Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think a license was a problem in this case. Do we know of any companies that internally improved OpenSSL and did not open source the changes? For a crypto infrastructure code like this, it would be a very strange strategy. It doesn't seem like any competitive advantage to be the only company that runs OpenSSL with proprietary fixes.


> Do we know of any companies that internally improved OpenSSL and did not open source the changes?"

Akamai did (covered on HN when the Heartbeat vulnerability was at the top of the news).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: