer, and passed its first security audit with flying colors? (https://github.com/ctz/rustls/blob/main/audit/TLS-01-report....)

    (I am also currently available on part-time freelance basis, feel free to contact me if you need commercial support on your endeavour to structurally address your TLS security issues.)

  • void-packages

    The Void source packages collection

  • Somewhat ironically to this circumstance (assuming it doesn't affect LibreSSL), the Void team has just switched back away from LibreSSL which it shipped by default with for years.

    Discussion: https://github.com/void-linux/void-packages/issues/20935

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • libsodium

    A modern, portable, easy to use crypto library.

  • That's what I thought, too, but it looks like at least libsodium implements constant-time array comparison in C.

    https://github.com/jedisct1/libsodium/blob/ae4add868124a32d4...

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts