Don't trust comments
nns.ee
nns.ee
Remember the NSO iMessage exploit?[1] copyGifFromPath didn't really copy the GIF from the path.
At some point, you do have to trust that the kernel API's documentation (or whatever) is correct[2], simply because it's physically impossible for you to exhaustively verify that each piece of software you use (transitively) has correct documentation and consistent semantics. That doesn't mean that you shouldn't audit third-party code, do code reviews, write tests, fuzz your code, and use static analysis and formal methods - in fact, you should do all of those things, if you can.
But, "don't trust comments" is a gross oversimplification. Perhaps "trust, but verify" is a better pithy saying.
[1] https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
[2] technically, if you did all of the above things, or found other people that did them, then you wouldn't have to trust documentation - but the vast majority of the time, most of the software you encounter will not have been thoroughly audited, tested, and fuzzed, with a nice formal specification
You can only ever trust or verify. "Trust, but verify" is functionally identical to "verify", thus, equivalently, "distrust, therefore verify", with maybe a generous helping of cynicism, doublethink, and official mollification.
"Trust, but verify" is a semantically null expression that appears to have filtered out of the Soviet Union during arms reduction negotiations, and eagerly taken up by Reagan administration appointees.
In a modern context it means, look for errors but not deception. It's how I approach code review.
* Any Soviet saying would come from a culture used to double-speak to survive government oppression and censorship. Which is probably still new to many Americans who remember good old days.
It's been straight up surreal watching the world turn into the George Orwell "1984" world we were all warned about as children, and seeing the USA (Land of "Freedom") gleefully join in the dystopian "fun".
Either way, if you insist on an excessively narrow definition of trust as being "never verifying", then yes, they're mutually exclusive... but only because it's circular logic.
Bar tabs are a good example of this behavior. Just get your regular a drink and assume their card will go through. In the past checks worked like this too.
1. Let the person start doing what they set out to do.
2. Check if they actually have permission.
3a. If yes, stop.
3b. If no, block their access.I mean, when you get any. That is increasingly rare.
"How can it be both NEW and IMPROVED?"
is there some kind of equivalent of aphantasia but for the feeling of trusting something ?
I'm not racist, but <some racist shit>.
You don't like the Corvette. Not that Corvette. However, you like Corvettes in general. Or you only like red Corvettes.
> I like steak, but
Turn the comma into a period: I like steak. It's unconditional; steak is a big yes for you. Except it's not. You have conditions. So sometimes you like steak and sometimes the opposite. You don't like steak.
I think the interpretation of but is not as trivially stupid as you say.
I verify their code with testing because humans are fallable.
On the other, this does feel a bit whatabouty. Because yeah, you can’t check the kernel code, but you can and should check the code of direct dependencies. Not every time you do anything, but certainly whenever there’s something to be feared. Running code against untrusted inputs from the Internet is one of the few places that would justify “reverse engineer the kernel to make sure it’s safe” levels of concern, in the right conditions.
Or am I misunderstanding something?
I don't think the lie was deliberate - the comment was probably erroneously added.
When it comes to security no one should trust that intent matches reality.
Commits need to be in a separate version tree from their commit messages.
Sort of a combination of a reverse github auto-pilot metric and checking how old a comment is based on it's surrounding code.
You could even syntax highlight based on how accurate it thinks it is like how down voted HN comments fade out.