The question is: Who are the ones more likely to drive us to a better solution than the status quo?
As other commenters have stated, the OpenSSL Project is not the only way to implement SSL. There are other open projects, though do not call themselves "OpenSSL".
I would imagine there is tremendous power over some peoples' minds when a project has the name "Open" and at least a small bit of history. They will defend it fervently without caring much about the code itself.
The OpenSSL Project's code is awful if for no other reason than it is far too complex to use, let alone when security is a requirement.
You can shift the focus to the programming language used or to "lack of funding" or whatever else you can conjure up, but the fact remains: OpenSSL's code is a mess.
Other SSL projects have implemented SSL in much simpler and smaller code. It makes one wonder how OpenSSL maintains its position as the default and we continue to accept the problems it creates.
Maybe because of attitudes like yours: "How dare anyone offer any critique on OpenSSL."
If he had been convicted would he have also been required to pay for the "damage" done to AT&T's computer?
Isn't there something in the CFAA about having to allege causing damage, measurable in financial terms?
Maybe they did not use that provision?
Surely there must be logical reasons I am overlooking, but I find it peculiar that today technology companies can so easily get federal authorities to bring proceedings on their behalf.
Whether it's the DMCA or the CFAA, these "violations" seem like civil matters to me.
Do they harm the public, or do they just (potentially) harm a business?
I thought this opinion was very clearly written and although it only addresses venue, it does have some precedential value for the future of "CFAA law".
For one, if you plan to rely on improper venue as a defense, stay away from the Second Circuit!
"The shell can be a disproportionately powerful programming environment."
Then how do you explain why other languages are so much more popular?
Not only that, but how do you explain why the market for software developers compensates those with experience in these other languages more than those few developers who are highly competent in writing portable shell scripts?
Relative to what I have seen written by other developers, I consider myself a competent shell user.
Practice helps. On average I write or revise more than one new script per day.
And I've been doing this for years. The number of shell scripts I have written numbers in the thousands.
Is there a place where shell scripting is valued on par with the trendy languages like Python, Ruby, etc.?