OpenSSL Communities

Nicola Tuveri, Doctoral Researcher, Tampere University [FAC 2026 nomination, Academics]

Nicola Tuveri Sat 22 Aug 2026 5:17PMPrivateSeen by 2

I am a Researcher at Tampere University (Finland).
My research specializes in software and microarchitecture side-channel analysis, and in the integration of modern cryptosystems -- lately mainly post-quantum -- into mainstream libraries such as OpenSSL.
That work sits precisely where the academic community and the OpenSSL Project meet: academia is often first to find weaknesses in deployed cryptography and first to prototype what should replace it, but this only matters once it reaches the code that actually secures people's communications.

I made my first contribution to OpenSSL in 2010, later had the honor of becoming an OpenSSL Committer, and have served on the OpenSSL Technical Committee since 2019.
I also serve on the Security Response Team, which evaluates disclosures and manages their outcomes.
I have represented the Academics community on the Foundation's advisory committees in both their business and technical forms, and previously on the Corporation's Technical Advisory Committee.

During my current term, in addition to consulting the Academics community on technical decisions facing the Project, I raised the difficulty that community contributors face in getting their work reviewed.
I suggested implementing mechanisms to route straightforward PRs to external reviewers, leaving internal reviewers more capacity for substantial ones.
I argued for extending the tracking practices applied to internal contributions to cover external ones as well.
I also brought European funding instruments, Horizon Europe in particular, to the committee as a strategic avenue for the Foundation.

If elected I would continue to bring academic perspectives into the Foundation's strategic planning.
Beyond that, I see three areas where the academic community and the Foundation can grow together.

  • Facilitating collaborations with new researchers

Research that builds on OpenSSL should come back to the library as patches, tests, and documentation, and not only as papers.
Working with new researchers is also one of the few ways available to grow the contributor base, and especially the pool of reviewers, which is what limits how quickly good work gets merged.
I would like to approach this deliberately, by helping research groups whose work already builds on OpenSSL to route it back as contributions, and by supporting those contributors as they grow into reviewing.
Beyond outreach, bringing researchers in early is strategic: a part of the contributions of the academic community to the OpenSSL Foundation that secures its long-term sustainability.

  • Joint funding as an engagement incentive

Funding is closely tied to the point above.
Academics I have spoken with over my past terms came back to the same observation.
What makes it worth engaging with a project institutionally, rather than as individuals in their spare time, is the prospect of applying for grants together.
Growing academic participation in the Communities platform has been hard, and shared funding is one of the few incentives substantial enough to bring research groups in and keep them engaged.
I would like to keep advising towards making the Foundation eligible for European funding programmes such as Horizon Europe.
Besides being an engagement incentive, these programmes typically fund three years of work, sometimes more, which would let the Foundation take on initiatives that shorter grants cannot accommodate.

  • A wider range of disciplines

"Academics community" is easily misread as the researchers who write code, but OpenSSL's mission reaches much further than that, and so should the range of research represented in this community.
Privacy and usability research is one example.
Work in the social sciences and the humanities that depends on the availability of security and privacy tools is another.
There are many more: any discipline that relies on this technology or on the mission behind it has a perspective on the Project's direction that those of us closest to the code cannot supply on our own.
Progress here is slow, though. The Communities platform is where the Project expects these conversations to happen, but the low participation from these disciplines suggests it is not an obvious destination for researchers outside the usual contributor base.
Building routes towards it, starting from the fields whose work already depends on OpenSSL, is something I would want to make a concrete goal of this term.
Such a wider reach could also, in practice, be a step towards a more diverse Academics community, in gender identity, sexual orientation, and geography, across both participants and representatives.

With the Business and Technical Committees now merged, a good deal of the Foundation Advisory Committee's early work will involve working out how strategic and technical topics are best discussed in a single room.
Having served on both, and on the OTC, I hope to be useful in making that transition work.

It would be an honor to continue serving.