Live data from Hacker News

Linus: Don't bother with grsecurity. Their patches are pure garbage

spinics.net

41–50 of 172 posts

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#41
post #10

See Linus' follow-up http://seclists.org/oss-sec/2017/q2/596 for clarification: > They aren't split up, there has never been any effort by you to make them palatable to upstream, and when somebody else dioes try to make them palatable to upstream, you start crying about how people are taking advantage of your work (hah), and try to make them private instead. ... > It's literally less work for people to re-implement t…

And the other guy's reply: http://seclists.org/oss-sec/2017/q2/597

Note: this is a lot tamer than a lot of the stuff I've seen him post in lwn.net comments.

I have a lot of respect for their work. It's just a shame that their toxic communications will make the good things they do so much less likely to be widely adopted.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#42
post #30
post #21

Earlier quoted context omitted.

The grsecurity patches have been made private. Although they are under the GPL (because they are a derivative work of the Linux kernel), the company that produces grsecurity engages in the unethical (and potentially illegal) business practice of threatening to terminate customer subscriptions if they exercise their right to distribute the patches. In other words, no customer is going to distribute the patches because…

> the company that produces grsecurity engages in the unethical (and potentially illegal) Unethical, probably - illegal, probably not. The GPL dictates what you can do once code hits your hands (or binaries compiled with), it doesn't prevent companies from selling it to you or what contract they do it under.

That depends on how you read section 6 of the GPL2. It states in part:

> You may not impose any further restrictions on the recipients' exercise of the rights granted herein.

The central right granted under the GPL is, of course, the right to modify and redistribute the source. I'm not a lawyer, and I'm certain that Grsecurity could find a number of legal arguments that what they're doing is allowed (likely starting with the claim that terminating a relationship with a customer isn't legally imposing a restriction on that customer's actions), but the idea that they're in violation of the GPL isn't pulled from thin air.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#43
post #10

See Linus' follow-up http://seclists.org/oss-sec/2017/q2/596 for clarification: > They aren't split up, there has never been any effort by you to make them palatable to upstream, and when somebody else dioes try to make them palatable to upstream, you start crying about how people are taking advantage of your work (hah), and try to make them private instead. ... > It's literally less work for people to re-implement t…

That's actually pretty tame for Linus. This is his kinder, gentler side. He must be getting old.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#45
post #6

Grsecurity wouldn't exist if Linux made security a priority. It doesn't, because backwards compatibility and features is more important to them. It doesn't mean because Linus says something so strongly on a subject is right or wrong, he is generally abusive and rants and has for years. Grsecurity is important to some people, not all, and vice versa for the features and backwards compatibility crowd. Personally I'd ho…

If backwards compatibility is broken, what you wind up with is a subsection of users that out of necessity use versions of linux with none of the updates that secure the product. You can't just tack on security patches that break user-required features willy-nilly, there's a big cost paid here.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#47
A genuine question: Why isn't it perfectly reasonable to accept to break compatibility in order to increase security? Isn't that what we do in our lifes all the time? When the authorities issue new fire safety regulations for buildings, then that is breaking compatibility to the older building standard. We still do it because there is good reason. Sometimes even old buildings need to be retrofitted, and that is then what is done.

I don't get Linus in this point, and suspect so far that he is wrong, or that I didn't get it yet.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#48
post #30
post #21

Earlier quoted context omitted.

The grsecurity patches have been made private. Although they are under the GPL (because they are a derivative work of the Linux kernel), the company that produces grsecurity engages in the unethical (and potentially illegal) business practice of threatening to terminate customer subscriptions if they exercise their right to distribute the patches. In other words, no customer is going to distribute the patches because…

> the company that produces grsecurity engages in the unethical (and potentially illegal) Unethical, probably - illegal, probably not. The GPL dictates what you can do once code hits your hands (or binaries compiled with), it doesn't prevent companies from selling it to you or what contract they do it under.

Sure you can sell it, and under whatever terms you like. But you have to _also_ provide the full source under the GPL, not under "the GPL with additional constraints".

I'm no lawyer, but I highly doubt it'll hold. And buying Linux from them could be very toxic as "GPL violation" => "termination of license" -- and I'm not sure how you go about getting a new license :)

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#49
post #4

Earlier quoted context omitted.

Can you point to specific times? I want to dig into this more.

Google Linus rant. There are many examples.

The term “Crying Wolf” implies the very specific and extreme accusation of lying. Ranting, or even ranting then reversing course are very different from lying.

Words have meaning, be careful how you use them.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#50
post #23

Earlier quoted context omitted.

A differently sounding username would have at least helped your case. :) Even if Windows kernel security is more robust, anybody can easily fault you for some form of cognitive bias. I use Windows, therefore Windows is more superior.

This is a very weird post. It's like some kind of sith mind trick. "I'd love to know more, but your name implies a connection to the subject matter and we wouldn't want that chuckle taken the wrong way."

[deleted]
Post reply on HN