Live data from Hacker News

OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative

linuxfoundation.org

11–20 of 94 posts

Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative

#11

Just give the money to the OpenBSD team. We saw with OpenSSH that they have a proven track record taking crappy security software and fixing it. Why does everyone have this aversion to giving the OpenBSD team the funding they deserve? And "Theo's a dick" doesn't qualify as a valid reason to not fund real security development. For the work those guys have done improving the security infrastructure of every operating s…

> Just give the money to the OpenBSD team

Unless OpenBSD decides to change, that is the way to fund OpenSSH. Currently you don't get to decide how your donations are spent by them, OpenSSH isn't it's own spinoff funded group.

Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative

#12

Just give the money to the OpenBSD team. We saw with OpenSSH that they have a proven track record taking crappy security software and fixing it. Why does everyone have this aversion to giving the OpenBSD team the funding they deserve? And "Theo's a dick" doesn't qualify as a valid reason to not fund real security development. For the work those guys have done improving the security infrastructure of every operating s…

> And "Theo's a dick" doesn't qualify as a valid reason to not fund real security development. Yeah, but people who give money usually tend to see that as a valid reason.

Seems to have worked out for Torvalds and good chunks of the Web ecosystem.

Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative

#13
post #8

Just give the money to the OpenBSD team. We saw with OpenSSH that they have a proven track record taking crappy security software and fixing it. Why does everyone have this aversion to giving the OpenBSD team the funding they deserve? And "Theo's a dick" doesn't qualify as a valid reason to not fund real security development. For the work those guys have done improving the security infrastructure of every operating s…

Actually if I'm giving someone a donation, charity, then whether they are or are not a dick is a perfectly valid part of the decision. And to me how you run a project is as important as the quality of the final result.

You don't have to have a reason to not donate to something, so the color of their shoes is also a perfectly valid part of the decision. The important question is whether it's a good reason. If you rank the style of his speech as a more important issue than having secure software (unless you think that the style of speech will negatively effect the software), I'd wonder how a single person's personality got so high on your list of priorities.

It sounds a bit like voting for a president because he's the guy you feel you'd most enjoy having a beer with: short-sighted.

Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative

#14
post #5

It is possible the OpenSSH funding, since it is done through the OpenBSD Foundation, could, at the Foundation's discretion, go toward LibreSSL, since it's the same group.

No it's not. Libressl is a different team; one that feels a fork was more appropriate than just fixing the problems in openssl.

IMHO, libressl is a mistake. It's splitting resources over something that needs to be as air-tight as possible. I'd much rather have 1 really really good ssl library that everyone uses instead of 2 so-so ones.

Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative

#16

Just give the money to the OpenBSD team. We saw with OpenSSH that they have a proven track record taking crappy security software and fixing it. Why does everyone have this aversion to giving the OpenBSD team the funding they deserve? And "Theo's a dick" doesn't qualify as a valid reason to not fund real security development. For the work those guys have done improving the security infrastructure of every operating s…

Why does everyone have this aversion to giving the OpenBSD team the funding they deserve?

One reason may be that donations to the OpenBSD Foundation are not tax-deductible in the US.

Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative

#17
post #6

I'm actually looking forward to seeing how the OpenSSL problem will deal with their own legacy code, compared to how the OpenBSD developers have handled it. It seems that own of the only ways of dealing with the OpenSSL code is to strip out the code for a large number of, should we say "less used platforms". Is the OpenSSL developers willing to drop support for 16 bit Windows or OpenVMS?

Is the OpenSSL developers willing to drop support for 16 bit Windows or OpenVMS?

They either need to properly maintain it or drop it, and they don't have enough money to maintain it.

Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative

#18
post #17
post #6

I'm actually looking forward to seeing how the OpenSSL problem will deal with their own legacy code, compared to how the OpenBSD developers have handled it. It seems that own of the only ways of dealing with the OpenSSL code is to strip out the code for a large number of, should we say "less used platforms". Is the OpenSSL developers willing to drop support for 16 bit Windows or OpenVMS?

Is the OpenSSL developers willing to drop support for 16 bit Windows or OpenVMS? They either need to properly maintain it or drop it, and they don't have enough money to maintain it.

I just want to know who's still compiling against 16bit windows or OpenVMS. I know my world view isn't infinite, but those systems seem a bit out there.

Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative

#19

When the missing funding of OpenSSL was discussed, it came up several times, that OpenSSH, while doing great, is quite underfunded, too. I am glad to see them getting some money. What i can't really comment on myself, but am reading from the OpenBSD guys is, that the OpenSSL team does quite well with FIPS consulting and has no increased interest in improving the library.[0] Even if those claims are not true, it would…

Straight from the horse's mouth[1]

> Also, the income they earn though their paid consulting work supports their unpaid work on OpenSSL, so by hiring OpenSSL team members you are not only solving your own problems but also helping to ensure the long term viability of the OpenSSL product.

They also on their website list hourly consulting starting at $250/hour. Neither of these describe how much they get out of this, but it seems reasonable to say that the "OpenSSL runs of $2k/year" line is disingenuous at best.

[1] http://www.openssl.org/support/consulting.html

Re: OpenSSL, OpenSSH and NTP to receive support from Core Infrastructure Initiative

#20
post #14
post #5

It is possible the OpenSSH funding, since it is done through the OpenBSD Foundation, could, at the Foundation's discretion, go toward LibreSSL, since it's the same group.

No it's not. Libressl is a different team; one that feels a fork was more appropriate than just fixing the problems in openssl. IMHO, libressl is a mistake. It's splitting resources over something that needs to be as air-tight as possible. I'd much rather have 1 really really good ssl library that everyone uses instead of 2 so-so ones.

> No it's not. Libressl is a different team

OpenSSH and LibreSSL are both a part of OpenBSD. So when you donate to the OpenBSD Foundation, you are very much donating to one project.

> one that feels a fork was more appropriate than just fixing the problems in openssl

You can't start fixing things in other peoples' source tree just like that. I'm pretty sure nothing useful would've come out of it if the OpenBSD folk had sent half a million lines in diffs to OpenSSL; http://www.openbsd.org/papers/bsdcan14-libressl/mgp00026.htm...

Post reply on HN