Live data from Hacker News

EU study recommends OpenBSD

undeadly.org

141–150 of 153 posts

Re: EU study recommends OpenBSD

#141

Earlier quoted context omitted.

He is actually more or less correct in the case of both Microsoft and Apple.

You know that's not true.

I know it is true, and I know you probably know people who work(ed) there, and they'll confirm it. This isn't because there aren't good security people who want to do the right thing, it's because management and PR doesn't support it.

You'll notice that the recent TLS bulletins were the only ones to credit an internal finder. There's a reason for that, and it's not because MS people aren't finding vulns in their own software.

Re: EU study recommends OpenBSD

#142

Earlier quoted context omitted.

You know that's not true.

I know it is true, and I know you probably know people who work(ed) there, and they'll confirm it. This isn't because there aren't good security people who want to do the right thing, it's because management and PR doesn't support it. You'll notice that the recent TLS bulletins were the only ones to credit an internal finder. There's a reason for that, and it's not because MS people aren't finding vulns in their own…

You're here arguing that Apple traded zero-days to NSA in order to get Apple Pay contracts with USG. At what level am I supposed to take this thread seriously?

My issue is that the comment that roots this thread is, as you discreetly agree, totally uninformed, yet written in a tone suggesting direct knowledge of how vulnerabilities are handled at big software companies.

If you want to discuss the subtleties of internal vs. external reporters, patch timelines, prioritization, pre-disclosure, and things like that, I'm up for it, but not until there's clarity about what --- let's call it: --- "the HN community" --- does and does not know about this stuff.

I am fine with random commenters on HN talking about vuln disclosure without ever having reported a vulnerability or triaged a report. I don't think our having spent so much time with those things makes us special. I am less fine with people pretending to know things that they don't, or, to be as charitable as I can, writing comments that carelessly create that impression.

Re: EU study recommends OpenBSD

#143

Earlier quoted context omitted.

I know it is true, and I know you probably know people who work(ed) there, and they'll confirm it. This isn't because there aren't good security people who want to do the right thing, it's because management and PR doesn't support it. You'll notice that the recent TLS bulletins were the only ones to credit an internal finder. There's a reason for that, and it's not because MS people aren't finding vulns in their own…

You're here arguing that Apple traded zero-days to NSA in order to get Apple Pay contracts with USG. At what level am I supposed to take this thread seriously? My issue is that the comment that roots this thread is, as you discreetly agree, totally uninformed, yet written in a tone suggesting direct knowledge of how vulnerabilities are handled at big software companies. If you want to discuss the subtleties of intern…

What? No. Hah. That comment is indeed ridiculous, and isn't the one I'm agreeing with. That appears to be a different thread. I'm only referring to:

Microsoft has had 2 Heartbleed-level vulnerabilities in its Windows code so far, that were not just 2-3 years old but 10+ years old, leaving systems vulnerable to them for much longer. The "advantage" of proprietary code here was that Microsoft got to downplay them (surprise surprise, no scary logo made by Microsoft for them!), and that's how proprietary code owners deal with security issues in general - they try to hide that they exist to keep the illusion that the software is (more) secure.

Related to the other claim, I'm fairly certain that the NSA does get pre-disclosure of MS vulns via MAPP, but it's pretty obvious that this is a side effect of disclosure complexities and not a quid pro quo deal. China also gets the same pre-disclosure, or did, until they got caught leaking it. But they probably still do, one way or another.

I'm actually laughing out loud at the Apple Pay in the USG thing.

Re: EU study recommends OpenBSD

#144

Earlier quoted context omitted.

You're here arguing that Apple traded zero-days to NSA in order to get Apple Pay contracts with USG. At what level am I supposed to take this thread seriously? My issue is that the comment that roots this thread is, as you discreetly agree, totally uninformed, yet written in a tone suggesting direct knowledge of how vulnerabilities are handled at big software companies. If you want to discuss the subtleties of intern…

What? No. Hah. That comment is indeed ridiculous, and isn't the one I'm agreeing with. That appears to be a different thread. I'm only referring to: Microsoft has had 2 Heartbleed-level vulnerabilities in its Windows code so far, that were not just 2-3 years old but 10+ years old, leaving systems vulnerable to them for much longer. The "advantage" of proprietary code here was that Microsoft got to downplay them (surp…

I don't think it's that funny anymore. It's funny until you realize lots of readers believe him.

If you want to roll the discussion up to the original claim on this thread:

* Yes, closed-source vendors, Google included, do not as a rule announce severe flaws they find (or contract to find) in their own code. On the other hand, when we're talking about Google, Microsoft, and Apple: they are actually finding sophisticated flaws in their own product, which is something very few open source projects can credibly claim.

* Open source projects are not as a rule particularly awesome about handling disclosures either. See, for instance, AFNetworking.

