Reading one of the follow-up e-mail http://seclists.org/oss-sec/2017/q2/586 Wouldn't it be nice if you didn't demand free work of us in our free time? seems an odd line, but is there some context for the non-Linux person on what is going on?
Don't count on this recount to be correct but as far I've followed it: 200x? - grsecurity patchset is introduced and fixes a lot of bug-classes (!) and introduces lot's of security improvements to the kernel that are ground breaking and find their way in other systems like *BSD / Windows 200x-201x - code and trademarks of grsecurity get ripped from embbedded vendors - Linux foundations does nothing because they don't…
Linus: Don't bother with grsecurity. Their patches are pure garbage
161–170 of 172 posts
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#162Earlier quoted context omitted.
No, under the GPL you have the right to redistribute the source. You don't have a right to receive new patches or maintain any particular subscription, that is a different consideration that you can maintain in a separate contract.
True, But punishing people for exercising their rights, is quite similar to placing restrictions on said rights. I'm no lawyer, but you generally can't out-smart the law :)
IANAL either, in case that wasn't obvious.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#163Earlier quoted context omitted.
It is, and he's wrong, and he's usually wrong when security comes up. See also git using SHA-1: people warned him about this, and he argued passionately and incorrectly that git doesn't use SHA-1 as an integrity measure. He also argued passionately and incorrectly that SHA-1 was unlikely to be broken and worrying about it was a waste of effort. And now other people are doing a lot of slow work to dig ourselves out of…
Security in git is done by signing tags with GPG. This signs the whole tree state as in all of commit IDs and blobs. To break that, you need to collide a blob hash and commit hash or potentially pack file hash. Much harder than doing it for one file. (Albeit git used to be lax with its compression allowing garbage at the end.)
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#164Earlier quoted context omitted.
It is, and he's wrong, and he's usually wrong when security comes up. See also git using SHA-1: people warned him about this, and he argued passionately and incorrectly that git doesn't use SHA-1 as an integrity measure. He also argued passionately and incorrectly that SHA-1 was unlikely to be broken and worrying about it was a waste of effort. And now other people are doing a lot of slow work to dig ourselves out of…
Git is not really using SHA-1 for encryption, just as unique hashes. I think it is unlikely to get a collision in a non-contrived instance. Eventually git will move off of SHA-1, but I imagine it will never matter.
By "encryption" do you mean "cryptography"?
If I sign a git tag, I am signing a data structure that consists of SHA-1 hashes of other data structures. Any attack on SHA-1 means that the thing I'm signing can be subverted.
So, yes, git is using SHA-1 for cryptographic purposes.
> I think it is unlikely to get a collision in a non-contrived instance.
Why do you think this? Usually in engineering we prefer to back up statements like this with evidence.
In particular, practical SHA-1 collisions have been demonstrated: https://shattered.io/
And an attacker is going to be trying to contrive a collision, are they not?
And none of this explains why git didn't use SHA-256 back when it was easy to change. Even if SHA-1 isn't broken in practice (which it is), there's no downside to using SHA-256.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#165Earlier quoted context omitted.
Lot's of embedded vendors have plenty of GPL violations - Linksys and Ubiquity for instance in the case of grsecurity it was appearently Wind River. Apparently even no source code even if you purchased a device.
Sure, but--so? grsecurity has the copyright on what they've created. They don't need the Linux Foundation to enforce violations and there's no cause to force the Linux Foundation to do so if they don't feel it's best for Linux; copyright is optionally enforced in most jurisdictions (unlike trademark in the USA). On top of that, you're miffed that the Linux Foundation didn't "ask grsecurity or PaX if they want to get…
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#166Earlier quoted context omitted.
Along with that Grsec then says that if while the patch is GPLv2 if you distribute them they'll never let you subscribe again to get the patch in the future.
They've turned core infrastructure enhancements into what might as well be one of Microsoft's "reference source" deals, or a EULA.
The comparison with the windows reference source doesn't work because every grsec customer gets the source.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#167Earlier quoted context omitted.
Excuse typos from phone...A quote from Randy pausch (0) last lecture(1) "And he put his arm around my shoulders and we went for a little walk and he said, Randy, it’s such a shame that people perceive you as so arrogant. Because it’s going to limit what you’re going to be able to accomplish in life. What a hell of a way to word “you’re being a jerk.” [laughter] Right? He doesn’t say you’re a jerk. He says people are…
Now imagine Randy continuing with his behaviour and you having that chat with him once every x months. After few of these, what would you tell Randy? Imagine Randy worked for you, or under you on a project. I've been on teams where people left quietly or loudly because of "Randies", going through the pains to change jobs. Will you still have the same response for Randy?
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#168Earlier quoted context omitted.
Excuse typos from phone...A quote from Randy pausch (0) last lecture(1) "And he put his arm around my shoulders and we went for a little walk and he said, Randy, it’s such a shame that people perceive you as so arrogant. Because it’s going to limit what you’re going to be able to accomplish in life. What a hell of a way to word “you’re being a jerk.” [laughter] Right? He doesn’t say you’re a jerk. He says people are…
Have no idea who the guy is but.. > it’s going to limit what you’re going to be able to accomplish in life... Sure. But the counter point is that it is also going to limit what you can learn (and hence achieve) if you are only willing to take lessons wrapped in fancy paper..
what my point was here, is in this situation I think it is difficult to argue if Linus (And our IT community at large) had more of an attitude like the 'Lucky Ten Thousand' [0] not only would I think that have a much more positive effect on our code, it would in all aspects of technology and culture. yes you can easily have success with arrogance (I certainly have the problem every once in awhile albeit I usually vent when alone not at others unless it was started by someone else) that is not the point, the success could have been bigger and better if people worked together. personally I would like to see true open source GNU/source-phone(pardon the name) installation on smartphones so we stop having to sell our souls to apple/google/other major player and see solutions like that could be obtained with more cooperation and well reasoned and calm debate rather than inflammatory remarks.
[0] https://www.xkcd.com/1053/
##this part is a rant and can be safely ignored. just to add one more note, compare reddit and HN. I think you will find people solving more complex issues and having more elegant solutions and discussion on here rather than Reddit... I find it is unfortunate that we sitll need to censor ourselves here because there are some topics that generate very emotional responses (my opinion) rather than being able to have constructive conversations, in order to keep the beauty we have here we have had to self sensor some topics and that makes me sad, I love this community and the discussions we have here, but if we cannot figure out a framework to have healthy debates about taboo topics, how can we expect others? I realize that is an elitest comment but there are a lot of smart people here and we still struggle.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#169Guess you lack the level of abstraction capabilities I expect. Sure. The parable is just about lies and not signals and noises. All Linus rants are full of information. He is a brilliant programmer. Everything he screams and shouts about is always correct. He has never confused a raccoon with a wolf.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#170Earlier quoted context omitted.
I've always found it weird that de Raadt is admired for being abrasive, and Torvalds is pilloried. I've always wondered, if the grsec people are such believers of 'security above all else', why they just don't work with OpenBSD instead.
Until someone says "literally everyone uses ssh, you should donate" then watch the excuses fly.