Live data from Hacker News

Grsecurity: Potential contributory infringement and breach of contract risk

perens.com

101–110 of 128 posts

Re: Grsecurity: Potential contributory infringement and breach of contract risk

#101
post #95

Earlier quoted context omitted.

I see grsecurity in the web hosting industry a lot . Tons of people have bought their snake oil (and major players in the shared hosting and multi-tenant hosting space are proponents of grsec). I've always been uncomfortable with it, even though there are a handful of good ideas in there. Why would I trust something that isn't allowed to go through the normal quality vetting process as the rest of the kernel?

I don't think it's at all reasonable to refer to Grsecurity as "snake oil". I think it was a mistake to say that, and you should probably retract and apologize. You don't have to like Grsecurity, or recommend it. Lots of people don't. But you're a professional working in this field and what you've written on this thread doesn't meet that standard.

You'd know better than I would, though I'm not inclined to apologize. I will use more mildly negative language henceforth, however.

My problems with Grsecurity are, in order of importance:

- This whole licensing thing. I like the GPL. I publish much of my software under the GPL. I want the GPL to be a real thing that we all respect and abide by. When someone breaks that social contract, we all lose.

- The lack of effort to work with the rest of the kernel community. They've got this huge stack of patches (and it is huge), they're selling it to a bunch of folks (some of whom probably know enough to be making security decisions, many of whom probably don't), and yet they don't really seem interested in being a member of the OSS community.

- There's a recurring theme (even before now, I've heard this argument) of people asserting that someone attacked their server, and, because they had grsec, it crashed instead of allowing the attacker to exploit the system. As though that's not a successful attack in and of itself. The quality of grsecurity code has been called into question by more than one kernel dev, including Linus.

- There's some misleading marketing going on somewhere. I happen to work in the industry sort of parallel to grsecurity. We have a handful of the same customers, there's some overlap in the systems we see and the ones they exist on. For whatever reason, our users who have grsecurity on their systems are the most poorly informed about how the security features of a Linux system fit together (and they think all of them come from grsecurity, even though usually it's none of the ones we're talking about or helping them with). I don't know if grsecurity folks are misleading their customers, or people are just filling in the blanks with where security comes from (obviously it's the security product they paid money for, rather than the kernel itself which was free and thus obviously worthless). It's like the Fox News of kernel patches, somehow messing with it makes people less knowledgeable about the security of their systems.

It's a personal pet peeve, I guess. But, there are, as I said, good ideas in grsecurity. I wish they'd go through the usual process of getting things into the kernel. As it is, they've got a cool research kernel that's unfortunately been pushed into production on some of the most dangerous systems out there (shared hosting and multi-tenancy systems that have barely trusted users and frequently run poorly maintained web apps that often expose the system to untrusted code).

I'm rambling a bit here, but my point is, I won't call it snake oil anymore, but I'm probably not gonna shower it with praise, either. The folks building it are clearly very smart. I really don't mean to denigrate their skills, their experience, or even the software they've built. I just wish they worked with the kernel community more, and I wish whoever is spreading around myths about kernel security and how grsec interacts with it would stop doing so.

Re: Grsecurity: Potential contributory infringement and breach of contract risk

#102

Earlier quoted context omitted.

"Also, you should read the fine print from any other Linux vendor – RHEL, Oracle, etc. You don't have to go on "my understanding from several reliable sources", the documents actually state they'll terminate you as a customer if you redistribute their stuff." I don't know about Oracle, but I know about Red Hat. They not only do not prohibit one from distributing source code and the patches they apply to it, they dist…

> Red Hat. They not only do not prohibit one from distributing source code and the patches they apply to it Of course they prohibit it. e.g. from [1] > This EULA does not permit you to distribute the Programs or their components using Red Hat's trademarks, regardless of whether the copy has been modified. You may make a commercial redistribution of the Programs only if (a) permitted under a separate written agreement…

Red Hat requires you remove their trademarks before distributing the component. The trademarks are not the source code.

