Live data from Hacker News

Linus: Don't bother with grsecurity. Their patches are pure garbage

spinics.net

121–130 of 172 posts

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#121

Linus, and this stubborn attitude of his, is the reason that Linux will always lag behind Windows in kernel security. With the vast security improvements Microsoft are putting into their operating system year on year, it's a shame to see Linux failing to keep up.

Bleh. There are enough NSA backdoors in implanted within Windows to the point that any sane person regards Microsoft security as pure theater. Secrets aren't actually secrets in Windows at all.

Now that's just silliness.

I invite you to provide solid technical evidence of these supposed "NSA backdoors" in Windows.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#122
post #90

Earlier quoted context omitted.

> their toxic communications If you can't handle the truth, then every truhful communication can be "toxic" to you.

There is not factual statement argument in that mail, so it can hardly be "the truth". Except the truth about Linus emotions (strongly negative). It is an emotional outburst, not learning material.

It's not a learning material in the sense that random outsiders won't get much out of it, but not a pointless emotional outburst either.

People on the Internet like to masturbate over the language of these rants from open source mailing lists but usually they make sense within their context and to the people who are their intended recipients. It was probably the hundredth time grsecurity was discussed on LKML and people who needed to know generally knew what is the actual criticism of it.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#123
post #98
post #84

Earlier quoted context omitted.

You're not using the term "crying wolf" correctly[1]. It has a very specific meaning in English, and that is what my complaint is in relation to. No amount of personal derision about how I "lack the level of abstraction capabilities" (whatever that means) will change that you are using the phrase incorrectly. I even specifically said that I agree that we need less difficult personalities in kernel development. It's q…

His point about desensitisation of audience stands whether cry wolf in English is limited or not. It was also quite clear from original comment.

> desensitisation of audience

This is probably a good thing. No idea why random people on the Internet get so upset every time some piece garbage is being called out ;)

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#124
post #78

Earlier quoted context omitted.

Excuse typos from phone...A quote from Randy pausch (0) last lecture(1) "And he put his arm around my shoulders and we went for a little walk and he said, Randy, it’s such a shame that people perceive you as so arrogant. Because it’s going to limit what you’re going to be able to accomplish in life. What a hell of a way to word “you’re being a jerk.” [laughter] Right? He doesn’t say you’re a jerk. He says people are…

Have no idea who the guy is but.. > it’s going to limit what you’re going to be able to accomplish in life... Sure. But the counter point is that it is also going to limit what you can learn (and hence achieve) if you are only willing to take lessons wrapped in fancy paper..

I'm sure Linus has a lot to learn that grsecurity could teach him. No, hold on.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#125
post #63
post #9

Earlier quoted context omitted.

I kind of find Linus refreshing, although I'm not sure that would survive working directly with him. I think you're begging the question though: surely compatibility/ABI stability/performance trumps extreme security (for some values of 'extreme') for people and in cases where that is true. I happen to agree with you and Linus on this (baring a known exploit of an unpatched security bug), but that heirarchy is nowhere…

I've always found it weird that de Raadt is admired for being abrasive, and Torvalds is pilloried. I've always wondered, if the grsec people are such believers of 'security above all else', why they just don't work with OpenBSD instead.

Until someone says "literally everyone uses ssh, you should donate" then watch the excuses fly.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#126
post #84

Earlier quoted context omitted.

You're not using the term "crying wolf" correctly[1]. It has a very specific meaning in English, and that is what my complaint is in relation to. No amount of personal derision about how I "lack the level of abstraction capabilities" (whatever that means) will change that you are using the phrase incorrectly. I even specifically said that I agree that we need less difficult personalities in kernel development. It's q…

Let me break it down for you with all the necessary substitutions > (idiomatic) To raise a false alarm; to constantly warn others about an imagined threat, thereby failing to get assistance when a real threat appears. The imagined threat is the level of quality in patches. He consistently raises false alarms about the quality of patches. The false part being the absolute terms he uses about the character of the peopl…

> The imagined threat is the level of quality in patches.

No, it often is a real threat.

> The false part being the absolute terms he uses about the character of the people that proposed the patches.

So feel free to disregard his opinions about the characters of other people, but don't be surprised that barely anyone treats you seriously when you suggest that the above somehow invalidates his technical analyses.

> Now that he is complaining about grsecurity I'm not inclined to listen

Which is fine because it's clearly not your job.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#127
post #59

Reading one of the follow-up e-mail http://seclists.org/oss-sec/2017/q2/586 Wouldn't it be nice if you didn't demand free work of us in our free time? seems an odd line, but is there some context for the non-Linux person on what is going on?

Don't count on this recount to be correct but as far I've followed it: 200x? - grsecurity patchset is introduced and fixes a lot of bug-classes (!) and introduces lot's of security improvements to the kernel that are ground breaking and find their way in other systems like *BSD / Windows 200x-201x - code and trademarks of grsecurity get ripped from embbedded vendors - Linux foundations does nothing because they don't…

Their groundbreaking research was improvements that were directly derivative of work shipped with a license that said all derivative works must be provided under the same free license they received the work with.

Your tone seems to suggest that some obligation exists that some obligation exists to do more than share the source to any improvements.

This obligation is wholly and totally imaginary. Its as if someone gave another party an entire farm and in the contract specified that he could eat some of the food that grew from it and that someone threw a fit when the first party walked up and made a sandwich.

Seeing as there is no sane and legal way to require anyone to pay for said patches the reasonable way to fund such an effort is to get the community to voluntarily fund such an effort with whatever platform is most useful preferably in advance.

It seems that they have instead chosen to rely on a mixture of manufactured drama, illegal threats, and general unpleasantness to keep their efforts from being well integrated with mainstream. While this remains so they can offer definable value.

In the long run I predict bankruptcy and irrelevance for a company that few care about now and none will care about later.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#128

Earlier quoted context omitted.

And the other guy's reply: http://seclists.org/oss-sec/2017/q2/597

Seems like a waste of time for him to hold up that side of the argument. Even if he's 100% correct, what's he going to achieve? The changes aren't going into the kernel until they get past Linus, and for that to happen the patches need to meet the same standards as every other patch. It's not like he's going to lower the bar for one company.

> Even if he's 100% correct, what's he going to achieve? The changes aren't going into the kernel until they get past Linus

You are incorrectly assuming grsec guy wants the changes[1] in the mainline Linux kernel - this would destroy a huge fraction of the value proposition. In a follow-up message, Linus directly challenged them on how they intentionally make their patches hard to upstream (and how they complain about 'leeching' if someone does attempt to upstream - talk about lack of self-awareness).

1. He might not mind old changes, but the quicker the new patches get upstreamed, the less valuable the patchset becomes for their paying clients

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#129
post #71
post #47

A genuine question: Why isn't it perfectly reasonable to accept to break compatibility in order to increase security? Isn't that what we do in our lifes all the time? When the authorities issue new fire safety regulations for buildings, then that is breaking compatibility to the older building standard. We still do it because there is good reason. Sometimes even old buildings need to be retrofitted, and that is then…

It is, and he's wrong, and he's usually wrong when security comes up. See also git using SHA-1: people warned him about this, and he argued passionately and incorrectly that git doesn't use SHA-1 as an integrity measure. He also argued passionately and incorrectly that SHA-1 was unlikely to be broken and worrying about it was a waste of effort. And now other people are doing a lot of slow work to dig ourselves out of…

Actually this is true on some level:

- He argues and argues that everything is fine

- Weeks later he fixes the issue

Conclusion: he was wrong

Post reply on HN