4 ms·
Agreed that tensions are running high. But I think the ruby devs are in the right here. They are just following the man page. What else is the authoritarian sou
by educar 10y ago
Agreed that tensions are running high. But I think the ruby devs are in the right here. They are just following the man page. What else is the authoritarian source?
How is one supposed to know who wrote those blog posts? Just because it is linuxexpert.com does not mean they are linux experts. It's funny, if people changed it randomly following blogs then people will claim this is some NSA conspiracy :-) How does one verify the person behind the blogs?
node has similar https://github.com/nodejs/node/issues/5798 https://github.com/nodejs/node/issues/5798
- lifthrasiir 10y ago> They are just following the man page. I think Ruby devs' position is more than this. By keeping the faulty man page, Linux maintainers are implicitly communicating that they intended `/dev/urandom` to be a limited and less recommended way of doing things. The intention is important: even though `/dev/urandom` is actually better in the current kernel it may not in the future. It is not the only answer, as other languages did another choice, but it is perfectly reasonable to be conservative like this. We badly need to change that intention, really.
- tptacek 10y agoExactly what, do you imagine, Linux could do to make urandom less secure? I'm sorry, but the word for that concern is "nonsensical". Linus Torvalds has world-shattering conniption fits when developers make changes that hurt performance. Can you imagine breaking every one of the many security applications --- for instance, every Go program ever written --- that depend on urandom? No, that is not a legitimate concern.
- binkert 10y agoThe authoritative source in Linux is the code and always has been.
- disposeofnick9 10y agoCode is useless if no one knows how to use it properly and it's not communicated clearly. Users certainly can't be expected to read every line of code. That's like shipping a car with no user manuals and saying "take the engine apart and see how it works." Arrogance. Clearly document system behavior or code is essentially useless.
- azet 10y agoUsers of languages can't be expected to. Therefore the language designers and maintainers themselves, especially if they're working on the stdlib, should do so, IMO. It's not only education for a proficient programmer, it helps to understand the underlying system you're building on and it's security assumptions. The random char device code isn't that hard to understand, and if you're not a strong C programmer (the Ruby-core people are good C programmers, I suppose) - there's a paper explaining how it works: https://eprint.iacr.org/2012/251.pdf https://eprint.iacr.org/2012/251.pdf Aaron
- batiste 10y agoThen I have a little quiz for you: According to this documentation: http://ruby-doc.org/core-2.1.2/Float.html#method-i-round http://ruby-doc.org/core-2.1.2/Float.html#method-i-round How do you explain? 2.1.2 :011 > 15.round(-1) => 20
- nilved 10y agoI think that's hardly the case. If Linux users were reading the source code, we wouldn't have such an embarrassing track record when it comes to security. Major security issues like Heartbleed existed in code for years.
- onli 10y ago> What else is the authoritarian source? Basically everything else. If you see how manpages are written, or just how often they are out of date, you quickly arrive at the conclusion that they are not authoritative source at all. Add in the political plays done in this area. Being stubborn over a wrong manpage is very frightening, especially in a security context. This thread shakes my believe in ruby as a language.
- torrent-of-ions 10y agoAgreed. The problem is the man page. Suggesting that one should read the source code instead of the man page is ridiculous. Might as well write your own kernel while you're at it if that's the case.