6 ms·
More importantly, I wonder how much they were paying for this library, or to what extent they were supporting it internally. Because if the answer is zero and t
by reverted 9y ago
More importantly, I wonder how much they were paying for this library, or to what extent they were supporting it internally. Because if the answer is zero and they weren't, I would put a lot of the blame on HipChat engineering.
- lolsal 9y agoI'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?
- eropple 9y agoI read it as "if it's open-source, a company of Atlassian's size should be being good stewards and taking care of things that are helping them make money."
- lolsal 9y agoOpen source code now carries a moral maintenance obligation? Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? That doesn't seem fair or reasonable.
- plange 9y agoNot only moral, but mostly legal. Warranties are not included. So it's a bit lame to blame "a popular third party library". The OP was trying to say a company of Atlassians size should dedicate the resources to vet (and fix) those libraries if they use them for these purposes.
- lolsal 9y agoI don't think anyone is trying to shift blame, just to explain what happened. I am not affiliated with Atlassian so I'm only guessing.
- plange 9y agoSorry, i wasn't trying to imply they shifted blame. But atlassian does bare the legal&moral burden of securing their product here.
- lolsal 9y agoI agree with you. I don't agree that they have a moral obligation to make pull requests to the open source library that had the issue. Hopefully they will, but there is no obligation there in my mind.
- sithadmin 9y ago>Open source code now carries a moral maintenance obligation? Many have always argued that it has. >Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? Many do. >That doesn't seem fair or reasonable. Many argue that any company that failing to contribute to the OSS projects they depend upon isn't fair or reasonable.
- lolsal 9y ago> Many have always argued that it has. Alright, I'm arguing that it doesn't. > Many do. shrug I don't. > Many argue that any company that failing to contribute to the OSS projects they depend upon isn't fair or reasonable. This sort of attitude bothers me. At this point the software is not really free in my opinion. I am not a lawyer :P Just my $0.02
- plange 9y agoNothing in life is free. Quality software doesn't create itself out of thin air (yet, if ever). That means someone has to make an investment. You don't have to invest in the upkeep of the foundation of your house, but if some bugs, say termites, were to sneak in you can't blame the original builders for the donated foundation. Please downvote for the bad analogy.
- lolsal 9y agoI think of it like the Heartbleed vulnerability - was everyone affected to blame for the vulnerability? Was everyone simultaneously morally obligated to be contributing patches back to openssl? I don't think so.
- geofft 9y agoEveryone affected was to blame for their own vulnerability, to the extent they relied on OpenSSL. I worked for a company that needed to push out an out-of-cycle patch for Heartbleed. We were building a virtualization product that included a OpenSSL and other free-software libraries in the core product, plus an entire Linux distro to support our install-this-on-dedicated-hardware product. We made the business decision that we could reuse Ubuntu and not develop our own operating system and control plane. Others, like Microsoft, made the decision to implement it all themselves. Others, like VMware, took a decision sort of in the middle. We got a significant amount of functionality for free - and a significant amount of risk for free. Whatever code worked for our needs, we could profit from. Whatever code introduced security vulnerabilities in our application (and it was not all upstream security vulnerabilities, since we intentionally designed our system to anticipate that local root exploits would be easy), we took responsibility for. That was part of saying that this was our product, and not just a shell script for building a similar product on your own.
- eropple 9y ago> Open source code now carries a moral maintenance obligation? Yes, and it always has and it can't be discharged. Pay-it-forward is the right thing to do. > Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? I certainly do. A red line, I-will-quit condition is and always has been "I won't participate in the development of private forks of open-source software" and I have at multiple employers gotten checks straight-up cut to open-source software maintainers. I have also entreated (and in two cases succeeded in convincing) maintainers to start up maintenance programs so we could pay them a yearly fee--because donations are way harder to push than support plans. And, in turn, I open-source useful tools[1][2][3], including major parts of my consulting business, because it, too, is the right thing to do. You should do likewise, because it is the decent and human thing to do. > That doesn't seem fair or reasonable. I consider not paying forward kindnesses paid to you way, way more unfair and unreasonable. [1] - https://github.com/bossmodecg https://github.com/bossmodecg [2] - https://github.com/eropple/auster https://github.com/eropple/auster [3] - https://github.com/eropple/cfer-provisioning https://github.com/eropple/cfer-provisioning
- lolsal 9y ago> Yes, and it always has and it can't be discharged. Pay-it-forward is the right thing to do. Interesting - it may be a nice thing to do, but I don't agree that there is any sort of obligation to the project just for using the project. > I certainly do. A red line, I-will-quit condition is and always has been "I won't participate in the development of private forks of open-source software" and I have at multiple employers gotten checks straight-up cut to open-source software maintainers. I have also entreated (and in two cases succeeded in convincing) maintainers to start up maintenance programs so we could pay them a yearly fee--because donations are way harder to push than support plans. I have also worked at companies that funded open source projects through donations or maintenance, but there was never a moral obligation there. It was more a method of risk management than altruism. > I consider not paying forward kindnesses paid to you way, way more unfair and unreasonable. Paying forward kindness and being morally obligated to maintain an open source library just because you use it are different things in my mind. It seems like being paid a kindness creates an obligation, which is not that nice. --- Interesting perspective even though I strongly disagree. I'll continue to use open source projects 'AS IS'[0] and I still wont feel morally obligated to maintain them. Similar to how I use linux/BSD and don't feel obligated to maintain the kernel. I'm certainly grateful of course, but I don't feel like there was any sort of contract/exchange between myself and the maintainers that creates an obligation on my part. [0] https://github.com/eropple/auster/blob/master/LICENSE.txt https://github.com/eropple/auster/blob/master/LICENSE.txt
- cbhl 9y agoI think this is a part of the general meme that big companies are making money by taking open source without giving back, and that big for-profit companies could do more for the open-source community.
