The trouble is that they were so ambitious but lacked any experience from which to chart those ambitions. They're just a bunch of young twenty-somethings just getting out of school. They haven't built any large-scale real-world security-hardened software yet. More than the fact that the code isn't production ready (by a long shot it seems), I'm just surprised the released anything at all. Perhaps spending all that mo…
Trouble with Diaspora
21–30 of 166 posts
Re: Trouble with Diaspora
#22They (Diaspora staff) said this as they released it: "Feel free to try to get it running on your machines and use it, but we give no guarantees. We know there are security holes and bugs..."
The issue is you shouldn't build (or ship) code like this with such major security holes, you build security at the start, it should be an integral part of the application. You can't just dick out some insecure application then add in security, it doesn't work.
Re: Trouble with Diaspora
#23They (Diaspora staff) said this as they released it: "Feel free to try to get it running on your machines and use it, but we give no guarantees. We know there are security holes and bugs..."
The issue is you shouldn't build (or ship) code like this with such major security holes, you build security at the start, it should be an integral part of the application. You can't just dick out some insecure application then add in security, it doesn't work.
.............................
................................................
Still waiting.........................
Re: Trouble with Diaspora
#24Earlier quoted context omitted.
I don't think anybody is "holding it to the same standards as a finished product." I haven't read the code myself, but the OP is claiming "really, really bad security holes", and calls out the encryption code. Security is not something that can be bolted on after the fact; it needs to be baked in from the start, in a product like this. And, remember, security/privacy was Diaspora's raison d'etre. No one expects the f…
Security is not something that can be bolted on after the fact In fact, this is how it happens in the vast majority of cases, including the case of Facebook.
Re: Trouble with Diaspora
#25This code was released to developers as an incomplete preview. I'm not sure why people are holding it to the same standards as a finished product that's being released to end users. Seems like a pretext to talk trash.
Re: Trouble with Diaspora
#26Re: Trouble with Diaspora
#27As other people have already said: this is just an early code drop. It would be good to have it transition into an open source project with many developers, especially because the developers are I assume starting their fall school term. I enjoyed building and playing with the code, and I hope that there is a much improved version in the future.
Re: Trouble with Diaspora
#28The trouble is that they were so ambitious but lacked any experience from which to chart those ambitions. They're just a bunch of young twenty-somethings just getting out of school. They haven't built any large-scale real-world security-hardened software yet. More than the fact that the code isn't production ready (by a long shot it seems), I'm just surprised the released anything at all. Perhaps spending all that mo…
Thank God that our industry isn't lousy with ambitious but inexperienced twenty-somethings. If we let them run amok, we'd get crapware like MS-DOS and computers like the Apple II.
Re: Trouble with Diaspora
#29They could've really saved themselves some grief is they'd been far more explicit about saying that it's Alpha and months from being production ready. All this 'there's bugs! omfg!' hoo-ha could've been headed off at the pass
I think there's a big difference between "omfg bugs" and "The bottom line is currently there is nothing that you cannot do to someone's Diaspora account, absolutely nothing" from http://www.theregister.co.uk/2010/09/16/diaspora_pre_alpha_l...
Re: Trouble with Diaspora
#30It's great that they're getting so much open-source help, but I'm going to ask the obvious question: if a "complete overhaul" is what's needed, as the author seems to imply, and the FOSS community performs said overhaul, then what of the $250k that was given to the Diaspora guys? Is it still even "Diaspora" anymore, as opposed to a FOSS project?
And more importantly, if you're going to rewrite, why help Diaspora, and not a more mature option?