Live data from Hacker News

Samsung's Tizen is riddled with security flaws, amateurishly written

arstechnica.com

11–20 of 69 posts

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#13
post #4

Is anyone the least surprised by this?

...Yes? I mean, Samsung is a big enough company with big enough profits to attract talented candidates and also be selective:

https://www.quora.com/How-would-you-prepare-for-the-Samsung-...

Furthermore, their mobile business is mature and well-known enough that even if they were staffed with complete amateurs whose legacy code was awful, Samsung has been a prominent player for a long time in terms of tech-biz-years. The chances are significant that they have among their ranks a wise-enough manager to realize that it's time to tackle technical debt. Or, in lieu of that, that Samsung would've by now had a come-to-Security-Jesus security fuckup traumatic enough to force a thorough audit and revamp.

Clearly that hasn't happened here so I'm interested in learning the details as they come out.

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#14
post #7

Should not come as a surprise... https://what.thedailywtf.com/topic/15687/code-review-maledic... https://what.thedailywtf.com/topic/15001/enlightened

> https://what.thedailywtf.com/topic/15001/enlightened

Actually it's the author of the rant that comes of as totally uninformed and with unwarranted snark to boot.

https://what.thedailywtf.com/topic/15001/enlightened/242

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#16
Tizen was/is mostly built out of a Samsung subsidiary in Warsaw, Poland. (Several thousand software engineers in total.) I worked with Polish software engineers for a western company that used the same outsourcing method during the same time that Tizen was being built. We had hires from Samsung and they had hires from us.

I think that what I witnessed at our company (which I won't name) is representative for what Samsung saw.

The stereotypical development model was one where individual developers were perceived as lego blocks that could be moved from one area to another about as the project(s) progressed without any regard for the individual contributors accumulated knowledge. Large volumes of contributors ("bug resolvers") were valued over smaller, coherent teams with smarter contributors.

There was also a disturbing amount of machoismo surrounding everything - nothing could be questioned; everything was a of sense pride to someone.

(What I heard from the local engineering managers supports the above.)

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#17
post #13
post #4

Is anyone the least surprised by this?

...Yes? I mean, Samsung is a big enough company with big enough profits to attract talented candidates and also be selective: https://www.quora.com/How-would-you-prepare-for-the-Samsung-... Furthermore, their mobile business is mature and well-known enough that even if they were staffed with complete amateurs whose legacy code was awful, Samsung has been a prominent player for a long time in terms of tech-biz-years.…

I interviewed for a position with one of their Smart TV software development teams. They gave me a simple-ish problem to solve. It needed to be C++ code, it needed to contain no mistakes (although they wouldn't give me a list of what they'd consider "mistakes"), and it had to be done in a plain text editor while talking to the interviewer on the phone.

I took from their "perfect on the first try" requirement for interviewing that their strategy for handling technical debt was supposed to be "don't create technical debt".

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#18
post #13
post #4

Is anyone the least surprised by this?

...Yes? I mean, Samsung is a big enough company with big enough profits to attract talented candidates and also be selective: https://www.quora.com/How-would-you-prepare-for-the-Samsung-... Furthermore, their mobile business is mature and well-known enough that even if they were staffed with complete amateurs whose legacy code was awful, Samsung has been a prominent player for a long time in terms of tech-biz-years.…

Maybe then security is less to do with individuals and more so company culture ?

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#19
Is it that big industrial corporations are bad at creating code? Toyota, samsung, synaptic.

I'm really beggining to think that code should be left to smaller and medium sized outfits. i.e samsung should buy or hire a small startup to independently develop and grow their next ecosystem. Large enterprises just seem too clumsy pull pull it off unless they wholly dedicate themselves to developing that one piece of technology.

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#20

everything i've ever purchased from samsung has broken. i just don't even consider their gear now.

I've got a TV from them, 8 years old now. The connection from the component cables is slightly "iffy", but everything else has been solid as a rock. I've had 2 Samsung bluray players. The first was a refurb and still works 90% of the time, but the 10% instances are read errors from the disk drive. After 7 years of use, I was happy with it for the price I paid. The replacement player seems OK so far, although there were a lot of "features" to disable. My Galaxy Nexus is still my favorite phone. I'd pay a lot for that phone, but with upgraded guts.
Post reply on HN