Live data from Hacker News

Welcoming Semmle to GitHub

github.blog

101–110 of 110 posts

Re: Welcoming Semmle to GitHub

#101
post #4

The linked blog post [0] and the new security marketing page [1] both have a little more detail on what this actually means. Basically, Semmle offers a static analysis tool that operates on your source code as a graph (from what I understand) and points out bugs and security holes in your code. Github is now offering that for free on repos at all tiers. [0] https://github.blog/2019-09-18-securing-software-together/ […

Semmle is basically datalog over source code. For what it works for, it works nice. But it is not a pancaea. Security vulnerability finding is almost certainly the wrong target for Semmle - I am unsure why they are trying to push that angle. There are much better stories in things like refactoring and understanding. (I say this having overseen a number of deployments for various reasons, some successful, some not)

> Security vulnerability finding is almost certainly the wrong target for Semmle

CVE-2019-5876

CVE-2019-16230

CVE-2019-16231

CVE-2019-16232

CVE-2019-16233

CVE-2019-16234

CVE-2019-15026

CVE-2019-14192

CVE-2019-14193

CVE-2019-14194

CVE-2019-14195

CVE-2019-14196

CVE-2019-14197

CVE-2019-14198

CVE-2019-14199

CVE-2019-14200

CVE-2019-14201

CVE-2019-14202

CVE-2019-14203

CVE-2019-14204

CVE-2019-14437

CVE-2019-14438

CVE-2019-14438

CVE-2019-14498

CVE-2019-14535

CVE-2019-14534

CVE-2019-14533

CVE-2019-14776

CVE-2019-14778

CVE-2019-14779

CVE-2019-14777

CVE-2019-14970

CVE-2019-15119

CVE-2019-14524

CVE-2019-14523

CVE-2019-7307

CVE-2019-11476

CVE-2019-13115

CVE-2019-3570

CVE-2019-13110

CVE-2019-13112

CVE-2019-13113

CVE-2019-13108

CVE-2019-13109

CVE-2019-13111

CVE-2019-13114

CVE-2019-3560

CVE-2019-9721

CVE-2019-9718

CVE-2019-9717

CVE-2019-9720

CVE-2019-9719

CVE-2018-20222

CVE-2019-3828

CVE-2019-6986

CVE-2019-5414

CVE-2018-4460

CVE-2018-16491

CVE-2018-16489

CVE-2018-16490

CVE-2018-19476

CVE-2018-19477

CVE-2018-19475

CVE-2018-19134

CVE-2018-16472

CVE-2018-18820

CVE-2018-4407

CVE-2018-16487

CVE-2018-4259

CVE-2018-4286

CVE-2018-4287

CVE-2018-4288

CVE-2018-4291

CVE-2019-5413

CVE-2018-16461

CVE-2018-16469

CVE-2018-16486

CVE-2018-16460

CVE-2018-16492

CVE-2018-11776

CVE-2018-8018

CVE-2018-8294

CVE-2018-4249

CVE-2018-8013

CVE-2018-5388

CVE-2018-1295

CVE-2018-4136

CVE-2018-4160

CVE-2018-1000140

CVE-2017-15692

CVE-2017-15693

CVE-2017-13904

CVE-2017-15089

CVE-2018-6834

CVE-2018-6835

CVE-2017-15713

CVE-2017-12634

CVE-2017-13782

CVE-2017-7545

CVE-2017-14949

CVE-2017-14868

CVE-2017-8046

CVE-2017-8045

CVE-2017-9805

CVE-2017-1000207

CVE-2017-1000208

CVE-2017-12612

CVE-2017-0141

https://lgtm.com/security/

Re: Welcoming Semmle to GitHub

#102

Earlier quoted context omitted.

"and I don’t know Fermin, but taking a CSO role there would suggest to me that he believes in it." Sure, but Fermin was also offered a fairly ridiculous amount of money and a serious promotion :) I mean, he doesn't not believe in it, of course, but i also think most folks would have taken the role in his situation. IE it's not the kind of offer that really required a lot of faith I'll try to write a bit more later af…

Danny, I am the CEO and founder of Semmle. I will refrain from arguing about the value of our product and technology. However, I must correct your statement about Fermín which is utterly false. He took a huge pay cut to come to Semmle. Please stick to facts when talking about people.

[deleted]

Re: Welcoming Semmle to GitHub

#103
post #99

Earlier quoted context omitted.

"and I don’t know Fermin, but taking a CSO role there would suggest to me that he believes in it." Sure, but Fermin was also offered a fairly ridiculous amount of money and a serious promotion :) I mean, he doesn't not believe in it, of course, but i also think most folks would have taken the role in his situation. IE it's not the kind of offer that really required a lot of faith I'll try to write a bit more later af…

Fermin here. Danny, I loved working with you at Google but let me correct you about my promotion and money. Not true. I respect your point of view around our technology. You may like it or not (some folks love it), but please do not make statements about me you do not really know :) And to be clear, I believe this technology makes security researchers scale on different aspects. At least I had first hand experience w…

[deleted]

Re: Welcoming Semmle to GitHub

#104
post #4

Earlier quoted context omitted.

Semmle is basically datalog over source code. For what it works for, it works nice. But it is not a pancaea. Security vulnerability finding is almost certainly the wrong target for Semmle - I am unsure why they are trying to push that angle. There are much better stories in things like refactoring and understanding. (I say this having overseen a number of deployments for various reasons, some successful, some not)

> Security vulnerability finding is almost certainly the wrong target for Semmle CVE-2019-5876 CVE-2019-16230 CVE-2019-16231 CVE-2019-16232 CVE-2019-16233 CVE-2019-16234 CVE-2019-15026 CVE-2019-14192 CVE-2019-14193 CVE-2019-14194 CVE-2019-14195 CVE-2019-14196 CVE-2019-14197 CVE-2019-14198 CVE-2019-14199 CVE-2019-14200 CVE-2019-14201 CVE-2019-14202 CVE-2019-14203 CVE-2019-14204 CVE-2019-14437 CVE-2019-14438 CVE-2019-1…

Uh, I'm not sure why you believe this is an effective retort, perhaps you would like to explain?

Re: Welcoming Semmle to GitHub

#105

Earlier quoted context omitted.

> Security vulnerability finding is almost certainly the wrong target for Semmle CVE-2019-5876 CVE-2019-16230 CVE-2019-16231 CVE-2019-16232 CVE-2019-16233 CVE-2019-16234 CVE-2019-15026 CVE-2019-14192 CVE-2019-14193 CVE-2019-14194 CVE-2019-14195 CVE-2019-14196 CVE-2019-14197 CVE-2019-14198 CVE-2019-14199 CVE-2019-14200 CVE-2019-14201 CVE-2019-14202 CVE-2019-14203 CVE-2019-14204 CVE-2019-14437 CVE-2019-14438 CVE-2019-1…

Uh, I'm not sure why you believe this is an effective retort, perhaps you would like to explain?

>This list provides details about security vulnerabilities discovered by the Semmle Security Research Team using Semmle QL.

Clearly, it works.

Re: Welcoming Semmle to GitHub

#106
post #103
post #99

Earlier quoted context omitted.

Fermin here. Danny, I loved working with you at Google but let me correct you about my promotion and money. Not true. I respect your point of view around our technology. You may like it or not (some folks love it), but please do not make statements about me you do not really know :) And to be clear, I believe this technology makes security researchers scale on different aspects. At least I had first hand experience w…

[deleted]

All good Danny, we had good times at Google... let's remember those :)

Coffee offer is still there!

Re: Welcoming Semmle to GitHub

#107
post #96

Earlier quoted context omitted.

So I did read a whitepaper about static analysis at Google, and how it was largely self-serve - let developers run the tools and fix what it tells them to as they see fit. I’m wondering if it was under this model where you found it was not useful. I would not expect it to provide much value in that scenario, and would not be surprised by your feedback. If your data is closer to a model where security bug hunters whos…

[deleted]

I think there's some great feedback here, for anyone at Semmle thinking about how to develop the tool further.

Re: Welcoming Semmle to GitHub

#108

Earlier quoted context omitted.

Uh, I'm not sure why you believe this is an effective retort, perhaps you would like to explain?

>This list provides details about security vulnerabilities discovered by the Semmle Security Research Team using Semmle QL. Clearly, it works.

You want to see how long a list I can make for you for grep?

Re: Welcoming Semmle to GitHub

#109
post #96

Earlier quoted context omitted.

[deleted]

I think there's some great feedback here, for anyone at Semmle thinking about how to develop the tool further.

Annoyingly, now the GP post is now deleted, the context to my comment looks different, and I can't delete my comment.

Since the GP has been deleted I'll respect that and not reference specifics, but I want to clarify for any passers by, much of the GP comment I replied to was of a detailed and technical nature, about things like performance enhancements, features and semantic analysis approaches that could make the tools useful in more use-cases - very different from the rather general and personal criticisms I see elsewhere in the nearby comment tree.

It's the suggested technical and product enhancements that I felt was potentially useful feedback, rather than any of the criticism (I can understand why those are deleted).

Re: Welcoming Semmle to GitHub

#110
post #4

Earlier quoted context omitted.

Semmle is basically datalog over source code. For what it works for, it works nice. But it is not a pancaea. Security vulnerability finding is almost certainly the wrong target for Semmle - I am unsure why they are trying to push that angle. There are much better stories in things like refactoring and understanding. (I say this having overseen a number of deployments for various reasons, some successful, some not)

> Security vulnerability finding is almost certainly the wrong target for Semmle CVE-2019-5876 CVE-2019-16230 CVE-2019-16231 CVE-2019-16232 CVE-2019-16233 CVE-2019-16234 CVE-2019-15026 CVE-2019-14192 CVE-2019-14193 CVE-2019-14194 CVE-2019-14195 CVE-2019-14196 CVE-2019-14197 CVE-2019-14198 CVE-2019-14199 CVE-2019-14200 CVE-2019-14201 CVE-2019-14202 CVE-2019-14203 CVE-2019-14204 CVE-2019-14437 CVE-2019-14438 CVE-2019-1…

How would this list compare to other methods?
Post reply on HN