7 ms·
I wonder which "popular third-party library" caused the problem
by ndrake 9y ago
I wonder which "popular third-party library" caused the problem
- pavel_lishin 9y agoI assume they'll reveal that information once the library fixes the issue.
- SteveNuts 9y agoProbably left-pad
- reverted 9y agoMore importantly, I wonder how much they were paying for this library, or to what extent they were supporting it internally. Because if the answer is zero and they weren't, I would put a lot of the blame on HipChat engineering.
- lolsal 9y agoI'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?
- eropple 9y agoI read it as "if it's open-source, a company of Atlassian's size should be being good stewards and taking care of things that are helping them make money."
- lolsal 9y agoOpen source code now carries a moral maintenance obligation? Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? That doesn't seem fair or reasonable.
- plange 9y agoNot only moral, but mostly legal. Warranties are not included. So it's a bit lame to blame "a popular third party library". The OP was trying to say a company of Atlassians size should dedicate the resources to vet (and fix) those libraries if they use them for these purposes.
- lolsal 9y agoI don't think anyone is trying to shift blame, just to explain what happened. I am not affiliated with Atlassian so I'm only guessing.
- plange 9y agoSorry, i wasn't trying to imply they shifted blame. But atlassian does bare the legal&moral burden of securing their product here.
- lolsal 9y agoI agree with you. I don't agree that they have a moral obligation to make pull requests to the open source library that had the issue. Hopefully they will, but there is no obligation there in my mind.
- sithadmin 9y ago>Open source code now carries a moral maintenance obligation? Many have always argued that it has. >Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? Many do. >That doesn't seem fair or reasonable. Many argue that any company that failing to contribute to the OSS projects they depend upon isn't fair or reasonable.
- lolsal 9y ago> Many have always argued that it has. Alright, I'm arguing that it doesn't. > Many do. shrug I don't. > Many argue that any company that failing to contribute to the OSS projects they depend upon isn't fair or reasonable. This sort of attitude bothers me. At this point the software is not really free in my opinion. I am not a lawyer :P Just my $0.02
- cbhl 9y agoI think this is a part of the general meme that big companies are making money by taking open source without giving back, and that big for-profit companies could do more for the open-source community.
- falcolas 9y agoIMO, frankly, yes. If you use someone else's code, especially if you're not paying anything for it, you get what you put into it: nothing. The liability for this breach is ultimately owned by Atlassian, not the third party library writer. To quote the most permissive license out there: "THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED."
- lolsal 9y agoTo use an analogy, do you blame everyone that has ever used the linux kernel whenever bugs/vulnerabilities are discovered in the kernel?
- falcolas 9y agoI would certainly blame Google if their Android phones were backdoored, especially if they tried to foist the blame off on the Linux kernel developers - a much more apt analogy since they sell Android phones.
- algesten 9y agoI would be very surprised if something as complicated as Android phones didn't contain anything that can be back doored. Obviously that is Google's problem, but I haven't seen Google (nor Atlassian in this case) claim anyone else is to blame.
- geofft 9y agoIf they use the upstream kernel, yes. Linus Torvalds has been very clear that security is not a priority. "We have one rule in the kernel: don't break userspace. Everything else is kind of a guideline. The whole security thing? It's a guideline that we shouldn't do stupid shit. But people do stupid shit all the time and I don't get that upset." https://www.youtube.com/watch?v=1Mg5_gxNXTo#t=8m28 https://www.youtube.com/watch?v=1Mg5_gxNXTo#t=8m28 Imagine, Torvalds said, that terrorists exploited a flaw in the Linux kernel to cause a meltdown at a nuclear power plant, killing millions of people. “There is no way in hell the problem there is the kernel,” Torvalds said. “If you run a nuclear power plant that can kill millions of people, you don’t connect it to the Internet.” Or if you do, he continued, you build robust defenses such as firewalls and other protections beyond the operating system so that a bug in the Linux kernel is not enough to create a catastrophe. http://www.washingtonpost.com/sf/business/2015/11/05/net-of-insecurity-the-kernel-of-the-argument/ http://www.washingtonpost.com/sf/business/2015/11/05/net-of-... And the Linux kernel has a track record for not being the world's most secure piece of software. Which is fine, it's a project he started for fun. It's certainly possible to pay people for a kernel that they'll stand behind commercially. If you're using, say, a RHEL kernel and a bug or vulnerability is discovered that impacts you, by all means get upset at Red Hat. If you're using a Fedora kernel, though, you made the choice to use it. It's completely unfair for you to get the benefits of running a kernel you put neither time nor money into, and not also the risk of running that kernel.
- GrinningFool 9y agoWhen you use any third party library, you're responsible for its behaviors (or misbehaviors) on your customer's machine. How is it possible to view this in any other way?
- lolsal 9y agoI 100% agree with you. Atlassian is 100% responsible. I'm not sure I would not say they are at 'fault' though. Maybe I'm just quibbling over semantics. I don't know the details of the vulnerability - I would say they were at fault if they did not update/patch a fixed vulnerability.
- throwaway91111 9y agoThis really depends on the use case of the library. It's entirely possible to find bugs that are outside your expertise to fix. I can't speak to this case, obviously.
- geofft 9y agoIf it's free software? Yes, absolutely. To do otherwise is a chilling effect against hobbyist free-software authors in favor of large companies that have the ability to take on that liability. I, as an individual, want to be able to write code in my free time, put it on GitHub, and let it get popular without worrying that maybe it has a bug in it. If people want to start holding me responsible for it, I'm just not going to release it. Maybe you can pay my employer for a commercial license if we think that the cost of auditing it and taking on the liability for bugs is commercially reasonable, but it's also unlikely my employer will be interested.
- lolsal 9y agoI am absolutely not advocating that the library author be held liable.
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- ej_campbell 9y agoOne of these: http://sources.hipchat.com/ http://sources.hipchat.com/
- masterleep 9y agoIt might be: https://bugs.ghostscript.com/show_bug.cgi?id=697808 https://bugs.ghostscript.com/show_bug.cgi?id=697808