[OTC VOTE PROPOSAL] Don't merge PR#14759 (blinding=yes and similar properties)
tomas at openssl.org
Fri Apr 9 07:53:37 UTC 2021
On Fri, 2021-04-09 at 08:44 +0100, Matt Caswell wrote:
> On 08/04/2021 18:02, Nicola Tuveri wrote:
> > Proposed vote text
> > ==================
> > Do not merge PR#14759, prevent declaring properties similar to
> > `blinding=yes` or `consttime=yes` in our implementations and
> > discourage 3rd parties from adopting similar designs.
> I think this vote tries to cover too much ground in a single vote. I
> would prefer to see a simple vote of "Do not merge PR#14759"
> followed up by separate votes on what our own policies should be for
> provider implementations, and what we should or should not encourage
> parties to do.
I disagree partially. IMO we should primarily have a policy vote and
the closing or merging of PR#14759 should come out of it naturally.
No matter how far down the wrong road you've gone, turn back.
[You'll know whether the road is wrong if you carefully listen to your
More information about the openssl-project