Live data from Hacker News

Samsung's Tizen is riddled with security flaws, amateurishly written

arstechnica.com

51–60 of 69 posts

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#51
post #40

Earlier quoted context omitted.

The counter arguments include Google, Apple, Microsoft, etc. I think the big vs small comparison is flawed. I've seen some atrocious code produced by small/medium sized outfits. My fondest memory including auditing code from a 3 person outfit who's code quite literally setup an RPC on the server that executed any string it was sent, verbatim, against a database that handled money.

Those counter examples were all software startups. And have very very different cultures to other corporations their size due to their roots.

Is Samsung at this point really _that_ different in terms of semantics from those examples though. Obviously they are all unique and Samsung's location makes a big impact on their culture but like they hire a similar intelligence echelon of people right? I don't know much about the internals of Samsung so maybe I'm missing something.

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#52
post #14

Earlier quoted context omitted.

> https://what.thedailywtf.com/topic/15001/enlightened Actually it's the author of the rant that comes of as totally uninformed and with unwarranted snark to boot. https://what.thedailywtf.com/topic/15001/enlightened/242

As bad as the author comes off in that exchange, Mr. Haitzler comes off worse. Nobody should respond to their customers like that, least of all in a public forum, regardless of the provocation.

He is not a customer, he just works for a company that has adopted the (open source) framework.

And even a customer is not some holy being that gets to behave in any way they like and it has to be accepted "regardless of the provocation". What he wrote has FUD and professionally damaging to mr. Haitzler (as a programmer), while also wrong in most aspects.

Nobody should just bend over for someone (even a "customer") "regardless of the provocation". Besides FUD and insults, should the "regardless" also allow for sexual or racist comments from a customer?

And speaking of duties, does the company (Samsung) see well to an employee of them bad-mouthing their OS and choices on some random forum?

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#53

Earlier quoted context omitted.

Depends on your threat model. From TFA: Another attack on Samsung Smart TVs was published last week that used malicious commands embedded in broadcast TV signals. So, even if it's airgapped, a tv that's been compromised in this way is effectively a hostile general-purpose computer with a wifi card running inside your house. If this is something you would do for a Klondike bar, then go ahead. I'll keep my dumb TV and…

Agreed. These "smart" TVs mostly run outdated and buggy software which are difficult if not impossible to update either because of technical limitations or because the manufacturer doesn't care enough after getting your money. So why bother with a "smart" TV if you're going to be using an external computer anyway. Saving a few hundred dollars to spend on that external computer seems like a better investment. I run a…

> So why bother with a "smart" TV if you're going to be using an external computer anyway. Saving a few hundred dollars to spend on that external computer seems like a better investment.

I'm in the market for a 4k TV with low input lag. If you look at input lag tests (e.g., http://uk.rtings.com/tv/tests/inputs/input-lag) you'll see that every single TV listed there is a smart TV, at least in the 43"-50" range anyway. In fact, are there even such things as "dumb" TVs anymore?

That said, I've done some more research and realised tha the LG UH6* range is actually also pretty good for low input lags and runs webOS to boot so I think I'll go for an LG instead.

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#54

everything i've ever purchased from samsung has broken. i just don't even consider their gear now.

I've got a TV from them, 8 years old now. The connection from the component cables is slightly "iffy", but everything else has been solid as a rock. I've had 2 Samsung bluray players. The first was a refurb and still works 90% of the time, but the 10% instances are read errors from the disk drive. After 7 years of use, I was happy with it for the price I paid. The replacement player seems OK so far, although there we…

[deleted]

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#55

Tizen was/is mostly built out of a Samsung subsidiary in Warsaw, Poland. (Several thousand software engineers in total.) I worked with Polish software engineers for a western company that used the same outsourcing method during the same time that Tizen was being built. We had hires from Samsung and they had hires from us. I think that what I witnessed at our company (which I won't name) is representative for what Sam…

My assessment after having a few years perspective: - There's quite a big span between the average level to high level to top level when it comes to polish devs. Specifically, it goes a lot lever than what I'm used to. It goes high too, though, but those individuals are not necessarily cheaper than a western european employee of the same calibre (probably similar). - (Engineering) Management culture is totally whacko…

There are a lot of good software engineers in Warsaw, working at various companies. However most of companies here doesn't care that much about top talent. They just want to pay an average salary and that's all.

