Linus Torvalds Interview for LinuxFR
linuxfr.org
linuxfr.org
His approach to licenses is the same - he uses what works for him, and lets others decide for themselves what works for them.
It makes Linux attractive as a platform at all levels because you never feel like you're making some grand statement, or locking into someone's master plan. I have Linux servers in the office, but also Windows desktops. I program code for embedded devices (running Linux). We use the right tool for the job, and if a better tool comes along we can switch. We're not married to the computers, we just use them.
To some extent this makes the whole "Linux on the desktop" issue a non-issue. Maybe it'll be on the desktop one day. Maybe it won't be. Either way it doesn't seem like this matters much to Linus - as he said Linux competes with itself.
I like pragmatism. It gets stuff done.
Good lord, so we're supposed to take an interest in ethics privately but never speak about it publicly? Almost everything I believe about ethics comes from processing other people's ethical ideas, and the same is true for Linus, I'm sure. I personally don't think less of anybody who uses an MIT or BSD license instead of the GPL, but I do think less of Linus for declaring ethics to be an unsuitable topic for public conversation, simply because he can't stand to hear people disagree with him or disapprove of him.
Not to mention he is a brazen hypocrite. He broadcasts his opinions about other people's behavior, calls them dickheads, and says he despises them, because it's inappropriate for them to talk about how other people should behave. Sorry, Linus, it's hard to be more of a sanctimonious dickhead than when you're calling someone else a sanctimonious dickhead.
Gotta say though, I do agree with his point. People who cram their ethical systems down other peoples throats are dickheads. Am I automatically a dickhead myself for calling people out on this? So be it, I can live with being a dickhead to that degree.
Then he goes on to say, "I really want to point out that it's not that the license is somehow ethical per se." So it's okay for him to have and express an opinion on that question. The hypocrisy is really thick there.
And here's the question that prompted that response: "Do you agree that there is an ethical content in the GPL?" Hardly a pushy question, and the interviewer practically apologizes before he asks the question. So no, there is no cramming, there is just a person who is extremely sensitive on an issue and responds to a polite question with an insulting rant about civility. There is nothing cool about that. He isn't dropping his brilliant technical judgment on an unsuspecting noob who will be better for it in the long run. It's just unpleasant behavior to no useful end.
All this said, he's literally just saying that people who cram the GPL onto other people because it's more "ethical" are dickheads. As far as I can tell, he's not doing that himself, and he's not attempting to imply that the questioner was doing it either. Rather, he just isn't kidding himself, and recognizes that the reason the question is being asked is because there are certain "high profile" people who have made it a full time hobby to do such cramming. He wishes to make it clear that his reasons for using the GPL are purely pragmatic, not quasi-religious.
To be honest, at this point it really just seems like you are attempting to be contrarian.
There are undeniably people who do what can only be realisticly described as "cramming" their ethics systems.
Most controversies include some number of unpleasant people. If we let that affect how we respond to polite questions from polite people, we become part of the problem. If you said something to me about the U.S. occupation in Iraq, would it be constructive for me to respond by complaining about the conduct of various people who have expressed similar opinions?
It's not as good as one signed by an ostensibly trusted CA, but it's strictly better than plain HTTP (no sniffing, harder MITM, etc) - so why not present it to the user the same way that plain HTTP is?
The conspiracy theorist in me wonders if trusted CAs 'lobby' browser vendors to make it so?
Basically, self-signed certificates can't be revoked in case of a security breach.
There's an excellent resume of the discussion of the subject at Mozilla : http://www.gerv.net/security/self-signed-certs/
Can you think of any counter examples? (Note: I'm a security noob - so I'm asking out of sincere curiosity).
Still there is good reason that browsers rub it in the users face when a site tries to use a self-signed certificate. The user has to be really really sure that this is expected (it is like the SSH "the remote host key has changed" warnings).
Still there is good reason that browsers rub it in the users face when a site tries to use a self-signed certificate
but I don't see where you say what that good reason is.
If a self-signed cert is more secure than plain HTTP, why make a self-signed cert more painful to use than plain HTTP?
