6 ms·
> It's written in an unusual programming language called OCaml, and in a fairly idiosyncratic dialect of it at that. This is of course no problem for a proof o
by Shoop 7y ago
> It's written in an unusual programming language called OCaml, and in a fairly idiosyncratic dialect of it at that. This is of course no problem for a proof of concept meant to support a Ph.D thesis, but for software that's deployed in the field it makes maintenance quite difficult. Not only do we need to be bright enough to understand an algorithm that's literally someone's Ph.D thesis, but we need expertise in obscure programming languages and strange programming customs.
Looking at the code [0], it looks like fairly standard Ocaml. Any particular reason it's difficult to maintain (other than the lack of popularity of FP in general)?
(It looks like the original author of the SKS Keyserver is Yaron Minsky, the guy who convinced Jane Street to use Ocaml.)
[0] https://bitbucket.org/skskeyserver/sks-keyserver/src/default/ https://bitbucket.org/skskeyserver/sks-keyserver/src/default...
- xvilka 7y agoYes, the code looks fairly simple, I would say.
- ghuntley 7y agoLooks like fairly standard OCaml and usage of functional programming idioms. Q: Where's the CI and property tests? If you feel uncomfortable maintaining the code base, start there.
- ghuntley 7y agoThe author of the gist has his CV on his personal website and lists himself proficient in fsharp. :confused:
- gravitas 7y agohttps://rationalwiki.org/wiki/Argumentum_ad_hominem https://rationalwiki.org/wiki/Argumentum_ad_hominem
- cbsmith 7y agoThat wasn't an argument... It was an expression of confusion as to why the author would say what they said.
- ghuntley 7y agoYup.
- pvg 7y agoIt's not. This thing: https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f#gistcomment-2957376 https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d695... is not an 'expression of confusion', it's an attempt at offtopic shitstirring and mockery. It's kind of dumb in the gist - keeping it up on HN (where it's sensibly forbidden) is worse.
- cbsmith 7y agoSo one person said yup, and the other person said nope. ;-) I agree it served to make the author look a bit foolish.
- hinkley 7y agoI’ve gotten stuck maintaining Python code for a testing framework and again for a CI/CD system. The fact that I know less than a junior programmer didn’t really slow me down that much, but it did make me a bit anxious. One of those systems involved a large and obvious crypto component. If the python code had been part of that work instead of merely peripheral to it, I would have rewritten it. Why? Because I can make python work but I can’t tell you if it’s safe. I have no idea what the weird gotchas are that look like good code but are not. What the “printf” of python is. Hackers do. And I know even less about O’Caml. I would not sign up for that gig. Lots of the sort of rational and cautious people you want working on crypto would not.
- ghuntley 7y agoI get that but in this case though this codebase has safety guarantees baked in via the Hindley–Milner (HM) type system whereas your python code base did not. Additionally there's a published, peer reviewed paper for this software that serves as a written specification. Those two things are fantastic resources when coming up to speed with an unfamiliar codebase.
- hinkley 7y agoI’m an old school strong, static typing proponent (strong typing shall rise again!) but I laugh at the notion that it protects you from crypto attacks. Are you a maintainer or an armchair critic? I hope the latter, because if you think type safety is anything more than necessary but insufficient, then that’s number three.
- hinkley 7y agoAlso, there are few enough tests that I had to do a text search for the word test to spot them. How many ml files in the top directory, and the word test appears nine times. So that’s the second big problem with this code, and it’s a huge one. The crypto project I worked on had better test coverage than anything I ever did before and quite possibly since. Because it was a dangerous animal and, like a responsible exotic pet owner, I treated it with respect at all times. Unlike the guy I took over the project from. And because of my paranoid fastidiousness, I stopped a user from shipping with only 8 bits of entropy in their key generator. That would have been a fun bug for a DEFCON presentation.
- literallycancer 7y agoIt looks like other OCaml code bases. Hardly a good thing.
- xvilka 7y agoTo the commenters blaming OCaml - it is being used in the Project Everest[1] (along with F#) for creating a proven network security stack. Basically, they created ML-like language called F*[2], which fits the task perfectly. There is also a pure OCaml implementation[3] of TLS stack, along with x509[4]. [1] https://project-everest.github.io/ https://project-everest.github.io/ [2] https://www.fstar-lang.org/ https://www.fstar-lang.org/ [3] https://github.com/mirleft/ocaml-tls https://github.com/mirleft/ocaml-tls [4] https://github.com/mirleft/ocaml-x509 https://github.com/mirleft/ocaml-x509
- slaymaker1907 7y agoI believe they are using the C target/dialect of F* for Everest.
- diafygi 7y ago> Any particular reason it's difficult to maintain (other than the lack of popularity of FP in general)? A much bigger issue than the language itself is the overall architecture of the server. It uses Berkeley DB as the main database and only handles one connection at a time. So, if your gossip process starts syncing a huge spam key, you block all front-end web requests (see my issue #61[1]). Also, the keyserver is completely synchronous, so you effectively have to cluster multiple keyservers running on different ports and different databases and load balance across them if you want to add any sort of scalability to your setup. Overall, the server code feels like an MVP or academic implementation. Definitely not designed for high scale or the ability to handle abuse like this. It would take a heavy re-write to make get the server code to where it needs to be, which is why no one has stepped up yet. BTW, I'd love to step up and write an sks-compatible keyserver in python (using postgres as the database), so that it could scale using something like uwsgi, but so far I haven't been able to find a mentor who can help me learn the gossip protocol that's largely undocumented. [1]: https://bitbucket.org/skskeyserver/sks-keyserver/issues/61/key-addition-failed-blocks-web-interface https://bitbucket.org/skskeyserver/sks-keyserver/issues/61/k...
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- acqq 7y agoHere in the comment however a new keyserver is presented: https://keys.openpgp.org/about/news#2019-06-12-launch https://keys.openpgp.org/about/news#2019-06-12-launch by dpc_pw and Valodim
- diafygi 7y agoI'm a bit confused as to the point you're trying to make. Can you please elaborate?
- the_why_of_y 7y agoAlso according to TFA, the server apparently can cope with these pathological keys just fine, it's the GnuPG client, "production" code implemented in C, that falls over dead after it has downloaded the key from a server. Which leaves me puzzled why the server needs bashing.
- AnaniasAnanas 7y agoIt's even worse than it seems. The certificates are only a few megabytes long. https://twitter.com/FiloSottile/status/1145091106138394625 https://twitter.com/FiloSottile/status/1145091106138394625