[Cryptography] Are dynamic libs compatible with security? was: Apple and OpenSSL

Lodewijk andré de la porte l at odewijk.nl
Fri Apr 25 05:52:04 EDT 2014


Imho dynamic linking SHOULD be okay, because the OS SHOULD be okay.

In practice you give control to the system administrator, which means you
will more often be insecure. You also get the regular slew of compatibility
issues that cause me to root for more rigor in linking targets. (Link to
LIBx.xx.xx instead of LIB, keep all versons if possible. Or link to APIs,
not libraries. That's far more honest anyway )
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.metzdowd.com/pipermail/cryptography/attachments/20140425/57d8047d/attachment.html>


More information about the cryptography mailing list