idk it seems bad to me that openssl implements both fundamental cryptographic algorithms, *and* a bunch of protocol/policy stuff. seems like they should be separate things. idk
-
Show this thread
-
today I learned it delegates part of the verification process to the caller, after doing its own built-in checks, but this interface is done in a way that means the caller can simply override and ignore the built-in checks
1 reply 0 retweets 4 likesShow this thread -
like I was being flippant when I said I'd simply make it easy to implement correctly but this is the sort of interface that something like this should not have
2 replies 0 retweets 4 likesShow this thread -
as in, you pass a function pointer to openssl, and it calls it with an int saying if its own checks passed or not. your function can simply, ignore this int, if it wants to
1 reply 0 retweets 2 likesShow this thread -
Miss Dada 🏳️⚧️ Retweeted Miss Dada 🏳️⚧️
Evergreen tweethttps://twitter.com/sgrif/status/1280664494088183808?s=20 …
Miss Dada 🏳️⚧️ added,
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.