5 ms·
There's plenty of great quotes from Torvalds about why it's like that. He places functionality over security, and assumes security will just 'happen' with code
by this-dang-guy 10y ago
There's plenty of great quotes from Torvalds about why it's like that.
He places functionality over security, and assumes security will just 'happen' with code quality. I tend to disagree - but I am typing this from a Linux box, not an OpenBSD box.
Because Linux is more functional as a desktop - the irony there isn't lost on me.
- nickpsecurity 10y agoExactly. Priorities = what you get out of your work. Far as Linux vs OpenBSD box, remember also that contributors (including corporate) are partly to blame here since they chose to put their investments into a project that doesn't care about security instead of one that bakes it in. Even if Theo et al weren't pleasant, they could've forked OpenBSD keeping any of their improvements while making what changes they absolutely needed. We'd have had an OpenBSD desktop in a few years as easy as OpenSUSE at the least.
- this-dang-guy 10y agoA very valid point. IBM contributes a TON of code to Linux. They could easily have worked to improve security if they cared. Or, improved BSD, and avoided all that GPL stuff if they wanted.
- nickpsecurity 10y agoI was actually shocked they didn't contribute to FreeBSD instead then rebrand their management or security customizations as their own enterprise OS. The Chinese ended up doing that with Kylan. Cambridge's CHERI team made it capability-secure with minimal modifications. IBM was in ideal position to do that, too, given they had legendary Paul Karger who already built high-assurance OS's and CPU's for them. Let's just call it Another Missed Opportunity for the Big Blue. :)
- this-dang-guy 10y agoThat's a big book right there! I was really disappointed in how Apple treated BSD, but I am stupid and naive. I would have expected that from IBM though.
- grzm 10y ago"I was really disappointed in how Apple treated BSD" Would you go into more detail here? The BSD license is very liberal. That's no excuse for bad behavior, but I'm unfamiliar with bad actions on Apple's part wrt BSD, which I gather there were given your phrasing.
- nickpsecurity 10y agoParent might be referring to how they just gobbled it up into Darwin and Mac OS X while contributing about nothing back. At least, I'm aware of them making a bunch of money off Mac OS X and iPhones but not hearing about contributions to FreeBSD at level IBM or Red Hat do to Linux.
- grzm 10y agoYeah, I was wondering about that, too. Granted, the BSD base is arguably one step removed from Apple (as that was NeXTSTEP, which Apple acquired), and both Darwin and OpenStep are open source. Apple continues to release the source of some of their software.[0] According to the "Myths" page at FreeBSD, "FreeBSD 9.1 and later include a C++ stack and compiler that were originally developed for OS X, with major parts of the work done by Apple employees",[1] so it hasn't completely been freeloading. I don't know enough about the levels of contribution to either to make a strong comparison, and I'm more than willing to grant IBM and Red Hat make much larger contributions to Linux than Apple does to FreeBSD. And I sympathize with the desire to have more contributions. The "how Apple treated BSD" phrasing sounds like there is more active bad treatment rather than not contributing enough. Maybe the hiring of Jordan Hubbard is considered active bad treatment? (Honest question) [0]: https://opensource.apple.com https://opensource.apple.com [1]: https://wiki.freebsd.org/Myths#FreeBSD_is_Just_OS_X_Without_the_Good_Bits https://wiki.freebsd.org/Myths#FreeBSD_is_Just_OS_X_Without_...