Live data from Hacker News

Buffer overruns, license violations, and bad code: FreeBSD 13’s close call

arstechnica.com

1–10 of 38 posts

Re: Buffer overruns, license violations, and bad code: FreeBSD 13’s close call

#2
So some Twitter grand inquisitors, whose names always seem to appear if individuals are targeted, discovered some unpleasant details about someone's past.

Code quality (especially when written under pressure) is unrelated to that and I've seen horrible code from from model citizens who check all the Twitter boxes of goodness.

It seems very dangerous to contribute to open source these days if you are not in the right Twitter cliques.

The nice thing is that the FreeBSD developers who were interviewed apparently remained fair and said that the target had produced high quality code before.

Re: Buffer overruns, license violations, and bad code: FreeBSD 13’s close call

#3
post #2

So some Twitter grand inquisitors, whose names always seem to appear if individuals are targeted, discovered some unpleasant details about someone's past. Code quality (especially when written under pressure) is unrelated to that and I've seen horrible code from from model citizens who check all the Twitter boxes of goodness. It seems very dangerous to contribute to open source these days if you are not in the right…

Best thing is to not use Twitter in the first place.

Re: Buffer overruns, license violations, and bad code: FreeBSD 13’s close call

#4
post #2

So some Twitter grand inquisitors, whose names always seem to appear if individuals are targeted, discovered some unpleasant details about someone's past. Code quality (especially when written under pressure) is unrelated to that and I've seen horrible code from from model citizens who check all the Twitter boxes of goodness. It seems very dangerous to contribute to open source these days if you are not in the right…

> It seems very dangerous to contribute to open source these days if you are not in the right Twitter cliques.

Nope. Lots of people contribute to Open Source without being in any Twitter cliques, they're just getting on with the work and doing their best.

One could also flip what you wrote, on its head and say "It seems very difficult to be visible in open source these days if you have been doing things that are illegal or frowned upon". It's the same thing, just without the persecution complex.

Re: Buffer overruns, license violations, and bad code: FreeBSD 13’s close call

#6
This does not paint FreeBSD in a good light.

“you either have a commit bit (enabling you to commit code to FreeBSD's repositories) or you don't. It's hard to find code reviews, and there generally isn't a fixed process ensuring that vitally important code gets reviewed prior to inclusion. This system thus relies heavily on the ability and collegiality of individual code creators.”

From my perspective, this whole thing is due to a severe failure of the development process. The sub-standard code should never have been committed. But if there is no process, is it really a failure? Or is this just how it is on FreeBSD?

Re: Buffer overruns, license violations, and bad code: FreeBSD 13’s close call

#7
post #6

This does not paint FreeBSD in a good light. “you either have a commit bit (enabling you to commit code to FreeBSD's repositories) or you don't. It's hard to find code reviews, and there generally isn't a fixed process ensuring that vitally important code gets reviewed prior to inclusion. This system thus relies heavily on the ability and collegiality of individual code creators.” From my perspective, this whole thin…

Ars seems to be calling all open source software insecure. I’m not saying they are wrong but what’s the value in their article? Is it gotcha journalism, or are they warning us not to trust bsd based systems in general. The article starts as a gotcha piece but concludes by saying there’s no review in place to catch these problems.

Re: Buffer overruns, license violations, and bad code: FreeBSD 13’s close call

#8
post #2

So some Twitter grand inquisitors, whose names always seem to appear if individuals are targeted, discovered some unpleasant details about someone's past. Code quality (especially when written under pressure) is unrelated to that and I've seen horrible code from from model citizens who check all the Twitter boxes of goodness. It seems very dangerous to contribute to open source these days if you are not in the right…

At least bad opinions on Twitter are not a crime... and you know, perhaps Ars shouldn’t bring it up, but it’s hard when they themselves refer to it as a personal set back. But even though I absolutely believe everyone deserves a second chance, I really find it hard to sympathize with a person who does what is alleged, doesn’t apologize (as far as I have heard), attempts to flee the charges, then has the gull to lament over how it has negatively impacted their career. At this point it feels like they are more upset about how they had to face consequences for their actions than anything else.

I don’t wish perpetual punishment on anyone for almost any reason. But still... it feels like some necessary self-improvement is sorely missing. I certainly say this as a person who is flawed and full of anti-patterns.

Re: Buffer overruns, license violations, and bad code: FreeBSD 13’s close call

#10
post #6

This does not paint FreeBSD in a good light. “you either have a commit bit (enabling you to commit code to FreeBSD's repositories) or you don't. It's hard to find code reviews, and there generally isn't a fixed process ensuring that vitally important code gets reviewed prior to inclusion. This system thus relies heavily on the ability and collegiality of individual code creators.” From my perspective, this whole thin…

Ars seems to be calling all open source software insecure. I’m not saying they are wrong but what’s the value in their article? Is it gotcha journalism, or are they warning us not to trust bsd based systems in general. The article starts as a gotcha piece but concludes by saying there’s no review in place to catch these problems.

> Ars seems to be calling all open source software insecure

> The article starts as a gotcha piece

Haha, that’s the problem. You, Netapp, value saving face so very much that you are incapable of constructive response to well-meaning, fair, and honest criticism.

Post reply on HN