Live data from Hacker News

Freenginx: Core Nginx developer announces fork

mailman.nginx.org

441–450 of 501 posts

Re: Freenginx: Core Nginx developer announces fork

#441
post #248
post #137

Earlier quoted context omitted.

I haven't read the content of the patches to understand the impact of the bugs, but from my own experience [0] I can suggest a few reasons: - CVEs are gold to researchers and organizations like citations are to academics. In this case, the CVEs were filed based on "policy" but it's unclear if they are just adding noise to the DB. - The severity of the bug is not as severe as greater powers-that-be would like to think…

"Denial of service" is never a security bug; it's a huge mistake people have started classifying these things as such to start with. Serious bug? Sure. Loss of security? Not really.

You are clueless

Re: Freenginx: Core Nginx developer announces fork

#442

Earlier quoted context omitted.

The question I ask is "Why not assign a CVE?" Exactly: why not ? Glory to the Linux Kernel which is on its way to assign CVE for everything :)

That's a whole different discussion - which isn't as dramatic as it is being made out to be. Other hats I wear (outside of my day job) include being on every (literally, every) CVE.org Working Group and being the newly elected CNA Liaison to the CVE Board. This has been a subject of discussion and things are a bit overblown right now, IMHO. Some of the initial communications were perhaps not as clear as they could ha…

Answering your original question to posted to me a bit down thread with this important context. The answer to "why not issue a CVE?" is the same reason that you don't call every random car burglary or graffiti an act of terrorism.

While I agree the whole Linux CVE thing is a bit overblown, but as an outside observer the new policy [1] does not read like they are super happy with CVE in general.

Too bad the CFP is closed for VulnCon, it might be fun to do a "Assume everything is wrong and you can't do anything the way you do it now - how do you build CVE 2.0" (also that title is too long).

1. https://lwn.net/ml/linux-kernel/2024021314-unwelcome-shrill-...

Re: Freenginx: Core Nginx developer announces fork

#443

Earlier quoted context omitted.

HTTP/1, HTTP/2 and HTTP/3 are huge standards that were developed, considered and separately implemented by hundreds of people. It's built in C which has an even more massive body of support through the standard, the compilers, the standard libraries, and the standard protocols it's all implemented on. 1 or 2 people maintain one particular software implementation of some of these standards. It's interesting to think o…

I mean at that point you might as well talk about the people building microchips and power plants. You can always abstract down, but you're ignoring the fact that nginx is ~250k very important LOC with huge impact on the world. That is non-trivial in its own right.

Exactly, you might as well. It compares precisely to the original hyperbole that two people are somehow the linchpin to the entire internet.

For example, how much of that code is the mail server component and how much is the http component? How much does http/1, or http/2 or http/3 take up? How much of that is necessary to keep the internet actually running?

I'm not suggesting it's trivial but the original perspective was highly overblown. To think of it another way, if these two men died tomorrow, how much of an impact would it actually have? Some, to be sure, but the internet wouldn't even notice.

Re: Freenginx: Core Nginx developer announces fork

#444

This isn’t just “a core nginx dev” — this is Maxim Dounin! He is nginx. I would consider putting his name in the title. (And if I were F5, I’d have given him anything he asked for to not leave, including concessions on product vision.) That said, I’m not sure how much leg he has to stand on for using the word nginx itself in the new product’s name and domain…

He was working for free for the last two years, and F5 was quite happy about it.

Re: Freenginx: Core Nginx developer announces fork

#445
post #439

Earlier quoted context omitted.

That's just a braindead policy. Really, really dumb. Not at all good security, just checking boxes.

I mean, yeah, but if that's the way big bureaucratic organizations get sometimes. Bigger means more likely to have a brain-dead policy like this, but also more money... so, do you give up the money, or do you accommodate their policy while trying to minimize the cost?

Oh, I'll cash their check. I'll tell them, in professional terms, why they should change their policy, but I'll still cash the check.

Re: Freenginx: Core Nginx developer announces fork

#446
post #442

Earlier quoted context omitted.

That's a whole different discussion - which isn't as dramatic as it is being made out to be. Other hats I wear (outside of my day job) include being on every (literally, every) CVE.org Working Group and being the newly elected CNA Liaison to the CVE Board. This has been a subject of discussion and things are a bit overblown right now, IMHO. Some of the initial communications were perhaps not as clear as they could ha…

Answering your original question to posted to me a bit down thread with this important context. The answer to "why not issue a CVE?" is the same reason that you don't call every random car burglary or graffiti an act of terrorism. While I agree the whole Linux CVE thing is a bit overblown, but as an outside observer the new policy [1] does not read like they are super happy with CVE in general. Too bad the CFP is clo…

We got around 150 submissions for 30ish panel slots over three days, so we're good there. Schedule should be out soon.

The CVE program has grown and changed a lot the past few years, and the rules are undergoing a major revision right now (comment period currently) taking in a lot of the feedback. And the rate of CNAs joining has been picking up rapidly as global interest in the program has increased.

No one thinks it is perfect, but that's why a lot of us are active in the working groups and trying to keep moving things forward.

Re: Freenginx: Core Nginx developer announces fork

#447

Earlier quoted context omitted.

Without HTTP/1.1 either the modern web would not have happened, or we would have 100% IPv6 adapation by now. The Host header was such a small but extremely impactful change. I believe that without HTTP/3, nothing much would change for the majority of users.

But also, the only thing in most of the organizations I've been in that was using anything other than HTTP 1.1 was the internet facing loadbalancer or cloudflare, and even then not always. Oh yeah we might get a tiny boost from using HTTP/2 or whatever, but it isn't even remotely near top of mind and won't make a meaningful impact to anyone. HTTP/1.1 is fine and if your software only used that for the next 30 years,…

Maybe you just haven't been in organizations that consider head-of-line blocking a problem? Just because you personally haven't encountered it, doesn't mean that there aren't tons of use cases out there that require HTTP/3.

Re: Freenginx: Core Nginx developer announces fork

#448
post #248

Earlier quoted context omitted.

"Denial of service" is never a security bug; it's a huge mistake people have started classifying these things as such to start with. Serious bug? Sure. Loss of security? Not really.

You are clueless

Please provide a counter-argument, a suspiciously fresh trollish account. Shallow dismissals are against the guidelines.

Re: Freenginx: Core Nginx developer announces fork

#449

Earlier quoted context omitted.

Another issue with nginx IIRC is that it allows HTTP request smuggling, which is a critical security vulnerability.

That's been fixed for years. The CVE I can find was resolved in 1.17.7 (Dec 2019), and further hardening was applied in 1.21.1 (Jul 2021).

Can nginx send requests upstream over HTTP/2?

I see this question has remained unanswered for a couple of years.

https://security.stackexchange.com/questions/257823/what-are...

Re: Freenginx: Core Nginx developer announces fork

#450

My biggest gripe as an internet keyboard warrior with an opinion is not being able to understand the source control and build process of Nginx. Probably a skill issue but when I last tried to compile Nginx from the Github mirror I spent hours trying to figure it out. I wish there was a GitHub page with an easy to understand build process... and that I could just run "cargo build --release" lol

./configure make make install I just ran this to be sure I wasn't delusional and it took only 2 minutes.

Really?

https://github.com/nginx/nginx/tree/branches/stable-1.24

I cloned this and it doesn't have a makefile or configure script

Neither does the official repo?

https://hg.nginx.org/nginx/file/tip

Do you run it from /auto/?

Post reply on HN