TL;DR? > The problem is strictly speaking not even in curl code. It comes with the version of LibreSSL that Apple ships and builds curl to use on their platforms.
But because they’re Apple (right next to the Pope, for infallibility), they know best; same old story, rinse’n’repeat.
Really liked their stuff back in the day. Now? It’s another walled garden they scrabble to maintain.
Apple adheres to the principle of form over function, instead of the old but still valid form follows function design principle.
But TBH I never liked their stuff or their over the top big cheese attitude. So it's not a disgruntled apple user writing this.
Probably so, but Apple is the only one I’ve encountered actually using it. The whole point is it’s supposed to be backwards compatible and it’s just not
OpenBSD forked OpenSSL due to HeartBleed. OpenBSD developers are generally regarded as quite on top of their game when it comes to security, so why the "still using LibreSSL" FUD?