logoalt Hacker News

gcryesterday at 10:42 PM2 repliesview on HN

MaraDNS is much less popular than dnsmasq though.

I have several libraries that I've written. Not one single serious security bug in them has been found since 1991. Granted, nobody uses my libraries...

Not to diminish your team's achievement! :D But it's important to contextualize claims like this with information about what your userbase looks like


Replies

strenholmetoday at 1:36 AM

A lot of security and other audits have been performed against it though; MaraDNS, after all, is notable enough to have a Wikipedia page and hundreds of GitHUB stars.

For example, when the Ghost Domain Name DNS vulnerability was discussed, MaraDNS was audited and named (MaraDNS was immune to the security bug, for the record)

https://web.archive.org/web/20120304054959/https://www.isc.o...

andrewjfyesterday at 11:11 PM

I don't think that's relevant. You can still find security issues in software nobody uses.

The question is a matter of impact because of how used the software is.

show 1 reply