Live data from Hacker News

Theo de Raadt: "You've been smoking something mind altering" (2007)

marc.info

11–20 of 99 posts

Re: Theo de Raadt: "You've been smoking something mind altering" (2007)

#12
post #6

Earlier quoted context omitted.

I mean, Torvalds has called basically every person on earth an asshole at some point, hasn’t he? He’s the opposite of being sparing with critisicism, and frankly has historically often used his bully pulpit to do it.

[flagged]

[deleted]

Re: Theo de Raadt: "You've been smoking something mind altering" (2007)

#13
One of his dumber takes. Virtualization replaces an ultra-functional general-purpose kernel evolved over decades to support every conceivable application with a drastically smaller "kernel" (KVM and the userland hypervisor). It's a drastic attack surface reduction, and the empirical data bears that out: kernel LPEs aren't even newsworthy (there's whole repos full of unnamed, unremarked-upon LPEs), and KVM escapes are very rare.

Re: Theo de Raadt: "You've been smoking something mind altering" (2007)

#14
post #6

Earlier quoted context omitted.

I mean, Torvalds has called basically every person on earth an asshole at some point, hasn’t he? He’s the opposite of being sparing with critisicism, and frankly has historically often used his bully pulpit to do it.

[flagged]

Personally I believe being an asshole to people is doing something wrong.

Re: Theo de Raadt: "You've been smoking something mind altering" (2007)

#15
post #6

Earlier quoted context omitted.

I mean, Torvalds has called basically every person on earth an asshole at some point, hasn’t he? He’s the opposite of being sparing with critisicism, and frankly has historically often used his bully pulpit to do it.

[flagged]

There are many extremely competent engineers who can’t deal with the idea of exposing themselves to public humiliation. That’s especially true in today’s environment where these kind of bully rants have become a spectacle for outsiders. Just google the name of the person who was the subject to one of Linus’ rants about a year ago. Despite being a very accomplished figure in the RISC-V world, top results for his name are links to Linus calling him an idiot. That’s a mark he will have for life. I would die of embarrassment.

It’s perfectly possible to critique without being a bully.

What Theo and Linus are doing wrong is scaring away a large pool of potential contributors who don’t want to take that risk.

Re: Theo de Raadt: "You've been smoking something mind altering" (2007)

#16
post #6

"Torvalds, via e-mail, says De Raadt is “difficult” and declined to comment further." https://www.forbes.com/2005/06/16/linux-bsd-unix-cz_dl_0616t... Imagine being so hard you're labelled as "difficult" by no other but Linus Torvalds

I mean, Torvalds has called basically every person on earth an asshole at some point, hasn’t he? He’s the opposite of being sparing with critisicism, and frankly has historically often used his bully pulpit to do it.

My read on Torvalds is that, coming from him, "asshole" is a much lesser criticism than "difficult".

Re: Theo de Raadt: "You've been smoking something mind altering" (2007)

#17
post #13

One of his dumber takes. Virtualization replaces an ultra-functional general-purpose kernel evolved over decades to support every conceivable application with a drastically smaller "kernel" (KVM and the userland hypervisor). It's a drastic attack surface reduction, and the empirical data bears that out: kernel LPEs aren't even newsworthy (there's whole repos full of unnamed, unremarked-upon LPEs), and KVM escapes are…

How big is the OpenBSD kernel and userland actually compared to a virtualization layer?

Re: Theo de Raadt: "You've been smoking something mind altering" (2007)

#18
post #13

One of his dumber takes. Virtualization replaces an ultra-functional general-purpose kernel evolved over decades to support every conceivable application with a drastically smaller "kernel" (KVM and the userland hypervisor). It's a drastic attack surface reduction, and the empirical data bears that out: kernel LPEs aren't even newsworthy (there's whole repos full of unnamed, unremarked-upon LPEs), and KVM escapes are…

Doesn't that message date back to a time that either predates or is almost concurrent with the introduction of x86 hardware-assisted virtualization? I wasn't around playing with VMs back then, but I'm not sure that the track record of x86 virtualization 20 years ago was that great.

Re: Theo de Raadt: "You've been smoking something mind altering" (2007)

#19
post #13

One of his dumber takes. Virtualization replaces an ultra-functional general-purpose kernel evolved over decades to support every conceivable application with a drastically smaller "kernel" (KVM and the userland hypervisor). It's a drastic attack surface reduction, and the empirical data bears that out: kernel LPEs aren't even newsworthy (there's whole repos full of unnamed, unremarked-upon LPEs), and KVM escapes are…

I'm anti virtualization, but mostly due to the internal complexities of the guest applications being swept under the rug, it's undeniable that the host is protected and thus neighbouring guests (of course it is with almost 20 years of hindsight I can say this.)

That the hypervisor is effectively an operating system/kernel I have always held, and that it is a smaller and thus less vulnerable kernel is an appropriate explication I think. It's very hard to secure an all purpose kernel like Linux without actually building it yourself (and even then..)

Re: Theo de Raadt: "You've been smoking something mind altering" (2007)

#20
> A simple tool was presented, iofuzz, that exposes exploitable security flaws in most, if not all, virtual machines available today. To the knowledge of the author, no similar research has been conducted before. The results produced by crashme, a tool well known for over a decade, locating trivial flaws dem- onstrates this. No virtual machine tested was robust enough to withstand the testing procedure used, and multiple exploitable flaws were presented that could allow an attacker restricted to a vir- tualised environment to reliably escape onto the host system. The results obtained demonstrate the need for further research into virtualisation security and prove that virtualisa- tion is no security panacea.

https://taviso.decsystem.org/virtsec.pdf

He’s not wrong based on the research at the time. The mistake is presenting this as if it’s something that will be true for all time. Is virtualization a panacea? No. CPU manufacturers can’t even protect against side channel attacks. But it’s completely missing what this provides which is that the difficulty and cost of creating an exploit is higher today than 20 years ago. And it’s amusing to hear someone blasting away at the security of others when BSD has its own share of problems and architectural weaknesses are discovered through popularity of your system being an attack target, not because you’re smarter than everyone else and made better choices (sometimes it can be true in places, but harder to maintain for a big piece of software like an OS)

Post reply on HN