- falcolas 9y agoIMO, frankly, yes. If you use someone else's code, especially if you're not paying anything for it, you get what you put into it: nothing. The liability for this breach is ultimately owned by Atlassian, not the third party library writer. To quote the most permissive license out there: "THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED."
- lolsal 9y agoTo use an analogy, do you blame everyone that has ever used the linux kernel whenever bugs/vulnerabilities are discovered in the kernel?
- falcolas 9y agoI would certainly blame Google if their Android phones were backdoored, especially if they tried to foist the blame off on the Linux kernel developers - a much more apt analogy since they sell Android phones.
- algesten 9y agoI would be very surprised if something as complicated as Android phones didn't contain anything that can be back doored. Obviously that is Google's problem, but I haven't seen Google (nor Atlassian in this case) claim anyone else is to blame.
- geofft 9y agoIf they use the upstream kernel, yes. Linus Torvalds has been very clear that security is not a priority. "We have one rule in the kernel: don't break userspace. Everything else is kind of a guideline. The whole security thing? It's a guideline that we shouldn't do stupid shit. But people do stupid shit all the time and I don't get that upset." https://www.youtube.com/watch?v=1Mg5_gxNXTo#t=8m28 https://www.youtube.com/watch?v=1Mg5_gxNXTo#t=8m28 Imagine, Torvalds said, that terrorists exploited a flaw in the Linux kernel to cause a meltdown at a nuclear power plant, killing millions of people. “There is no way in hell the problem there is the kernel,” Torvalds said. “If you run a nuclear power plant that can kill millions of people, you don’t connect it to the Internet.” Or if you do, he continued, you build robust defenses such as firewalls and other protections beyond the operating system so that a bug in the Linux kernel is not enough to create a catastrophe. http://www.washingtonpost.com/sf/business/2015/11/05/net-of-insecurity-the-kernel-of-the-argument/ http://www.washingtonpost.com/sf/business/2015/11/05/net-of-... And the Linux kernel has a track record for not being the world's most secure piece of software. Which is fine, it's a project he started for fun. It's certainly possible to pay people for a kernel that they'll stand behind commercially. If you're using, say, a RHEL kernel and a bug or vulnerability is discovered that impacts you, by all means get upset at Red Hat. If you're using a Fedora kernel, though, you made the choice to use it. It's completely unfair for you to get the benefits of running a kernel you put neither time nor money into, and not also the risk of running that kernel.
- GrinningFool 9y agoWhen you use any third party library, you're responsible for its behaviors (or misbehaviors) on your customer's machine. How is it possible to view this in any other way?
- lolsal 9y agoI 100% agree with you. Atlassian is 100% responsible. I'm not sure I would not say they are at 'fault' though. Maybe I'm just quibbling over semantics. I don't know the details of the vulnerability - I would say they were at fault if they did not update/patch a fixed vulnerability.
- throwaway91111 9y agoThis really depends on the use case of the library. It's entirely possible to find bugs that are outside your expertise to fix. I can't speak to this case, obviously.
- geofft 9y agoIf it's free software? Yes, absolutely. To do otherwise is a chilling effect against hobbyist free-software authors in favor of large companies that have the ability to take on that liability. I, as an individual, want to be able to write code in my free time, put it on GitHub, and let it get popular without worrying that maybe it has a bug in it. If people want to start holding me responsible for it, I'm just not going to release it. Maybe you can pay my employer for a commercial license if we think that the cost of auditing it and taking on the liability for bugs is commercially reasonable, but it's also unlikely my employer will be interested.
- lolsal 9y agoI am absolutely not advocating that the library author be held liable.
- deleted 9y ago[deleted]