Live data from Hacker News

Undisclosed hole in openssh on FreeBSD and Juniper?

thread.gmane.org

41–47 of 47 posts

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#41
post #40
post #34

Earlier quoted context omitted.

This is vintage Theo. It has the virtue of sounding correct, but, because OpenBSD ships threaded libraries, it probably lacks the virtue of being correct. I had a similar experience (note, though: I have a history with Theo, who I know/knew personally). When I was at Arbor Networks, we shipped appliances that monitored ISP backbones that were based on OpenBSD. An analysis process that happened to allocate a lot of me…

What happened next? Did the bug get fixed? Did you do a work-around somehow? Don't leave stories unfinished like this :)

I actually don't know. Arbor could have had its dev team hunt for a fix for the bug, but that would have been silly; no way did it make sense for them to take ownership of a custom fork of the most complicated kernel subsystem. So we worked around the problem instead.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#42
post #34

Many years ago, I submitted a bug report to OpenBSD about an issue I had discovered with threads. I received a one line response from Theo. I still have the mail. He wrote: "Threads are for idiots." At the time, I felt discounted and I was upset. I was younger then. Today, I realize what he meant and that he's right.

This is vintage Theo. It has the virtue of sounding correct, but, because OpenBSD ships threaded libraries, it probably lacks the virtue of being correct. I had a similar experience (note, though: I have a history with Theo, who I know/knew personally). When I was at Arbor Networks, we shipped appliances that monitored ISP backbones that were based on OpenBSD. An analysis process that happened to allocate a lot of me…

I don't see how his response was unreasonable.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#43
post #34

Earlier quoted context omitted.

This is vintage Theo. It has the virtue of sounding correct, but, because OpenBSD ships threaded libraries, it probably lacks the virtue of being correct. I had a similar experience (note, though: I have a history with Theo, who I know/knew personally). When I was at Arbor Networks, we shipped appliances that monitored ISP backbones that were based on OpenBSD. An analysis process that happened to allocate a lot of me…

I don't see how his response was unreasonable.

It helps to understand the role a virtual memory system has in an operating system kernel.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#44
post #34

Many years ago, I submitted a bug report to OpenBSD about an issue I had discovered with threads. I received a one line response from Theo. I still have the mail. He wrote: "Threads are for idiots." At the time, I felt discounted and I was upset. I was younger then. Today, I realize what he meant and that he's right.

This is vintage Theo. It has the virtue of sounding correct, but, because OpenBSD ships threaded libraries, it probably lacks the virtue of being correct. I had a similar experience (note, though: I have a history with Theo, who I know/knew personally). When I was at Arbor Networks, we shipped appliances that monitored ISP backbones that were based on OpenBSD. An analysis process that happened to allocate a lot of me…

In the beginning, when Theo was cast out of NetBSD, someone rewrote this thing

http://www.skrause.org/humor/poohgoesapeshit.shtml

with Theo and other BSD-ish personalities as the characters. There are many stories of prickly people mellowing with age. It's unlikely there'll be such a story about him.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#45
post #5

What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.

I can see that you have not interacted with Theo before. Sometimes these things are just all personality.

I've not yet had the pleasure, but despite the insight lholden's shared about the contentious relationship between the BSDs, I have a really hard time believing anyone in this industry would be so petty.

Its clear, however, that the only way to get to the bottom of this is to become a big contributor to OpenSSH.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#46
post #43

Earlier quoted context omitted.

I don't see how his response was unreasonable.

It helps to understand the role a virtual memory system has in an operating system kernel.

Its also important to choose your security battles. I imagine there was another severe bug or two in a project as large as OpenBSD.

That being said, thats a petty and ridiculous reason not to deal with someone's code. This gentleman strikes be as a builder, not a maintainer; someone who wants to breeze through town like a cowboy, bring cool ideas to fruition, and move on to the next conquest while someone else keeps the system from falling apart. Thats not a judgment, we need people like that, but they probably shouldn't be the ones fielding emails.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#47
post #19
post #5

What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.

Short Answer: Bitterness. Long Answer: It's complicated and I do not understand the whole picture myself. I can however outline two things that likely exasperate the situation. a) OpenSSH is used by nearly everyone. Nearly every unix-like installation includes a copy of OpenSSH. Most companies which do business on the internet use a unix-like operating system in some way. The OpenBSD Foundation has had trouble obtain…

Thank you for sharing your insight.
Post reply on HN