They do not restrict you from distributing the source code.

Grsecurity restricts you from distributing the source code.

These are very different things.

Re: Grsecurity: Potential contributory infringement and breach of contract risk

#103
post #28

Earlier quoted context omitted.

If I understand it correctly, you can distribute Red Hat's source all you want, but it's up to you to figure out which bits of the kernel that is. That extra information is not part of the code.

What is the "extra information" in this context?

The patch metadata: which lines have changed for what purpose.

Re: Grsecurity: Potential contributory infringement and breach of contract risk

#104
grsecurity is a good effort, if you dont like it dont use it but dont complain about people trying to make a turd less of a turd even if it is of your opinion they fail at it. alot of people sell software that 'only functions on linux', people even sell linux based appliances, they all leave the licence files etc. neatly tucked away somewhere for licence nazis to find >.>. people who critisize grsecurity and praise linux probarbly dont care much about the rootkits in their systems >.>

Re: Grsecurity: Potential contributory infringement and breach of contract risk

#105
post #95

Earlier quoted context omitted.

I don't think it's at all reasonable to refer to Grsecurity as "snake oil". I think it was a mistake to say that, and you should probably retract and apologize. You don't have to like Grsecurity, or recommend it. Lots of people don't. But you're a professional working in this field and what you've written on this thread doesn't meet that standard.

Care to refute? We've got quotes from Linus himself in this thread that show a belief that their products do not provide value. I'd say that while Linus is generally inflammatory, he's also generally correct. I don't know that what SwellJoe has said is any worse. Do you believe Linus should retract and apologize as well? This request is genuine - you're a well respected voice in the security world, and I'd be curious…

Linus' take on security patches is a highly debated topic. Not only with the grsec guys, but all other people working in netsec. That does not mean Linus is always wrong (though imo he often is regarding that topic) nor that grsec is great of course.

Re: Grsecurity: Potential contributory infringement and breach of contract risk

#106
post #95

Earlier quoted context omitted.

I don't think it's at all reasonable to refer to Grsecurity as "snake oil". I think it was a mistake to say that, and you should probably retract and apologize. You don't have to like Grsecurity, or recommend it. Lots of people don't. But you're a professional working in this field and what you've written on this thread doesn't meet that standard.

Care to refute? We've got quotes from Linus himself in this thread that show a belief that their products do not provide value. I'd say that while Linus is generally inflammatory, he's also generally correct. I don't know that what SwellJoe has said is any worse. Do you believe Linus should retract and apologize as well? This request is genuine - you're a well respected voice in the security world, and I'd be curious…

> We've got quotes from Linus himself in this thread that show a belief that their products do not provide value.

All I see is a link to some message where Linus calls these patches pure garbage. There's very little context, and the only borderline technical issue he points out is that grsecurity breaks things. If that is the message you're referring to, it only shows that the grsecurity patches are not aligned with Linus' values. That's a very different thing than the belief that they provide no value.

We know more about Linus' values, based on this old quote:

> I think the OpenBSD crowd is a bunch of masturbating monkeys, in that they make such a big deal about concentrating on security to the point where they pretty much admit that nothing else matters to them.

So, for example, if your values place performance and compatibility with old (proprietary..) binaries above all else, then a patch that degrades performance and breaks compatibility with old binaries may as well be "pure garbage."

Yet, a lot of people are willing to sacrifice some performance & compatibility for improved security. Now whether grsecurity does that adequately is a debate I do not wish to take part in.

Re: Grsecurity: Potential contributory infringement and breach of contract risk

#107
post #95

Earlier quoted context omitted.

I don't think it's at all reasonable to refer to Grsecurity as "snake oil". I think it was a mistake to say that, and you should probably retract and apologize. You don't have to like Grsecurity, or recommend it. Lots of people don't. But you're a professional working in this field and what you've written on this thread doesn't meet that standard.

