Earlier quoted context omitted.
His point about desensitisation of audience stands whether cry wolf in English is limited or not. It was also quite clear from original comment.
> desensitisation of audience This is probably a good thing. No idea why random people on the Internet get so upset every time some piece garbage is being called out ;)
Linus: Don't bother with grsecurity. Their patches are pure garbage
141–150 of 172 posts
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#142Earlier quoted context omitted.
Sure. But sometime, you can take away only that. but the loss will be all yours. I mean, somebody can give you a block on gold unpolished and unwrapped. Sure, you can say, "How dare you give me that gold unwrapped! There is no way I am taking it. I demand you give that wrapped up property in fancy paper and tied with a ribbon." Sure you can say that. But the loss will be all yours. You got the shit anyway and gained…
I'm not sure gold is the right analogy in this case.. I think that is holding grsecurity's work in higher esteem than is necessary. Don't forget, the code is just part of the work. Ones attitude in contributing that code is another large part of what makes the work "gold". A better analogy might person A be handing person B back an improvement on person B's own recipe. However, the improvement is written on a piece o…
> Ones attitude in contributing that code is another large part of what makes the work "gold".
Even if the analogy meant we were talking about the code being the gold, this wouldn't make sense. The machine only executes code, regardless of the attitude of who wrote it.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#143For all his unfortunate abrasiveness one strength of Linus is and has always been his capacity to see the big picture, e.g. that usually compatibility/API,ABI stability/performances trumps extreme security measures and also he has always been able to accomodate with big players/corps in the industry.
You can see why Google wants to move to its own OS when Linus has that attitude.
Besides, it's bullshit that you can't have ABI stability and security. It feels to me like Linus is still in the "I never write bugs" stage of denial, despite the evidence.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#144Earlier quoted context omitted.
Don't count on this recount to be correct but as far I've followed it: 200x? - grsecurity patchset is introduced and fixes a lot of bug-classes (!) and introduces lot's of security improvements to the kernel that are ground breaking and find their way in other systems like *BSD / Windows 200x-201x - code and trademarks of grsecurity get ripped from embbedded vendors - Linux foundations does nothing because they don't…
Their groundbreaking research was improvements that were directly derivative of work shipped with a license that said all derivative works must be provided under the same free license they received the work with. Your tone seems to suggest that some obligation exists that some obligation exists to do more than share the source to any improvements. This obligation is wholly and totally imaginary. Its as if someone gav…
I'm having trouble seeing, apart from ignorance or misinformation, why anyone would condone GRSecurity. The code is helpful but you wouldn't want the authors in a position of authority over the operating system of a billion-plus computers.
Right now, most arguments in defense of GRSecurity are simply: "Two sides are arguing, therefore they're both wrong. Aren't I smarter for pointing it out?"
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#145Earlier quoted context omitted.
I'm not sure gold is the right analogy in this case.. I think that is holding grsecurity's work in higher esteem than is necessary. Don't forget, the code is just part of the work. Ones attitude in contributing that code is another large part of what makes the work "gold". A better analogy might person A be handing person B back an improvement on person B's own recipe. However, the improvement is written on a piece o…
I think the gold in the parent's analogy is Linus's criticism. And people want it wrapped up in kinder words. > Ones attitude in contributing that code is another large part of what makes the work "gold". Even if the analogy meant we were talking about the code being the gold, this wouldn't make sense. The machine only executes code, regardless of the attitude of who wrote it.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#146Earlier quoted context omitted.
Note: this is a lot tamer than a lot of the stuff I've seen him post in lwn.net comments. I have a lot of respect for their work. It's just a shame that their toxic communications will make the good things they do so much less likely to be widely adopted.
> It's just a shame that their toxic communications will make the good things they do so much less likely to be widely adopted. You are talking as if they wanted it to be upstreamed in the first place, which isn't quite obvious from this email.
> I've no doubt Brad is smart, but the play reads like an attempt at a Xanatos Gambits where he technically makes his fixes public, but deliberately keeps them tough to use, so his competitors get horrid press if they don't use the fixes, but have to expend more resources than necessary in order to use them, furthering his market posture.
https://www.reddit.com/r/linux/comments/6j7saq/linus_torvald...
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#147Earlier quoted context omitted.
It is, and he's wrong, and he's usually wrong when security comes up. See also git using SHA-1: people warned him about this, and he argued passionately and incorrectly that git doesn't use SHA-1 as an integrity measure. He also argued passionately and incorrectly that SHA-1 was unlikely to be broken and worrying about it was a waste of effort. And now other people are doing a lot of slow work to dig ourselves out of…
Git is not really using SHA-1 for encryption, just as unique hashes. I think it is unlikely to get a collision in a non-contrived instance. Eventually git will move off of SHA-1, but I imagine it will never matter.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#148Earlier quoted context omitted.
Don't count on this recount to be correct but as far I've followed it: 200x? - grsecurity patchset is introduced and fixes a lot of bug-classes (!) and introduces lot's of security improvements to the kernel that are ground breaking and find their way in other systems like *BSD / Windows 200x-201x - code and trademarks of grsecurity get ripped from embbedded vendors - Linux foundations does nothing because they don't…
Their groundbreaking research was improvements that were directly derivative of work shipped with a license that said all derivative works must be provided under the same free license they received the work with. Your tone seems to suggest that some obligation exists that some obligation exists to do more than share the source to any improvements. This obligation is wholly and totally imaginary. Its as if someone gav…
KSPP is a program started by some corporations (including Intel which is the parent company that was being talking about that messed with trademarks) and they pay some developers (such as kees cook) to rip off grsecurity/PaX code.
It's funny how you talk about obligation when linus is here calling them clowns for their code which has for years protected systems which would otherwise be vulnerable such as vanilla linux kernels just because they are not in the format that the linux upstream wants?
Doesn't hero worship get tiring? You make predictions about something you are seemingly ignorant about because they have customers because some people can't rely on the joke that is upstream linux security.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#149Earlier quoted context omitted.
Don't count on this recount to be correct but as far I've followed it: 200x? - grsecurity patchset is introduced and fixes a lot of bug-classes (!) and introduces lot's of security improvements to the kernel that are ground breaking and find their way in other systems like *BSD / Windows 200x-201x - code and trademarks of grsecurity get ripped from embbedded vendors - Linux foundations does nothing because they don't…
"2016-2017: - Linux foundation founds KSPP and works on integrating basically PaX/grsecurity into mainline - does not even ask grsecurity or PaX if they want to get paid for helping but they are flamed at and bothered with inquiries from devs - according to grsecurity most of KSPP work is copy&paste the grsecurity code without deeper understanding" I don't follow this stuff closely, but I believe that the KSPP was st…
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#150Earlier quoted context omitted.
Don't count on this recount to be correct but as far I've followed it: 200x? - grsecurity patchset is introduced and fixes a lot of bug-classes (!) and introduces lot's of security improvements to the kernel that are ground breaking and find their way in other systems like *BSD / Windows 200x-201x - code and trademarks of grsecurity get ripped from embbedded vendors - Linux foundations does nothing because they don't…
>they produced ground breaking research and it got ripped of everywhere. This is the part I don't get. They produced ground breaking research on a GPL platform, what did they expect to happen?
They produced ground breaking research only to have the linux foundation (which includes intel which is one of the companies that messed with trademarks of grsecurity) pay someone else to copy it over so they can make grsecurity obsolete and then get called clown by the upstream.