The people that really know what they're doing can click through the warnings and still do what they want. But casual users that assume https=safe have the chance to leave.
I'm all for deprecating HTTP the same way they did with TELNET, and warning the user for every HTTP site they go to, but that's a wholly different discussion :)
This is the right workflow you should follow with self-signed certificates, it is similar to SSH. You need to accept the certificate once. After manually verifying it is the right one, you're even more secure than trusting on a CA...
Your statements about what should happen are only true if you are requiring encryption for everything that you do. On the web, it's assumed (although most people don't actually know this) that your information is not secure unless you see the green bar or whatever the security visual is on your particular browser.
This brings me back to smanek's point. We have three levels of security: no SSL, untrusted cert, trusted cert. Nothing about the first level is superior to the second level, except for the possibility of a false sense of security. Therefore, a browser should not freak out more in the second situation.
Or more accurately, for all intents and purposes they are exactly as secure, but carry an unearned sense of security. Unjustified senses of security are a very very dangerous thing.
The important thing here is that a browser can do something like this without interrupting something that the user actually cares about with an annoying message. Annoying messages are bad.
In summary, firefox exaggerated with their warning, I'm wondering if it is possible to do an addon to fix this.
The browser should jump up and down when encountering such a certificate as it's exactly how an attempted MITM attack would look.
I don't know if browsers do this, but in principle they could even notify the user on certificate change, so the MITM would have to be on the first connection to a site.
The attack is more involved than just openly sniffing packets. You need to poison the DNS cache on the victim's machine, so that facebook.com resolves to you. Or, you need to poison the ARP cache, so the victim machine thinks that you are the router. These are both easy to do, though, and once you've done that, then you are a man that's in the middle, and MITM attacks are easy under those circumstances.
"ettercap" is a program to automate this technique to spy on SSH, HTTPS, etc. Works quite well.
For someone who is not a native English speaker, Linus really has an awesome way with words.
Edit: OTOH, Linus is talking in the context of software licenses -- I agree with him that it can get holier-than-thou the way some folks push the GPL (not least its original author).
So it's as easy to find something we all mostly agree on (murder) than something we all mostly disagree on (property).
Also taking the murder example is quite dishonest. Linus wasn't talking about murder issues. He was talking about intellectual property issues. Do you claim there is objective right and wrong in this domain ? Do you claim to know what it is ?
EDIT : Didn't see your edit, so correction about the "dishonest argument" part :)
No. He did say ethics were personal but ethical relativism was not even hinted at. Those two ideas are not interchangeable.
One can very well use it as an argument for why somebody else should or should not do something. e.g: One should not throw a hard-disk at Linus Torvalds because they might hurt him and that's just wrong...
If you're talking about the fact that every culture has notions of right and wrong, yeah sure.
If you're saying that what is right and what is wrong is universal and not cultural ... Well where to begin
Some of thoses traits are shared amongst most cultures (Murder is wrong, incest is wrong), but even there there are exceptions (ritual murder ?). For anything more complicated than that, this position is simply impossible to hold.
Most precisely, about property, intellectual or physical, and things like profit, the sense of right and wrong varies so wildly amongst cultures that i can't really think you're making this argument seriously.
And even if it does vary wildly in current cultures, there is such a thing as a sense of morals that we can combine with rational thought to reach a fair solution. The fact that culture A considers ritual murder ok fails this morals + rational though test.
That sounds a lot like most theology I've heard, and I suspect that the HN crowd is not one that puts a whole lot of stock in theology.
(Yes, let the lawyers and marketing droids point out that "UNIX" is a trademark of the Open System Group and that no Linux distribution has been registered as comformant to the Single Unix Specification, but that doesn't change the reality that Linux is a Unix.)
"Linux is the focal point of all Free Software development"
...which is of course bullshit (pardonnez-le-mot ;-). Look at all the open source applications and servers that are developed nowadays. Look at the BSD projects! Free (as in Freedom) Software is not confined to the linuxsphere.
It has to be fairly recent, since it talks of the upcoming anniversary and the site considered it newsworthy, but ...