5 ms·
I'm really not sure what the point of this message is. From a PR perspective it is an own goal. It was obvious from earlier statements that self-critique was
by _zrlg 6y ago
I'm really not sure what the point of this message is. From a PR perspective it is an own goal. It was obvious from earlier statements that self-critique was underway. The right time to send another communication is once some improvement has been made.
What is unfortunate is that the project has not publicly defended itself, which is what core should have addressed -- that the situation has been broadly and unfairly misreported. The history of wireguard is bizarre, Donnefeld is hellbent on total control of both the protocol and implementations. He blew the same gasket on NetBSD developers for implementing his protocol http://mail-index.netbsd.org/tech-net/2020/08/22/msg007842.html http://mail-index.netbsd.org/tech-net/2020/08/22/msg007842.h.... The real story here, that the Ars reporter missed because he allowed himself to be compromised by Donnefeld, is how this single person is accumulating and aiming a cult following as he chooses and what are the security and business implications of this in the future. This is a simple tunneling protocol. I don't expect WG to end well. At the very least, you are subject to public zero days and shakedowns if you don't do exactly what Donnefeld wants. A new black hat open source business model of monetization by mob rule and "scooping" low intellect reporters instead of license and implementation.
- ksec 6y agoUnfortunately the NetBSD side's story was not widely known or reported. Otherwise it would give a different perspective to the case here.
- deleted 6y ago[deleted]
- gonzo 6y agoSalter couldn’t even get the CEO’s name right, but he did manage to drag Macy’s spouse into his article. Guy is a muck-racking misogynist.
- tw04 6y agoCurious what the end result was though. It appears they collectively agreed to talk it out in September, then... nothing? Github shows a handful of commits, but nothing major. No chatter on the mailing list. NetBSD hasn't renamed "wireguard" which they said they were considering as an option if Jason was going to keep pushing back on the existing code. The lack of major changes to the code makes me think they also didn't take him up on his offer to scrap the whole thing and start from scratch or port the OpenBSD implementation. Anyone happen to have any further insight?
- ksec 6y agoI sometimes wonder why Jason himself doesn't just do it himself on NetBSD and FreeBSD. Although OpenBSD doesn't seems to have any issues which is also worth mentioning.
- jron 6y agoCan you expand on why the history of WireGuard is bizarre? Do you believe that a blackhat presentation taints the code quality of WireGuard? Do you believe that Donnefeld's desire to maintain tight control over kernel implementations suggests he has ulterior motives?
- _zrlg 6y agoI'm just a systems software guy, I don't know anything more than anyone else on Donnefeld's true motivations. The old saying is where's smoke there's fire. If Salter had intellectual integrity he would have dug into Donnefeld's past, and asked pointed and direct questions about vulnerability disclosure and how he intends to work with or against people that compete with him in the future. All I know is what is obvious to anyone else who spends 15 minutes looking into things. When a reporter spends DAYS digging up details on Matt yet fails to mention anything about the governance and flamboyant history of WG (the NetBSD incident is a carbon copy minus the salacious clickbait of Matt), what the heck is actually going on here? I think Salter is just stupid rather than a fully aware actor in all this. Donnefeld appears to have some kind of fundamental personality flaw that facilitates using people to inflate his ego.. this became such a big deal because he compromised another FreeBSD developer who never fully took responsibility nor publicly rebuked being used by a narcissist. Donnefeld was a nobody in the kernel development community, comes out of nowhere with a relatively simple tunneling protocol that is tightly bound to certain design and implementation decisions, and continually insists implementation is inseparable from the protocol. Noobs celebrate this. Pros look at this and wonder what happens when the governance fails for any reason, when the crypto becomes outdated, how it evolves. Pros celebrate independent implementation because it means a general solution has been achieved and stands a good chance of lasting beyond one person, one company, and one implementation.
- jron 6y agoI'm just a systems guy too so I can't really make judgements on why so much input is needed for the implementation of a seemingly simple protocol. I disagree with there being smoke but I appreciate the reply and it seems like you're not alone in thinking something might be a little off: https://news.ycombinator.com/item?id=24430424 https://news.ycombinator.com/item?id=24430424
- stock_toaster 6y ago> The history of wireguard is bizarre, Donnefeld is hellbent on total control of both the protocol and implementations. Given how bungled implementations can apparently end up (case in point), as a user of wireguard, I'm like.. thankful I guess? This _is_ crypto/security stuff, and I'm glad it is being held to a higher standard by _someone_ at least.
- _zrlg 6y agoThat is misrepresentation, it was never not held to high standards. There were bugs, one serious while much fever was made over less critical corner cases i.e. the pfsense release that has been pilloried by Salter by way of Jason doesn't use jails. There are others like jumbo frames that are not common on internet outside of certain high end carriers.. less common but valid bug, good for new contributors. Most were personal preference: the pseudo driver framework, malloc style etc. There were fixes by multiple people in progress, including two well respected developers at Netgate. The communications were not handled in good faith by the rewrite party by their own admissions, so a rational discussion to fix or to disable the code ahead of 13.0 release in the stable branches was not able to be had with Netgate or by any of dozens of other mature FreeBSD developers. Instead drama was created. I am quite certain the right call would have been made without all of the bad blood spilled had this been conducted respectfully by all parties from the outset. So while new tooling and re-commitment to review process is nice, the processes FreeBSD had in place were already in action and it is sad to not see core assert this. There is also a layer 8 and 9 vulnerability. One guy now tightly controls a protocol in several free *nix kernels and has interesting reactions whenever anything happens without his blessing. He was able to cause a disproportionate reaction by talking to a journalist. This probably doesn't matter if you are encrypting your home PC traffic but it does to people who work in the Internet industry. Say whatever you want about the particular technology and particular individuals, it boils down to whether you think the desire for control of implementation is a weird situation or not.