Live data from Hacker News

Linus: Don't bother with grsecurity. Their patches are pure garbage

spinics.net

1–10 of 172 posts

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#5
For all his unfortunate abrasiveness one strength of Linus is and has always been his capacity to see the big picture, e.g. that usually compatibility/API,ABI stability/performances trumps extreme security measures and also he has always been able to accomodate with big players/corps in the industry.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#6
Grsecurity wouldn't exist if Linux made security a priority. It doesn't, because backwards compatibility and features is more important to them. It doesn't mean because Linus says something so strongly on a subject is right or wrong, he is generally abusive and rants and has for years.

Grsecurity is important to some people, not all, and vice versa for the features and backwards compatibility crowd.

Personally I'd hope someone in Linus position would see both sides of the fence, but he doesn't and always has some mouthy outrageous opinion. So this is zero surprise.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#7
It's a struggle to respect the security opinions of someone who has actively admitted that he thinks "[security] bugs are just bugs". [0] Personally, I find it quite hard to respect Linus generally - his offensive personality is clearly not something that would be appropriate coming from anyone else in any community, but for some reason he gets a free ride for being a difficult genius.

0. http://www.washingtonpost.com/sf/business/2015/11/05/net-of-... N.B. The article is a bit deep in technical inaccuracies - it calls Linux an OS, for example.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#9
post #5

For all his unfortunate abrasiveness one strength of Linus is and has always been his capacity to see the big picture, e.g. that usually compatibility/API,ABI stability/performances trumps extreme security measures and also he has always been able to accomodate with big players/corps in the industry.

I kind of find Linus refreshing, although I'm not sure that would survive working directly with him. I think you're begging the question though: surely compatibility/ABI stability/performance trumps extreme security (for some values of 'extreme') for people and in cases where that is true. I happen to agree with you and Linus on this (baring a known exploit of an unpatched security bug), but that heirarchy is nowhere engraven in stone. If I always recompiled a critical codebase, I wouldn't care as much about ABI compatibility. If I'm always targetting a very specific platform, I don't care about compatibility. If I'm sitting on millions of unused cycles in a single-threaded realtime environment, I only care about performance to a certain point. If I'm working on software to control a medical device or nuclear reactor, my priorites around extreme security change.

You're right about that priority for the vast majority of the Linux user-base, but that's a characteristic of those users and developers, not of kernel software in general.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#10
See Linus' follow-up http://seclists.org/oss-sec/2017/q2/596 for clarification:

> They aren't split up, there has never been any effort by you to make them palatable to upstream, and when somebody else dioes try to make them palatable to upstream, you start crying about how people are taking advantage of your work (hah), and try to make them private instead.

...

> It's literally less work for people to re-implement things than look at your mixed-up patches, and YOU SEEM TO BE DOING THAT ON PURPOSE.

> Now, prove me wrong. Start trying to integrate your work upstream, and send individual patches with commit logs that can be integrated.

Post reply on HN