(Pidgin's) SSL support appears to have been written by a lobotomy victim
developer.pidgin.im
developer.pidgin.im
That aside, I have a hard time seeing that there's any level of rudeness this sort of code doesn't deserve.
No need for the spluttering outrage and emotional editorial comment by the bug reporter (to say nothing of the ad hominem attacks on the programmer).
"If you don't look carefully, it may appear that the NSS plugin doesn't do any validation of the SSL certificates, but that isn't the case; the validation is done, just not by the SSL_AuthCertificateHook hook."
"If you look at ssl-nss.c#l454, you'll see that before the SSL connection is considered "connected" from libpurple's perspective, ssl_nss_handshake_cb is called to validate the certificate using the libpurple's purple_certificate_verify functionality."
This is why you don't jump to conclusions, throw out an emotional diatribe, and generally make an ass of yourself when writing bug reports.
However, I'll also agree that being rude has some value. It's linked here and on other such sites.
It means they'll have to fix it, but also to be more careful in the future, because being bashed in public is never a fun thing. Unfortunate reality.
Do you think that using SSL where your client accepts every certificate (the link points to a function that returns a success code unconditionally, the 'real' stuff is disabled by preprocessor directives) is bad?
Whatever the severity (for me this is certainly high), the tone in that bug report is inexcusable.
Edit: Well, it seems that code existed like this since its creation, 2003-09-29: http://hg.pidgin.im/pidgin/main/rev/895a5ff9ebd4
Edit 2: The bug report has now a proper response, quite relaxed. So it seems this is totally expected - for whatever reasons. I'm still curious why the code is littered with #if 0 fragments for years (dead code belongs in the vcs history for me), but the initial expectation of a total lack of certificate verification is wrong.
Twitter(!) has the news as it broke/continues to break:
> .. the most widely used(?) open source IM client library, libpurple?
At the very least, would have been a great place in the code to comment on where (since obviously not there) the cert is supposed to get validated!
That's how bad it is.
It makes me so sad to see this kind of attitude. And usually (don't know about this case) it comes from a person who does not contribute to the project.
Not everyone is a cryptographer. Although they should refrain from writing crypto code, calling them "lobotomy victims" makes you sound like one.