Live data from Hacker News

Linus: Don't bother with grsecurity. Their patches are pure garbage

spinics.net

91–100 of 172 posts

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#91
post #70

Earlier quoted context omitted.

> their toxic communications If you can't handle the truth, then every truhful communication can be "toxic" to you.

If you speak the truth like an asshole all anyone will take away from it is that you're an asshole.

[deleted]

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#92

Earlier quoted context omitted.

Along with that Grsec then says that if while the patch is GPLv2 if you distribute them they'll never let you subscribe again to get the patch in the future.

That's a pretty interesting loophole in the GPL: apparently (at least with V2), it might be fine to impose consequences for exercising your rights while technically giving them to you. It certainly violates the spirit of the GPL even if it doesn't violate the letter.

It does not impose amy restrictions on getting the code. You need to write a bot to get status updates though.

Mailing list is not the code.

If he starts filtering on the web server or rejecting direct source requests, he starts violating the letter of GPL 2.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#93
post #42
post #30

Earlier quoted context omitted.

> the company that produces grsecurity engages in the unethical (and potentially illegal) Unethical, probably - illegal, probably not. The GPL dictates what you can do once code hits your hands (or binaries compiled with), it doesn't prevent companies from selling it to you or what contract they do it under.

That depends on how you read section 6 of the GPL2. It states in part: > You may not impose any further restrictions on the recipients' exercise of the rights granted herein. The central right granted under the GPL is, of course, the right to modify and redistribute the source. I'm not a lawyer, and I'm certain that Grsecurity could find a number of legal arguments that what they're doing is allowed (likely starting…

It is enough for them to send the source on a written request. May be a link (working!), may be source code on a disk.

Someone will have to set up an automatic snail mailer.

If they do not respect that, they are explicitly violating GPL.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#94
post #84

Guess you lack the level of abstraction capabilities I expect. Sure. The parable is just about lies and not signals and noises. All Linus rants are full of information. He is a brilliant programmer. Everything he screams and shouts about is always correct. He has never confused a raccoon with a wolf.

You're not using the term "crying wolf" correctly[1]. It has a very specific meaning in English, and that is what my complaint is in relation to. No amount of personal derision about how I "lack the level of abstraction capabilities" (whatever that means) will change that you are using the phrase incorrectly. I even specifically said that I agree that we need less difficult personalities in kernel development. It's q…

Let me break it down for you with all the necessary substitutions

> (idiomatic) To raise a false alarm; to constantly warn others about an imagined threat, thereby failing to get assistance when a real threat appears.

The imagined threat is the level of quality in patches. He consistently raises false alarms about the quality of patches. The false part being the absolute terms he uses about the character of the people that proposed the patches. Calling someone an infantile moron qualifies as falsehood in my book and counts as raising a false alarm. Now that he is complaining about grsecurity I'm not inclined to listen because the level of alarm he has used previously has been incommensurate with reality, as in he has said "here is a wolf" (this patch is the worst thing ever and the person that wrote it is a moron) when in reality there was no wolf (patch was actually fine and the person was not a moron). Less alarmism would have helped everyone involved get along better and make a more secure kernel. Instead I'm arguing about how comparing his alarmism to crying wolf is or isn't idiomatic. FML

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#95
post #71
post #47

A genuine question: Why isn't it perfectly reasonable to accept to break compatibility in order to increase security? Isn't that what we do in our lifes all the time? When the authorities issue new fire safety regulations for buildings, then that is breaking compatibility to the older building standard. We still do it because there is good reason. Sometimes even old buildings need to be retrofitted, and that is then…

It is, and he's wrong, and he's usually wrong when security comes up. See also git using SHA-1: people warned him about this, and he argued passionately and incorrectly that git doesn't use SHA-1 as an integrity measure. He also argued passionately and incorrectly that SHA-1 was unlikely to be broken and worrying about it was a waste of effort. And now other people are doing a lot of slow work to dig ourselves out of…

Security in git is done by signing tags with GPG. This signs the whole tree state as in all of commit IDs and blobs. To break that, you need to collide a blob hash and commit hash or potentially pack file hash. Much harder than doing it for one file. (Albeit git used to be lax with its compression allowing garbage at the end.)

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#97
post #48
post #30

Earlier quoted context omitted.

> the company that produces grsecurity engages in the unethical (and potentially illegal) Unethical, probably - illegal, probably not. The GPL dictates what you can do once code hits your hands (or binaries compiled with), it doesn't prevent companies from selling it to you or what contract they do it under.

Sure you can sell it, and under whatever terms you like. But you have to _also_ provide the full source under the GPL, not under "the GPL with additional constraints". I'm no lawyer, but I highly doubt it'll hold. And buying Linux from them could be very toxic as "GPL violation" => "termination of license" -- and I'm not sure how you go about getting a new license :)

No, under the GPL you have the right to redistribute the source. You don't have a right to receive new patches or maintain any particular subscription, that is a different consideration that you can maintain in a separate contract.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#98
post #84

Guess you lack the level of abstraction capabilities I expect. Sure. The parable is just about lies and not signals and noises. All Linus rants are full of information. He is a brilliant programmer. Everything he screams and shouts about is always correct. He has never confused a raccoon with a wolf.

You're not using the term "crying wolf" correctly[1]. It has a very specific meaning in English, and that is what my complaint is in relation to. No amount of personal derision about how I "lack the level of abstraction capabilities" (whatever that means) will change that you are using the phrase incorrectly. I even specifically said that I agree that we need less difficult personalities in kernel development. It's q…

His point about desensitisation of audience stands whether cry wolf in English is limited or not. It was also quite clear from original comment.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#99
post #25

Earlier quoted context omitted.

Crying wolf requires him to have been wrong (or lied). I think that GP was asking you for evidence of _that_, not of evidence that Linus has ranted in the past. From memory, I can't recall a time where his ranting was not justified, but he has been wrong a couple of times. Unless I'm missing something blatant, that doesn't constitute "crying wolf" to me.

The parable of the boy crying wolf is not about lies but about desensitizing your audience to what you are saying. I've read enough of the rants to know there is very little signal to all the noise he makes. The grsecurity stuff could be bad but I sure as hell am not gonna get my analysis from Linus. If he acted more like a grown up then maybe but he doesn't. He character assassinates and then says you are doing sill…

[deleted]
Post reply on HN