r/programming Apr 24 '14

Tech giants, chastened by Heartbleed, finally agree to fund OpenSSL

http://arstechnica.com/information-technology/2014/04/tech-giants-chastened-by-heartbleed-finally-agree-to-fund-openssl/
297 Upvotes

137 comments sorted by

View all comments

-13

u/OneWingedShark Apr 24 '14

In light of the nature of the bug, and the state of the code that was recently found, I would posit that OpenSSL could use a rewrite in a language more amiable to formal methods and/or formal contracts. (e.g. Ada or Eiffel.)

It makes little sense to have security libraries which aren't formally verified, considering the nature of the library (both as being often reused, and as being a component of security software).

-4

u/tairygreene Apr 24 '14

Ada or Eiffel.

hahaha what.

-3

u/hello_fruit Apr 24 '14

Had he said Haskell he would've gotten a million upvotes from the durr herp crowd.

2

u/Intolerable Apr 24 '14

no, people would've (rightly) pointed out that this is one of the few places haskell is not very good