* Nobody made logos for HTTP.sys (that I know of). On the other hand, HTTP.sys was a bigger deal in the industry than POODLE or pretty much any other vuln with a name besides Heartbleed, which, because it implicated a library used by lots of products, was particularly prevalent among Internet SAAS sites, and was easier to quietly exploit than an RCE, was a legitimately more important flaw. The idea that Microsoft gets a free pass for vulns is something you can only believe if your only contact with them is HN.

* There's no evidence Microsoft hid those vulnerabilities. They were there for 10+ years because nobody found them. In Microsoft's case, you can't reasonably claim that's because they weren't looking. Minesweeper gets more pentesting effort at Microsoft than most open source crypto projects.

I strongly prefer open source software to closed-source software, but I'm not unrealistic about how open source security works. See security tire fires such as: OpenSSL, Rails, PHP, Cryptocat, BIND --- each distinctive not just for having vulns but for the manner in which they've historically handled them.

Re: EU study recommends OpenBSD

#145

Earlier quoted context omitted.

And by "a while", one means "a few days after discovery" (a few months after it was introduced , but that's actually not terrible, all things considered).

Fact check: It was introduced years priors to discovery, not mere months.

Thanks for the fact check!

Looks like it was indeed committed to OpenSSL about 2 1/2 years prior.

Re: EU study recommends OpenBSD

#146
post #81

Earlier quoted context omitted.

Yes, but forget monetary/labor contributions. I think jkyle has a point: the BSD license is a "no strings attached" license, and so it can be chosen by people who presumably don't even want to promote the software, advertise the fact they are using it or campaign for more software like it. If Theo De Raadt finds this disappointing, maybe he should choose a different license?

The problem is that de Raadt and crew have a much bigger priority: that OpenBSD's code proliferate and prevent any duplication of effort in creating secure programs. They've explicitly stated in the past that they consider proprietary use of their code to be a good thing (albeit it would be better if they'd push some money back to the OpenBSD crowd) because it prevents those companies from having to create yet anothe…

    The problem is that de Raadt and crew have a much bigger priority: that OpenBSD's code proliferate and prevent any duplication of effort in creating secure programs.
I think that's an excellent reason to use a BSD license. If you want to facilitate wide industry adoption that has zero resistance from legal departments, BSD is an obvious choice.

Re: EU study recommends OpenBSD

#147
post #75
post #74

Earlier quoted context omitted.

Politicians in EU and US call various institutions a "NGO" when they disagree with it and want to ridicule it to intentionally reduce its public reputation. EP is a high reputation organization and has force within the EU structure. Calling an EPRS study "something by the parliament's research service" is not only redundant (EPRS = European Parliament Research Service) but also short-sighted (do you do the same thing…

I wasn't dismissing the study's quality, just saying that this is not necessarily going to lead to any change in policy (e.g. all EU computers mandated to run OpenBSD).

> all EU computers mandated to run OpenBSD

That kind of social change would require a change in the econo-political system.

Re: EU study recommends OpenBSD

#148
post #2

Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Good to see the EU at least acknowledging that its something that they should explore. They probably use it and its features more than they realise. I suspect there is a strong political motive as well behind being "technologically independent" after the NSA mass surveillance revelations. I like the sound of…

> I like the sound of an EU BSD fork - hopefully they fund one. We've always been lacking in the Operating Systems dev department over here in Europe.

There's no need to fork and split manpower, you can contribute to OpenBSD being in Europe.

Re: EU study recommends OpenBSD

#149
post #4
post #2

Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Good to see the EU at least acknowledging that its something that they should explore. They probably use it and its features more than they realise. I suspect there is a strong political motive as well behind being "technologically independent" after the NSA mass surveillance revelations. I like the sound of…

> Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Sounds like he needs a different license then.

The only licence that will fix this is one that requires payment from users, and that's never going to happen.

Things like GPL don't force users to send back contributions unless you redistribute a derivate product (which is not usually the case). Theo is talking about giving something back (an acknowledgement, or even better, money).

Re: EU study recommends OpenBSD

#150
post #117

Earlier quoted context omitted.

I think from the BSD point of view, contributing back is seen more of a weak social obligation than a legal one. You contribute back because it's a nice thing to do for those giving you free stuff, not because of section 6 paragraph 1 of some ten page legal document. Asking people to consider it is the right thing to do. Switching license would defeat the entire point.

There probably exists lots of differing experience on this, but I've found it easier to get permission to contribute paid work on a tit-for-tat basis, because it alleviates the "why should we let our competitors use our work for free" question. I don't think that it is a coincidence that GPL led to Red Hat, a billion dollar support and services company, while BSD let to a multitude of hardware companies. The former i…

> I don't think that it is a coincidence that GPL led to Red Hat, a billion dollar support and services company, while BSD let to a multitude of hardware companies.

GPL isn't directly responsible for Red Hat. The popularity of GNU/Linux at the time (vs *BSD) of it's inception is responsible for that. Licence had nothing to do with it.

Post reply on HN