@maybeanerd @eruwero the only reason #tinycurl can do #GPLv3 is because #WolfSSL dual-licensed this one commercially and AFAICT it doesn't use #curl's codebase but is a complete reimplementation (tho @bagder may correct me on that one!)…
@bagder @synlogic4242 you should sell that as a shirt - but I guess you'd rather focus on the success if #WolfSSL & #curl instead...

@cR0w too many.

http://github.com/kkarhan/windows-ca-backdoor-fix

So far testing by @ct_Magazin / @heiseonline (and myseof later on) revealed only few #Apps not vulnerable to this specifics #Govware:

Anything else that uses the CryptoAPI is, espechally *all #Chromium-Forks (aka. All Browsers except Firefox, Tor Browser, #dillo, #LynxBrowser…)

GitHub - kkarhan/windows-ca-backdoor-fix: Fixes a critical backdoor in Windows' CryptoAPI, which allows to unconsenting Update of CA Certificates in the background. See https://www.heise.de/ct/ausgabe/2013-17-Zweifelhafte-Updates-gefaehrden-SSL-Verschluesselung-2317589.html

Fixes a critical backdoor in Windows' CryptoAPI, which allows to unconsenting Update of CA Certificates in the background. See https://www.heise.de/ct/ausgabe/2013-17-Zweifelhafte-Updates-gefae...

GitHub

Long, but great read from #HAProxy on the state of #TLS libraries. Includes some scathing remarks about the #OpenSSL project.

“The development team has degraded their project’s quality, failed to address ongoing issues, and consistently dismissed widespread community requests for even minor improvements.”

“This unfortunate situation considerably hurts QUIC protocol adoption. It even makes it difficult to develop or build test tools to monitor a QUIC server.”

“When some of the project members considered a 32% performance regression ‘pretty near’ the original performance, it signaled to our development team that any meaningful improvement was unlikely.”

“In blunt terms: running OpenSSL 3.0.2 as shipped with Ubuntu 22.04 results in 1/100 of #WolfSSL’s performance on identical hardware! To put this into perspective, you would have to deploy 100 times the number of machines to handle the same traffic, solely because of the underlying SSL library.”

https://infosec.exchange/@0xabad1dea/114466046966536049

abadidea (@[email protected])

After heartbleed in 2014, there were a lot of calls to abandon OpenSSL and support alternative libraries because it had written itself into a corner full of holes. I didn’t anticipate that 11 years later, there’d be a call to abandon OpenSSL because it’s written itself into a corner of running at 1% the performance of those very same alternative libraries https://www.haproxy.com/blog/state-of-ssl-stacks

Infosec Exchange

“AWS-LC looks like a very active project with a strong community. […] Even the recently reported performance issue was quickly fixed and released with the next version. […] This is definitely a library that anyone interested in the topic should monitor.”

#OpenSSL #BoringSSL #WolfSSL #AWSLC #HAProxy #OpenSource #FreeSoftware #FOSS #OSS #TLS #QUIC
https://www.haproxy.com/blog/state-of-ssl-stacks

The State of SSL Stacks

The SSL landscape has shifted dramatically. In this paper, we examine OpenSSL 3.x, BoringSSL, LibreSSL, WolfSSL, and AWS-LC with HAProxy.

HAProxy Technologies

I'll be speaking at CYSAT Conference in Paris next month!

Let me know if you are going! Stop by and say hi. I'll be at the #wolfSSL booth, too.

Frontgrade Gaisler and wolfSSL Collaborate to Enhance Cybersecurity in Space Applications

https://fed.brid.gy/r/https://spacenews.com/frontgrade-gaisler-and-wolfssl-collaborate-to-enhance-cybersecurity-in-space-applications/

Frontgrade Gaisler and wolfSSL Collaborate to Enhance Cybersecurity in Space Applications

Gothenburg, Sweden (April 3, 2025) – Frontgrade Gaisler, a leading provider of radiation-hardened microprocessors for space missions, and wolfSSL, a renowned provider of embedded security solutions…

SpaceNews
@icing that's why #curl uses #WolfSSL!
Speed-Testing #Privoxy 4.0.0 with #wolfSSL and a self-written patch using #ecc Elliptic Curve Cryptography - the whole thing packaged and running on #sailfishos.
Results (browser snappiness) are really impressive. Subjectively at least.

At this year's #FOSDEM my team at #wolfSSL got no booth space so my large volume #curl sticker distribution (LVCSD) has to be done using other means.

The LVCSD will most likely happen in the cafeteria area, but feel free to ping me if you can't get your fix as planned.

I will bring thousands of curl stickers and hundreds of coasters. There will be a few mugs and maybe some tshirts.

Buying myself friends, like a boss.