Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> That's why you don't change upstream code without reason.

They did have a reason; they were running analysis on the code, and one of their tools specifically called openssl out for using uninitialized memory, which is absolutely a red flag. But not to worry; rather than blindly patching it to fix the bug, they went out of their way to go ask upstream about it, appeared to get a favorable response to their patch, and then went ahead.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: