Live data from Hacker News

EU study recommends OpenBSD

undeadly.org

121–130 of 153 posts

Re: EU study recommends OpenBSD

#121
post #49

I love openBSD, it's implementation of certain things is slower (like networking), but it's so clean and well implemented. even if it doesnt' get to play with all the toys (like ZFS) it's what I'd love to default to for application servers/bastion server/firewalls etc; my only qualm with it currently is it's reliance of X11 for ports to work- I don't like install X11 libs on my servers wherever I can avoid it. :\

At least with packages, there are "no-X" versions of most packages available (useful if you don't have X on a machine).

the problem isn't that it's dependant for X11 on packages.. moreso that the port system requires X11 to function..

http://comments.gmane.org/gmane.os.openbsd.ports/54692

http://www.openbsd.org/faq/faq15.html#NoFun (at the bottom of this section)

Re: EU study recommends OpenBSD

#122
post #29

"[...] the use of open source computer operating systems and applications reduces the risk of privacy intrusion by mass surveillance. Open source software is not error free, or less prone to errors than proprietary software, the experts write. But proprietary software does not allow constant inspection and scrutiny by a large community of experts." That worked great for OpenSSL didn't it? ;)

Microsoft has had 2 Heartbleed-level vulnerabilities in its Windows code so far, that were not just 2-3 years old but 10+ years old, leaving systems vulnerable to them for much longer. The "advantage" of proprietary code here was that Microsoft got to downplay them (surprise surprise, no scary logo made by Microsoft for them!), and that's how proprietary code owners deal with security issues in general - they try to…

This is the second time today you've spread innuendo about how software security teams at big companies handle vulnerabilities, and the second time you've managed to casually insult teams that include some of the best software security people in the entire industry.

Here's the first:

https://news.ycombinator.com/item?id=9445436

These are egregiously bad arguments you're making, involving people who you don't know but that, from my experience reading so many of your comments, I believe are operating many levels above your own comfort level with actual software security.

The trouble is, like me, you comment on HN all the time, and so, like me, you get a huge name recognition boost for these comments you make. People reasonably believe that you know what you're talking about when you "explain" to them how Apple and Microsoft handle vulnerabilities. But you don't, and so these misleading comments prey on their lack of information.

Re: EU study recommends OpenBSD

#123
post #84

Earlier quoted context omitted.

That still only goes so far, though. If you're building a product on top of a database that's licensed with the AGPL, like Mongo, you have to distribute those changes.* If you build your Intranet site on Mongo, though, you don't need to distribute those changes in a way that gets back to upstream. * I think. And I don't know if this has withstood the sort of court scrutiny the GPL has.

For the intranet site, I think you'd still need to make the source code available to users, who could then make the source publicly available. IANAL, though, so I don't know if corporate policy forbidding this would be legal under the terms of the AGPL.

>I don't know if corporate policy forbidding this would be legal under the terms of the AGPL

Section 10 of both the GPLv3 and AGPLv3 prevent the imposition of "further restrictions" on the subject of the license.

Re: EU study recommends OpenBSD

#124

Earlier quoted context omitted.

For the intranet site, I think you'd still need to make the source code available to users, who could then make the source publicly available. IANAL, though, so I don't know if corporate policy forbidding this would be legal under the terms of the AGPL.

>I don't know if corporate policy forbidding this would be legal under the terms of the AGPL Section 10 of both the GPLv3 and AGPLv3 prevent the imposition of "further restrictions" on the subject of the license.

I'm aware. What's not clear is whether applies to the individual components of an organization (i.e. its employees) or just the organization as a whole. I want to think the answer is that intra-organizational distribution still counts as distribution (and therefore cannot be restricted), but usually it's considered acceptable to use a modified version of (A)GPL'd software internally (i.e. not used outside the organization) without it counting as "distribution", so things are kind of fuzzy without explicit terms in that regard.

Such are the side-effects of treating organizations as singular entities :)

Re: EU study recommends OpenBSD

#125
post #23
post #19

Earlier quoted context omitted.

Interesting! Could you elaborate some more and perhaps list a few projects, if you're allowed to?

I primarily know about the projects listed at https://www.fokus.fraunhofer.de/809f10db25eddf3e/projects A personal observation is that, nowadays, gitlab seems to be preferred to github as part of a push to rely more on software developed inside the EU (guess it's an aftermath of the whole NSA story). PolicyCompass, for example, lives at https://github.com/policycompass Carneades lives at http://github.com/carneades M…

This has to be taken with a grain of salt. Frauenhofer in particular is rather "patent focused" and I think it carries over to their (there's a lot of Frauenhofers...overgeneralizing) general view on software. It's only anecdotal evidence from being at some research matchmaking events (Horizon 2020 etc.) and working in that field.

That being said OpenSource is explicitly mentioned in many calls. I'm mostly working on country specific calls but they are usually constructed similarly. OpenSource is often mentioned as a "potential use after the project" or a "result". Interestingly the provided headlines for calls will often read like this: "Potential use (for example OpenSource, patents, marketable product)" :D

+Actual software development usually isn't the goal of research projects. In the EU they use maturity levels (initially from the aviation industry I think) and it's quite a bit more "actual software/solutions" focused than the country specific calls (by design). Overall anyone who has worked in software development or even better at a startup would get a good chuckle out of these research funding events and the general process btw. (my personal opinion).

