Earlier quoted context omitted.
And the other guy's reply: http://seclists.org/oss-sec/2017/q2/597
"Days of our lives" Linux kernel edition. Do many people have a taste for kernel drama and Linus antics? I mostly just want the software.
Linus: Don't bother with grsecurity. Their patches are pure garbage
81–90 of 172 posts
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#82Earlier quoted context omitted.
Don't count on this recount to be correct but as far I've followed it: 200x? - grsecurity patchset is introduced and fixes a lot of bug-classes (!) and introduces lot's of security improvements to the kernel that are ground breaking and find their way in other systems like *BSD / Windows 200x-201x - code and trademarks of grsecurity get ripped from embbedded vendors - Linux foundations does nothing because they don't…
>they produced ground breaking research and it got ripped of everywhere. This is the part I don't get. They produced ground breaking research on a GPL platform, what did they expect to happen?
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#83Earlier quoted context omitted.
And the other guy's reply: http://seclists.org/oss-sec/2017/q2/597
"Days of our lives" Linux kernel edition. Do many people have a taste for kernel drama and Linus antics? I mostly just want the software.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#84Guess you lack the level of abstraction capabilities I expect. Sure. The parable is just about lies and not signals and noises. All Linus rants are full of information. He is a brilliant programmer. Everything he screams and shouts about is always correct. He has never confused a raccoon with a wolf.
I even specifically said that I agree that we need less difficult personalities in kernel development. It's quite ironic that you then followed up the way you did.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#85Earlier quoted context omitted.
>they produced ground breaking research and it got ripped of everywhere. This is the part I don't get. They produced ground breaking research on a GPL platform, what did they expect to happen?
This is, as I understand it, the core of the thing. They're making derivative works of a GPL work. They don't get to have it both ways. There's nothing for the Linux Foundation to go after, and they wouldn't be able to even if there was because they don't have the copyright for grsecurity's stuff.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#86Earlier quoted context omitted.
> their toxic communications If you can't handle the truth, then every truhful communication can be "toxic" to you.
If you speak the truth like an asshole all anyone will take away from it is that you're an asshole.
I mean, somebody can give you a block on gold unpolished and unwrapped. Sure, you can say, "How dare you give me that gold unwrapped! There is no way I am taking it. I demand you give that wrapped up property in fancy paper and tied with a ribbon." Sure you can say that. But the loss will be all yours. You got the shit anyway and gained no gold...
So the point is, if it the speaker who has to gain something by getting their point across, sure. They will have to be diplomatic. But when someone, halfway across the world is teaching you something from their ridiculously singular experience, seemingly in a rude way...
You shut up and listen.
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#87Reading one of the follow-up e-mail http://seclists.org/oss-sec/2017/q2/586 Wouldn't it be nice if you didn't demand free work of us in our free time? seems an odd line, but is there some context for the non-Linux person on what is going on?
Spender (and PaXTeam) has consistently claimed for many years that although he owns a software company whose sole product is a kernel patchset (and they are the only people who develop that patchset) that all grsecurity work is done in their free time. Which means that nobody (including their paying customers) is paying them for grsecurity development.
This usually comes up when Spender wants to claim that Linux has a lot of money in its development and that it is unreasonable that he, the poor developer he is, should work on upstreaming his patches. Personally it always struck me as dishonest.
I recently had an argument with them about this, which was "fun"[1].
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#88Earlier quoted context omitted.
> their toxic communications If you can't handle the truth, then every truhful communication can be "toxic" to you.
Excuse typos from phone...A quote from Randy pausch (0) last lecture(1) "And he put his arm around my shoulders and we went for a little walk and he said, Randy, it’s such a shame that people perceive you as so arrogant. Because it’s going to limit what you’re going to be able to accomplish in life. What a hell of a way to word “you’re being a jerk.” [laughter] Right? He doesn’t say you’re a jerk. He says people are…
> it’s going to limit what you’re going to be able to accomplish in life...
Sure. But the counter point is that it is also going to limit what you can learn (and hence achieve) if you are only willing to take lessons wrapped in fancy paper..
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#89A genuine question: Why isn't it perfectly reasonable to accept to break compatibility in order to increase security? Isn't that what we do in our lifes all the time? When the authorities issue new fire safety regulations for buildings, then that is breaking compatibility to the older building standard. We still do it because there is good reason. Sometimes even old buildings need to be retrofitted, and that is then…
It is, and he's wrong, and he's usually wrong when security comes up. See also git using SHA-1: people warned him about this, and he argued passionately and incorrectly that git doesn't use SHA-1 as an integrity measure. He also argued passionately and incorrectly that SHA-1 was unlikely to be broken and worrying about it was a waste of effort. And now other people are doing a lot of slow work to dig ourselves out of…
Re: Linus: Don't bother with grsecurity. Their patches are pure garbage
#90Earlier quoted context omitted.
Note: this is a lot tamer than a lot of the stuff I've seen him post in lwn.net comments. I have a lot of respect for their work. It's just a shame that their toxic communications will make the good things they do so much less likely to be widely adopted.
> their toxic communications If you can't handle the truth, then every truhful communication can be "toxic" to you.
It is an emotional outburst, not learning material.