Live data from Hacker News

Linus Torvalds Interview for LinuxFR

linuxfr.org

21–30 of 57 posts

Re: Linus Torvalds Interview for LinuxFR

#21
post #12

Earlier quoted context omitted.

Maybe I'm missing your answer there ... You just say: Still there is good reason that browsers rub it in the users face when a site tries to use a self-signed certificate but I don't see where you say what that good reason is. If a self-signed cert is more secure than plain HTTP, why make a self-signed cert more painful to use than plain HTTP?

Because with HTTP, there is no assumption of security at the side of the user, or at least there shouldn't be. With HTTPS (and the "lock symbol") there is. The people that really know what they're doing can click through the warnings and still do what they want. But casual users that assume https=safe have the chance to leave. I'm all for deprecating HTTP the same way they did with TELNET, and warning the user for ev…

The browser could just not show the "secure" visuals, instead of making us click through another page.

Re: Linus Torvalds Interview for LinuxFR

#22
Because ethics are to me something private. Whenever you use it as an argument for why somebody_else should do something, you're no longer being ethical, you're just being a sanctimonious dick-head.

For someone who is not a native English speaker, Linus really has an awesome way with words.

Re: Linus Torvalds Interview for LinuxFR

#23
post #22

Because ethics are to me something private. Whenever you use it as an argument for why somebody_else should do something, you're no longer being ethical, you're just being a sanctimonious dick-head. For someone who is not a native English speaker, Linus really has an awesome way with words.

At least it's clear what he's saying, but I was surprised at this -- it puts Linus well and truly in the postmodern camp. He says ethics are completely relative and personal. (Which of course is not the case: if I try to kill someone, the cops aren't being "sanctimonious dick-heads" when they stop me.) Anyway, all this is off topic, but I was just surprised at Linus's relativism when he seems so "absolutist" about many other things, for example, how much C++ sucks.

Edit: OTOH, Linus is talking in the context of software licenses -- I agree with him that it can get holier-than-thou the way some folks push the GPL (not least its original author).

Re: Linus Torvalds Interview for LinuxFR

#24
post #22

Because ethics are to me something private. Whenever you use it as an argument for why somebody_else should do something, you're no longer being ethical, you're just being a sanctimonious dick-head. For someone who is not a native English speaker, Linus really has an awesome way with words.

He doesn't have a way with words unless "being rude" now means "having a way with words". Furthermore, his statement is logically incorrect (the best kind of incorrect): the sense of right and wrong is a general human trait, independent of race or culture. It can be altered by nurture, but it transcends it.

One can very well use it as an argument for why somebody else should or should not do something. e.g: One should not throw a hard-disk at Linus Torvalds because they might hurt him and that's just wrong...

Re: Linus Torvalds Interview for LinuxFR

#25
post #21

Earlier quoted context omitted.

Because with HTTP, there is no assumption of security at the side of the user, or at least there shouldn't be. With HTTPS (and the "lock symbol") there is. The people that really know what they're doing can click through the warnings and still do what they want. But casual users that assume https=safe have the chance to leave. I'm all for deprecating HTTP the same way they did with TELNET, and warning the user for ev…

The browser could just not show the "secure" visuals, instead of making us click through another page.

Well, the warnings are only shown once. Once you import the self-signed certificate into your keystore, it never bothers you again (unless the certificate changes).

This is the right workflow you should follow with self-signed certificates, it is similar to SSH. You need to accept the certificate once. After manually verifying it is the right one, you're even more secure than trusting on a CA...

Re: Linus Torvalds Interview for LinuxFR

#26
post #19
post #10

Earlier quoted context omitted.

Granted, it doesn't provide as much protection as a cert signed by a trusted CA - but it's still far more protection than plain HTTP, right? e.g, Firesheep wouldn't work I don't know if browsers do this, but in principle they could even notify the user on certificate change, so the MITM would have to be on the first connection to a site.

