Linus Torvalds on the "security circus" (2008)
lkml.org
lkml.org
If a server with credit card information permanently corrupts the filesystem, and bricks all the hardware, and more or less does the worst that a non-security related software failure can do, the server gets reimaged or replaced. It costs maybe a few thousand dollars to replace. Nobody is really affected because failures are expected.
If a server with credit card information has a security bug, then credit card fraud and it's associated costs have to be dealt with, identities might have been stolen, and in general, large numbers of people are affected, possibly severely.
http://lkml.org/lkml/2008/7/15/498
He simply doesn't want to make it easier for "exploitz searchers" to recognize which bug patches are "easy to make an exploit."
People that fix ordinary bugs then also end up fixing many security bugs that are not classified as such. These are the unsung "heroes".
I think his point is that the important part is working on fixing bugs, and not making a show out of finding security ones.
There is no point in telling him he's wrong, either. He'll just call you a "masturbating monkey".
Because that is what is being discussed here.
Is this really anything more than yet another opportunity for message board geeks to go "RARRR!"?
What is silly? Really, I have no clue as to what you are trying to say.
The fact is, despite that one obvious nit with his comment, if you take what he's saying in context, he has a very valid point about how the security community interacts with the Linux development community.
So in my opinion he's right: both are equally important, as you cannot judge of the importance of each one on purely speculative and gross domain grounds. A potential is just that: a potential, until it gets real. Both cases can be mitigated or prevented by applying similar strategies (redundancy, layered checks, ...).
On the other side of the spectrum, a good bunch of Intel video cards have been crashing randomly (ranging from seconds to hours) since years and it affects a good deal of people which have to revert to vesafb or fbdev, or dismiss Linux entirely, right now. Another one is the issue introduced at some point that makes kworker eats up a chunk of CPU for no apparent reason (from 10% to 100%), resulting in useless wakeups and processing, raising power use by 1 to 10W. Multiply that by the growing number of Linux systems using 2.6.35+ and you get quite a bunch of watts that should have never been produced by power plants nor paid to energy companies by the machine owners. It happens right now with real, tangible effects.
I'm not dismissing security bugs, but put things into perspective as things are not black or white, and every single bug matters.
As an aside: Holy crap! Reading that thread reminded me how high signal/noise used to be on HN. Quite sad.
Go to e.g. osvdb.org, search for 'Linux kernel': 878 results. Search for 'Solaris', which includes many non-kernel vulnerabilities: 595 results; search for 'freebsd': 171, including e.g. ftpd issues; search for 'OpenBSD': 93, again including stuff like an XSS in OpenBGPD's bgplg (very much not part of the kernel!) This is not merely historical; Full-Disclosure readers get a "vulnerabilities in Linux kernel: 20 issues fixed" every month or so.
Yes, Linux has some really nifty stuff, lots of people are looking at it, and things like GrSecurity can be useful. But it also has a lot of (local) kernel-level vulnerabilities compared to similar pieces of software.
Seriously, try looking for dangling pointer bugs, there's tons, you can just pluck them from the trees.
Here's a comment I posted a while back that might be of interest: http://news.ycombinator.com/item?id=2301830
To be fair, this stuff happens in BSD land too, but nowhere near as much as on Linux. To be fair again, the Linux codebase is a very different beast and has grown in a very different way.
Or it is because no body cares or looks at it? ;-)
1. It's a very dumb metric, for reasons stated well downthread and for many others (the bewildering number of off-by-default hardware and kernel features many of those vulns appear in being another).
2. The fairly obvious rebuttal that things Linus says on message boards actually have little to do with the security of Linux, and that the particular thing Linus said this time has practically nothing to do with the security of Linux.
With the possible exception of OpenBSD†, nobody clueful picks server platforms other than Linux with the expectation that it is going to be easier to keep them secure on the Internet.
† Reasonable people can disagree about the extent to which OBSD is a win; in 2011, I'd rather have Spengler on my side than Theo.
Linus' words don't affect code quality; but wanting to move quickly does, and Linux does move quickly. I agree that Spengler is pretty awesome, though.
To quote the wisdom of the dude:
"Well, yeah. That's like, your opinion, man."
http://www.openbsd.org/goals.html - OpenBSD goals (security is #3).
I still think it was a cheap shot and not representative of the project. Goal #2 seems to get a lot more play in heat from the OpenBSD project.
OpenBSD is great because of everyone's obsessive focus on quality. This means fixing bugs (all security exploits are bugs), providing clean interfaces, and keeping garbage out of the system.
Linux development tends to be a lot more "pragmatic," which in practice means trying to hide bugs (http://seclists.org/fulldisclosure/2008/Jul/276), being ok with providing a crapload of weird, incompatible, non-unixy interfaces to do things (compare Linux wireless configuration vs. OpenBSD's ifconfig), including binary blob garbage with the kernel, and relying on bloatware like Gnome.
Sure if you look just at the source code, I agree that the one for OpenBSD looks better than the one for Linux.
Non-security defect: system goes down for a while, company loses money, possibly data, reputation suffers. Companies using sensible redundancy and backup procedures are able to recover.
Security defect: system is compromised, user data stolen, internal company secrets stolen, financial data stolen, financial instruments (CC data) stolen. Massive impact on the company and on the customers, much higher potential for the destruction of the company due to damage to its brand and its business.
"That is an idiotic thing to say; 1 + 1 is 2, not 3"
can be shortened to "1 + 1 is 2, not 3."
Parent comment can be shortened to "". Please avoid introducing classic flamewar topics unless
you have something genuinely new to say about them.
Resist complaining about being downmodded. It never
does any good, and it makes boring reading.If it is merely funny, trolling, or otherwise flippant, there are many other sites where such posts are at least tacitly encouraged.
But this question in particular is discouraged. Follow HN for any length of time and you see the answer. If you want a meta-thread about posting, create one. But this thread is (was) about security.
Sure you are. You're also welcome to leave if the community norms for voting are not in line with your own.
I too like to fire off witty, snarky comments. But after a few of them got torn apart vote-wise, I now spend more time asking myself if I will be adding anything useful to the discussion. While I try to refuse the allure of groupthink just so I can get the rush of seeing my karma count move up, I do attempt to at least find a way to state my opinion in a way that is palatable and intelligent.