Care to refute? We've got quotes from Linus himself in this thread that show a belief that their products do not provide value. I'd say that while Linus is generally inflammatory, he's also generally correct. I don't know that what SwellJoe has said is any worse. Do you believe Linus should retract and apologize as well? This request is genuine - you're a well respected voice in the security world, and I'd be curious…

I think you're missing the point here. It's not helped by the way Linus has expressed himself here. The truth is that there's a fundamental philosophical disagreement here: Linus prioritises not breaking userland, GR security doesn't. Their patches are "crap" because they're large and not in the correct style, not because they don't achieve what they set out to do. Sometimes people take subsets of those patches, clean them up and get them put into the kernel, which is the source of GRS's accusations of "stealing".

The short version is that GR Security have personalities and behaviors very like Linus' own. There's value in GRS, and a fair amount of bad behaviour, but let's be frank, the same's true of Linux.

Re: Grsecurity: Potential contributory infringement and breach of contract risk

#108
post #103

Earlier quoted context omitted.

What is the "extra information" in this context?

The patch metadata: which lines have changed for what purpose.

Sorry, I am still not sure what you mean. Could you point me at an example of 'patch metadata'? Thanks!

Re: Grsecurity: Potential contributory infringement and breach of contract risk

#109

Earlier quoted context omitted.

I'm not interested in re-litigating the trademark discussion here. It's not relevant to the grsecurity conversation, and it's been settled for a decade or so. Trademark law is separate from copyright law and really has no place in a copyright discussion. Red Hat places branding in their own packages, generally, which is easily replaced by distributions...they do their own re-branding in Fedora and CentOS; the tradema…

My assertion had nothing to do with whether they made it easy or hard to remove their trademarks. My assertion was that Red Hat customers make agreements with Red Hat in which they agree not to redistribute RHEL. That is directly analogous to the GRSecurity case, except there we are relying on something OP heard thirdhand and in the case of RH we can read the agreements.

You don't understand the issue then (and your assertion is patently false as I outlined elsewhere).

First of all, requiring trademark removal is something the FSF considers acceptable so long as it is reasonable to do[1]. Both RHEL and SUSE have all of their branding in specifically labeled packages so it is easy to replace.

Second of all, GRSecurity will always penalise you if you distribute their sources (regardless of whether you remove any trademarks they may have in their source -- which I don't think they do).

The two issues are completely different and you're muddying the waters by bringing up Red Hat, even though the free software community has agreed that removal of trademarks is acceptable[1]. You're bringing up a non-issue in a discussion about an actual issue.

[1]: https://www.gnu.org/distros/free-system-distribution-guideli...

Re: Grsecurity: Potential contributory infringement and breach of contract risk

#110
post #107

Earlier quoted context omitted.

Care to refute? We've got quotes from Linus himself in this thread that show a belief that their products do not provide value. I'd say that while Linus is generally inflammatory, he's also generally correct. I don't know that what SwellJoe has said is any worse. Do you believe Linus should retract and apologize as well? This request is genuine - you're a well respected voice in the security world, and I'd be curious…

I think you're missing the point here. It's not helped by the way Linus has expressed himself here. The truth is that there's a fundamental philosophical disagreement here: Linus prioritises not breaking userland, GR security doesn't. Their patches are "crap" because they're large and not in the correct style, not because they don't achieve what they set out to do. Sometimes people take subsets of those patches, clea…

> Sometimes people take subsets of those patches, clean them up and get them put into the kernel, which is the source of GRS's accusations of "stealing".

This is insane. If their argument had any legal merit, it is because of a bug in gpl and we should patch it. Just based on the accusation of theft, without knowing anything else about them or anything else, I can safely say they're scum bags and no I don't have a Fields medal but I don't retract it.

I do think Linus should have adopted "or later" a long time ago but that's a different discussion.

Post reply on HN