Re: EU study recommends OpenBSD

#126
post #69

Earlier quoted context omitted.

I don't think that would make them likely to contribute back, they'd just use something else. He'd rather have selfish people using good software than choosing to use something inferior.

Somehow Google, Samsung, and Intel are sticking the Linux kernel in everything despite it being GPL'd and them having to release their modifications. Might have something to do with how reengineering the Linux kernel would cost on the order of billions of dollars in engineer time.

Just look at how many Android vendors actually honor the GPL. Even the major vendors tend to mess up their source code dumps, and lots of the Chinese (hi Mediatek) vendors don't even react on emails.

Google should require in the vendor license terms for the Android brand and the Play Store that the sources be released on Github.

Re: EU study recommends OpenBSD

#127

Earlier quoted context omitted.

Microsoft has had 2 Heartbleed-level vulnerabilities in its Windows code so far, that were not just 2-3 years old but 10+ years old, leaving systems vulnerable to them for much longer. The "advantage" of proprietary code here was that Microsoft got to downplay them (surprise surprise, no scary logo made by Microsoft for them!), and that's how proprietary code owners deal with security issues in general - they try to…

This is the second time today you've spread innuendo about how software security teams at big companies handle vulnerabilities, and the second time you've managed to casually insult teams that include some of the best software security people in the entire industry. Here's the first: https://news.ycombinator.com/item?id=9445436 These are egregiously bad arguments you're making, involving people who you don't know but…

The above comment isn't attacking "teams with great software security people" but the fact that in proprietary software people can and do downplay vulnerabilities (not a very controversial statement).

I've noticed tptacek over the past few years that your comments have shifted from great general security advice to more defending "the security profession". Please consider this shift and whether it is helpful.

Re: EU study recommends OpenBSD

#128

Earlier quoted context omitted.

This is the second time today you've spread innuendo about how software security teams at big companies handle vulnerabilities, and the second time you've managed to casually insult teams that include some of the best software security people in the entire industry. Here's the first: https://news.ycombinator.com/item?id=9445436 These are egregiously bad arguments you're making, involving people who you don't know but…

The above comment isn't attacking "teams with great software security people" but the fact that in proprietary software people can and do downplay vulnerabilities (not a very controversial statement). I've noticed tptacek over the past few years that your comments have shifted from great general security advice to more defending "the security profession". Please consider this shift and whether it is helpful.

Is your assessment that "in proprietary software people can and do downplay vulnerabilities" based on looking at HN/news stories, or based on directly interacting with security teams at those companies?

In my experience, the worst security offenders are either small businesses or big businesses whose core competency is not in tech. My friend managed to download 50,000 passwords from GreatestJournal.com because they left their MySQL server exposed to the Internet, with no password, and the open-source LiveJournal code stored passwords in plain text in the DB. He reported the vulnerability to them, and their response was to put a password on the MySQL server (and take it off the Internet a few days later), write a blog post saying "You may want to change your passwords if you reuse your GJ.com password on other sites", and then take down that blog post a couple days later.

By contrast, when I worked at Google, a security bug was a drop-everything P0 bug. I recall grabbing dinner at In'n'Out at 11:00 PM because a potential data leak was discovered at 6:00 and the culture is such that when a potential security bug is discovered, you drop what you're doing, assess the impact, fix it, and don't do anything else until you've done that. And I didn't work on a security team, just an infrastructure one responsible for google.com.

Re: EU study recommends OpenBSD

#129

Earlier quoted context omitted.

This is the second time today you've spread innuendo about how software security teams at big companies handle vulnerabilities, and the second time you've managed to casually insult teams that include some of the best software security people in the entire industry. Here's the first: https://news.ycombinator.com/item?id=9445436 These are egregiously bad arguments you're making, involving people who you don't know but…

The above comment isn't attacking "teams with great software security people" but the fact that in proprietary software people can and do downplay vulnerabilities (not a very controversial statement). I've noticed tptacek over the past few years that your comments have shifted from great general security advice to more defending "the security profession". Please consider this shift and whether it is helpful.

If tptacek's attitude has shifted, it's probably because the prevailing attitude on HN has shifted as well, in the direction of "never have people cared so much yet known so little".

Re: EU study recommends OpenBSD

#130
post #120
post #85

Earlier quoted context omitted.

> my only qualm with it currently is it's reliance of X11 for ports to work- I don't like install X11 libs on my servers wherever I can avoid it. :\ Can you give a reference to this? I'm not doubting you, as I always install x11 anyway, I just didn't know this was still the case. I remember an issue with a lib in xbase.tgz a few years back that was required by lots of ports, but I thought they moved it to base.tgz. T…

http://comments.gmane.org/gmane.os.openbsd.ports/54692 http://www.openbsd.org/faq/faq15.html#NoFun (at the bottom of this section)

Good call. I was thinking packages in my head despite you specifically referring to ports. Thanks for following up!
Post reply on HN