It is very rare that Warsaw devs that write good quality code are compensated appropriately.

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#56
post #52

Earlier quoted context omitted.

As bad as the author comes off in that exchange, Mr. Haitzler comes off worse. Nobody should respond to their customers like that, least of all in a public forum, regardless of the provocation.

He is not a customer, he just works for a company that has adopted the (open source) framework. And even a customer is not some holy being that gets to behave in any way they like and it has to be accepted "regardless of the provocation". What he wrote has FUD and professionally damaging to mr. Haitzler (as a programmer), while also wrong in most aspects. Nobody should just bend over for someone (even a "customer") "…

I presumed from his post that he had actually developed with the framework in question. In which case, he is a user of the framework, and, as far as I'm concerned, a customer to the developers of the framework.

Unless you have evidence to the contrary...?

> Nobody should just bend over for someone...

There is a world of difference between being assertive (which is fine) and being dismissive and belittling (which is not). Mr. Haitzler went way over the line. He thought that tit for tat was appropriate. It is not.

By the way, given the rather suggestive way you phrased this, you might want to check your own use of sexualized comments before criticizing someone else's.

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#57
post #47

Earlier quoted context omitted.

As bad as the author comes off in that exchange, Mr. Haitzler comes off worse. Nobody should respond to their customers like that, least of all in a public forum, regardless of the provocation.

EFL is open source software, BSD licenced. The original author of the comment is not a customer. It's some uninformed person trashing the good work someone has made available to them for free. This attitude makes me want to stop writing open source, it's disgusting to see.

I understand you're upset. But does that make Mr. Haitzler's response OK in your book?

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#58
post #14
post #7

Should not come as a surprise... https://what.thedailywtf.com/topic/15687/code-review-maledic... https://what.thedailywtf.com/topic/15001/enlightened

> https://what.thedailywtf.com/topic/15001/enlightened Actually it's the author of the rant that comes of as totally uninformed and with unwarranted snark to boot. https://what.thedailywtf.com/topic/15001/enlightened/242

That response has plenty of WTFs of its own, e.g.:

> efl checks object validity by looking at the first 4 bytes of the memory of the object. in here is a "magic number" that indicates both type and that the object isn't freed or garbage memory.

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#59
post #52

Earlier quoted context omitted.

As bad as the author comes off in that exchange, Mr. Haitzler comes off worse. Nobody should respond to their customers like that, least of all in a public forum, regardless of the provocation.

He is not a customer, he just works for a company that has adopted the (open source) framework. And even a customer is not some holy being that gets to behave in any way they like and it has to be accepted "regardless of the provocation". What he wrote has FUD and professionally damaging to mr. Haitzler (as a programmer), while also wrong in most aspects. Nobody should just bend over for someone (even a "customer") "…

To further clarify my position: I believe that rules of decorum, including responses to breaches in decorum, should govern not just traditional customer-business relationships, but user-developer and open-source community relationships as well – particularly the higher up the open-source ladder you go. Good business practice often means good community practice as well, and a healthy community is more likely to attract and retain good developers.

Now I am aware that several leaders of several major open-source communities do not consider such restraint to be necessary or even desirable. They're of course welcome to manage their communities as they see fit. I think it's a mistake though, and I believe it will lead inevitably to serious issues in those communities, if indeed it hasn't already.

Re: Samsung's Tizen is riddled with security flaws, amateurishly written

#60
post #47

Earlier quoted context omitted.

As bad as the author comes off in that exchange, Mr. Haitzler comes off worse. Nobody should respond to their customers like that, least of all in a public forum, regardless of the provocation.

EFL is open source software, BSD licenced. The original author of the comment is not a customer. It's some uninformed person trashing the good work someone has made available to them for free. This attitude makes me want to stop writing open source, it's disgusting to see.

If even one third of what the original author was complaining is true (and judging by the response, it's way more than that), I don't see how EFL can be called "good work" in good conscience. Bad code and bad design don't get a free pass on account of being open source.
Post reply on HN