Introducing a "third state" for the SSL indicator, usability-wise, is very difficult. A lot of browser users don't understand SSL, and those that do have a binary understanding of the protocol: it can be used to either confirm or refute the identity of a website. It's very difficult to implement a UI for the regular users that says: "this might be a MITM attack since I cannot confirm the identity of the site but at l…

[deleted]

Re: Linus Torvalds Interview for LinuxFR

#27
post #21

Earlier quoted context omitted.

The browser could just not show the "secure" visuals, instead of making us click through another page.

Well, the warnings are only shown once. Once you import the self-signed certificate into your keystore, it never bothers you again (unless the certificate changes). This is the right workflow you should follow with self-signed certificates, it is similar to SSH. You need to accept the certificate once. After manually verifying it is the right one, you're even more secure than trusting on a CA...

It's a usability problem. Firefox (at least 3.x) does a full-on freak-out if the cert is untrusted, despite the fact that the site is no more unsafe than an unencrypted website.

Your statements about what should happen are only true if you are requiring encryption for everything that you do. On the web, it's assumed (although most people don't actually know this) that your information is not secure unless you see the green bar or whatever the security visual is on your particular browser.

This brings me back to smanek's point. We have three levels of security: no SSL, untrusted cert, trusted cert. Nothing about the first level is superior to the second level, except for the possibility of a false sense of security. Therefore, a browser should not freak out more in the second situation.

Re: Linus Torvalds Interview for LinuxFR

#28
post #22

Because ethics are to me something private. Whenever you use it as an argument for why somebody_else should do something, you're no longer being ethical, you're just being a sanctimonious dick-head. For someone who is not a native English speaker, Linus really has an awesome way with words.

"Dick" is a common nickname for people named "Richard". Considering who is most well known for making ethics arguments in the FLOSS world, could Linus be perpetrating a pun here?

Re: Linus Torvalds Interview for LinuxFR

#29
post #24
post #22

Because ethics are to me something private. Whenever you use it as an argument for why somebody_else should do something, you're no longer being ethical, you're just being a sanctimonious dick-head. For someone who is not a native English speaker, Linus really has an awesome way with words.

He doesn't have a way with words unless "being rude" now means "having a way with words". Furthermore, his statement is logically incorrect (the best kind of incorrect): the sense of right and wrong is a general human trait, independent of race or culture. It can be altered by nurture, but it transcends it. One can very well use it as an argument for why somebody else should or should not do something. e.g: One shoul…

> the sense of right and wrong is a general human trait, independent of race or culture.

If you're talking about the fact that every culture has notions of right and wrong, yeah sure.

If you're saying that what is right and what is wrong is universal and not cultural ... Well where to begin

Some of thoses traits are shared amongst most cultures (Murder is wrong, incest is wrong), but even there there are exceptions (ritual murder ?). For anything more complicated than that, this position is simply impossible to hold.

Most precisely, about property, intellectual or physical, and things like profit, the sense of right and wrong varies so wildly amongst cultures that i can't really think you're making this argument seriously.

Re: Linus Torvalds Interview for LinuxFR

#30
post #23
post #22

Because ethics are to me something private. Whenever you use it as an argument for why somebody_else should do something, you're no longer being ethical, you're just being a sanctimonious dick-head. For someone who is not a native English speaker, Linus really has an awesome way with words.

At least it's clear what he's saying, but I was surprised at this -- it puts Linus well and truly in the postmodern camp. He says ethics are completely relative and personal. (Which of course is not the case: if I try to kill someone, the cops aren't being "sanctimonious dick-heads" when they stop me.) Anyway, all this is off topic, but I was just surprised at Linus's relativism when he seems so "absolutist" about ma…

To reiterate, even if murder is universally considered as being wrong, other issues such as property, copyright, profit and a lot of other things are treated extremely differently in different cultures.

So it's as easy to find something we all mostly agree on (murder) than something we all mostly disagree on (property).

Also taking the murder example is quite dishonest. Linus wasn't talking about murder issues. He was talking about intellectual property issues. Do you claim there is objective right and wrong in this domain ? Do you claim to know what it is ?

EDIT : Didn't see your edit, so correction about the "dishonest argument" part :)

Post reply on HN