Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

steve2470

(37,457 posts)
Mon Apr 14, 2014, 07:25 PM Apr 2014

question about Open SSL versus a proprietary SSL solution

I know the advantage of open source. A bug becomes known, an army of coders moves in to patch it, life is good. However, I've read that only a few people actively work on Open SSL.

Other than Open SSL being a donation (or free), why choose it over a proprietary one ? Are the commercial SSL solutions really expensive and difficult to deploy ? I'm NOT being anti-open source here, just asking a sincere question. Thanks.

Steve

5 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
question about Open SSL versus a proprietary SSL solution (Original Post) steve2470 Apr 2014 OP
A comparison of different SSL implementaions... PoliticAverse Apr 2014 #1
I see they are all open source except for the MS and the SharkSSL one steve2470 Apr 2014 #2
I don't think Verisign have their own TLS implementation software. PoliticAverse Apr 2014 #3
And the Office 365 consultant sent jrandom421 Apr 2014 #4
Proprietary SSL Solution Advantages - SharkSSL JShima Apr 2014 #5

steve2470

(37,457 posts)
2. I see they are all open source except for the MS and the SharkSSL one
Mon Apr 14, 2014, 08:30 PM
Apr 2014

Last edited Sun Apr 20, 2014, 09:16 PM - Edit history (1)

Doesn't Verisign etc use their own TLS ?

eta: changed subject line

PoliticAverse

(26,366 posts)
3. I don't think Verisign have their own TLS implementation software.
Mon Apr 14, 2014, 08:50 PM
Apr 2014

Their SSL Certificate issuing business they sold to Symantec which now controls the verisign.com domain name.

Here's what they do now: https://www.verisigninc.com/

I think most places just use what comes with the Operating System and Webserver, VPN, Email
server they are using.


jrandom421

(1,005 posts)
4. And the Office 365 consultant sent
Sun Apr 20, 2014, 02:48 PM
Apr 2014

to all the Linux and open source fanboys he know, a simple email message: "Ha Ha!"

JShima

(1 post)
5. Proprietary SSL Solution Advantages - SharkSSL
Sun Apr 27, 2014, 04:21 PM
Apr 2014

Hi Steve,

There are a few advantages in a proprietary solution.

1) There is an inherient (additonal) buffer of security because the source code of the implementation is not readily downloadable. The Software provider serves as a check and balance to qualify that the recepient is an entity which can be identified. Given that the blueprints for the code are not easy available to parties that are not identifiable this limits exploit and vulnerablity experimentation.

2) The expense is minimal when you consider the impacts such as heartbleed can have to your product and customers. In most cases I would say that the price range for a commercial solution is around 5K-20K depending on the use senario and scope or utilization of support that your organization requires. Taking an Open Source implementation of OpenSSL, massaging it to your use parameters, and then maintaining it is not - (free), contrary to popular believe.

3) Many of the commercial solutions focus on size and performance. This may not be an issue for you depending on the device or implementation, but many of the connected devices for IOT/M2M simply do not have loads of memory available to waste. here there is also a cost savings which is hardware related.

4) Many of the arguments that I've seen for OpenSSL are a bit challenging to wade through. There's a good deal of theroitical input for the values of open source development, however you have identified the key point. Regardless, you have a single source small organization that is responsible to activly work on the project and maintain a distribution of OpenSSL. I'm not anti-open source either but for this particular security feature I personally feel that a commercial implementation is a smart solution.

5) Commercial software providers often license their products with indemnification and thus you have a for profit commercial entity taking responsiblity with repercussion that their continued ability to sustain revenue is at stake.

6) One of the areas that caused heartbleed to be so 'catostrophic' was the wide spread use and utilzation of OpenSSL. I would venture to say that most of the 2/3's world implementations didnt question adoption as you are doing now. Commercial solutions offer variety. Those companies that did not use OpenSSL were not effected.

JShima



Latest Discussions»Help & Search»Computer Help and Support»question about Open SSL v...