Earlier quoted context omitted.
Serious question: Do you need the non-techy explanation?
no.. but I could be a non IT user using hipchat. This sentence is likely meaningless to me.
HipChat security notice
21–30 of 119 posts
Re: HipChat security notice
#22Earlier quoted context omitted.
Serious question: Do you need the non-techy explanation?
no.. but I could be a non IT user using hipchat. This sentence is likely meaningless to me.
I'm happy they say this.. now i'd like some sort of proof :-)
Re: HipChat security notice
#23Re: HipChat security notice
#24Earlier quoted context omitted.
More importantly, I wonder how much they were paying for this library, or to what extent they were supporting it internally. Because if the answer is zero and they weren't, I would put a lot of the blame on HipChat engineering.
I'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?
If you use someone else's code, especially if you're not paying anything for it, you get what you put into it: nothing.
The liability for this breach is ultimately owned by Atlassian, not the third party library writer. To quote the most permissive license out there:
"THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED."
Re: HipChat security notice
#25Needless to say their (login) servers crashed from the pressure of people resetting their credentials. "Hey, you know what might be a good idea? Let's email all of the accounts at the same time using an Appriver blast!" Atlassian. I hate to hate you.
Only emailing a rolling amount of your customers becomes a shit show of support, who do you email first? Who do you email last? How long do you wait between groups? For who is security important, your biggest customers, highest paying, most security conscious? It's a real shit show to know, and one you'd absolutely get wrong, letting everyone know as fast as possible is the only acceptable solution to a security breach.
Re: HipChat security notice
#26Earlier quoted context omitted.
Not only moral, but mostly legal. Warranties are not included. So it's a bit lame to blame "a popular third party library". The OP was trying to say a company of Atlassians size should dedicate the resources to vet (and fix) those libraries if they use them for these purposes.
I don't think anyone is trying to shift blame, just to explain what happened. I am not affiliated with Atlassian so I'm only guessing.
Re: HipChat security notice
#27Re: HipChat security notice
#28Re: HipChat security notice
#29Is this implying their database was leaked?
Re: HipChat security notice
#30Earlier quoted context omitted.
Open source code now carries a moral maintenance obligation? Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? That doesn't seem fair or reasonable.
> Open source code now carries a moral maintenance obligation? Yes, and it always has and it can't be discharged. Pay-it-forward is the right thing to do. > Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? I certainly do. A red line, I-will-quit condition is and always has been "I won't participate in the development of private forks of ope…
Interesting - it may be a nice thing to do, but I don't agree that there is any sort of obligation to the project just for using the project.
> I certainly do. A red line, I-will-quit condition is and always has been "I won't participate in the development of private forks of open-source software" and I have at multiple employers gotten checks straight-up cut to open-source software maintainers. I have also entreated (and in two cases succeeded in convincing) maintainers to start up maintenance programs so we could pay them a yearly fee--because donations are way harder to push than support plans.
I have also worked at companies that funded open source projects through donations or maintenance, but there was never a moral obligation there. It was more a method of risk management than altruism.
> I consider not paying forward kindnesses paid to you way, way more unfair and unreasonable.
Paying forward kindness and being morally obligated to maintain an open source library just because you use it are different things in my mind. It seems like being paid a kindness creates an obligation, which is not that nice.
---
Interesting perspective even though I strongly disagree. I'll continue to use open source projects 'AS IS'[0] and I still wont feel morally obligated to maintain them. Similar to how I use linux/BSD and don't feel obligated to maintain the kernel. I'm certainly grateful of course, but I don't feel like there was any sort of contract/exchange between myself and the maintainers that creates an obligation on my part.
[0] https://github.com/eropple/auster/blob/master/LICENSE.txt