This is why software sucks
tedunangst.com
tedunangst.com
"I don’t have much involvement in portable, but I definitely had a hand in neutering the RAND and egd interfaces. Contrary to some commentary, we didn’t neuter these interfaces because we didn’t know what they were. We neutered them because we know precisely what they are. They’re fucking stupid."
uh... okay; thanks for the enlightenment.
I'm sure this post makes more sense to people who are intimately familiar with whatever it is that is being talked about in the first place, but to the rest of us it might as well be written in Klingon.
OpenSSL took a rather strange approach of "hey, $some_obscure_operating_system doesn't provide $some_critical_system_function, so let's implement it ourselves and activate it for every single platform that OpenSSL is used on regardless of whether or not there's an existing equivalent". In many cases, these sorts of shenanigans are the source of various bugs or - just as horribly - the reason why so many bugs had been undetectable via stricter memory access requirements and debugging techniques (the latter being what's referred to when the phrase "exploit mitigation countermeasure" is used in the context of OpenSSL).
Ted could probably be a bit more helpful by providing a link to the "fucking stupid[ity]" that is OpenSSL's bass-ackwards API, but most of this is already explained in prior announcements about libressl's improvements/development and such, so it's understandable why he didn't feel the need to provide links for context.
As I've written before, it's almost entirely about the economics of it. For tons of software out there, there is simply no incentive to make it super stable, polished, secure, etc.
In other words: let's say you're building a web app for a small local business. Are you going to build it in Erlang, run it on several physical machines and do all the other fault-tollerant, high-availability stuff, or are you going to put together some pieces of Rails or PHP or Django and call it 'pretty good'? You're going to do the latter, because otherwise you're going to cost a lot more than the competition, deliver less, and in any case the guy running the business is going to be understanding if you need to take the site down for an hour on Sunday morning to upgrade something once in a while.
So far, so good. Security is a bit more problematic, because there can be some pretty serious financial ramifications. The trick is to get the people who bear those risks to pay some of what it costs to produce better software, which is not always easy in the case of open source.
(The economic effects of the different liability regime might be good or bad, but it's quite striking how doctrines that are well-understood in other areas are applied so differently to software.)
I don't like what they're doing, but its not like they don't understand their own actions.
Anyone have a less horrific take?
AKA I'd like you to sprinkle magic security dust on the code so I can check off "secure" on my checklist, but don't actually change anything.
This is one of those "Live by the sword, die by the sword" things: LibreSSL was birthed, it seems to me, as an opportunistic venture to take the meager funding and attention away from OpenSSL during its time of crisis, sold on the premise that OpenSSL is a festering heap maintained by a bunch of hacks, and now it's time for the big boys to show how it should be done.
When you start like that, you will face an incredible amount of scrutiny. Every failure will be exaggerated and spread far and wide.
Expect to die by the sword. Or to use another cliche, when you throw rocks at your neighbor's glass house, you should avoid building your own of the same.
How do people come up with bullshit like this? You try to make the free software project look like an obnoxious enterprise that would exploit a time of uncertainty to show off and bolster their status, for revenue.
The reality is that they realized a critical component of their security-focused project is broken and needs fixing, urgently. So they started working on it. That is what they do. All the attention was generated by media and citizen of the Internet. At the time, I don't think anyone was talking about funding. Definitely not about the funding of OpenSSL.
Then people started demanding portability. Other people wanted to support the project just because. Or because they came to realize (or already knew) that OpenSSL had serious issues. At the time, no funding was being directed at fixing these issues.
They didn't 'suddenly realise' that it was crap. They have been criticising OpenSSL for a long long time. Why didn't they create a fork until now?
During the wide media exposure of OpenSSL's heartbleed vulnerability, Theo quite cleverly forked off LibreSSL, started a campaign for funding, and aggressively and viciously attacked the existing codebase.
http://arstechnica.com/information-technology/2014/04/openss...
Yes, it absolutely appears to be exploiting uncertainty for their own benefit. Both in exposure and status ("I'm here to save the day"), but also in funding. Theo, and I assume others, are paid by such funding, so it isn't quite so benevolent.
Sticking "free software" in the description doesn't suddenly remove all normal human motivations.
Nothing says "This codebase is beyond repair" quite like forking a codebase and repairing it.
So when the media interviews Theo about it, is Theo being the attention whore? Did Theo offend you somehow? Did you read the article you linked?
I did not make this decision... in our larger development group, it made itself.
You willfully choose to ignore reality and interpret it against the OpenBSD project. Why all the hate? They are trying to make better software. And everyone does benefit (so long as OpenBSD stays afloat, which costs money). Maybe you should look for origins of libressl, and also watch Bob's talk, which was mentioned here.
Spoken like someone who hasn't spent enough time in the open source software business. ;-)
Probably, everyone was running around yelling about libressl security like a chicken with it's head chopped off. It's a brand new fork under heavy development that just started compiling on Linux a few days prior. What, did people expect it to be production-ready just because OpenSSL is?
it seems to me, as an opportunistic venture to take the meager funding and attention away from OpenSSL during its time of crisis
If we're making claims of bad faith, lets go with a much less conspiratorial thought: Some blogger oversold a bug they found because they wanted the self promotion of finding a security-related bug in the thing seen as OpennSSL done right built the guys that take security seriously. Sure, that's not a charitable reading of events, so I don't subscribe to it myself. But, where is the openbsd mailing list report of this bug before the blog post went up? If he went to the mailing list first, it would have solved faster and without unnecessary commotion.
Everything written on LibreSSL's linux port is infuriating. It's no surprise that openbsd is seen as insular and hard to work with. They're misinterpreted, misrepresented, and have really weird expectations set of them by people that don't even run openbsd. If I worked on openbsd I'd be real ornery too!
Probably true, though that's of the "live by the sword" variety. It's like being a grammar critic: one had better exercise perfect grammar or expect to hear about it.
One of the major talking points of the LibreSSL initiative is a 4 year old bug in OpenSSL if you use a non-standard, non-default mode and multithread access. There are zero demonstrated exploits of it, it is by most analysis at most responsible for dropped connections, so it is far less concerning than even this "oversold" bug.
That is the bug that the LibreSSL team always talks about, railing about a "critical security vulnerability that sat unfixed for 4 years". It has been referenced multiple times throughout this discussion.
So again, what goes around comes around. Someone criticized a product that claims to be version 2.0, and which is based on long-proven, long-existing code, and found a pretty extraordinary fault that looped back to the LibreSSL team simply removing functionality they didn't think was relevant. Alright, in reality it just isn't a big deal, but it is what a team sets themselves up for when they criticize others with seeming impunity.
You keep saying that as if their hubris gives others a free pass on how they represent or respond to open bsd. To me, jumping on them just looks hollow and petty.