3 ms·
Fair enough. But to me it was the smell of a toxic Java ecosystem, where people had to use crappy software even though they knew how bad it was. It took a simp
by jacquesc 5y ago
Fair enough. But to me it was the smell of a toxic Java ecosystem, where people had to use crappy software even though they knew how bad it was.
It took a simple problem and turned it into a clusterfuck of configuration and complexity.
- ivan_gammel 5y agoJava ecosystem is rich and much more developed than anything else. There are plenty of better solutions on the market, both open source and commercial. There exist alternatives to log4j for a while, e.g. logback, which is the default option for Spring Boot applications - there was absolutely no need to use log4j2. It was always a free choice. It is worth mentioning, that any even very basic solution always has a possibility to shoot in the leg, and only professionalism of the developers of the client code can avoid it, so the real reason why this is happening now on a massive scale is that Java world is big and has probable hundreds of thousands, if not millions of developers, who do not have enough knowledge or experience to write better code, understanding all the possible side effects and other consequences of their decisions. This was going to happen eventually. It will happen again, but maybe next time it will be a Python or TypeScript library. Would it be right to call their ecosystems toxic? I honestly do not know. But let's at least have some respect for people who have built it, almost for free.
- jacquesc 5y agoWhy can't we point out that the "default" choice for most java shops is one that is massively overcomplicated, a nightmare to use, and subject to security disasters like we are seeing? This wasn't "unknowable". Using overly complicated, poorly designed software is a direct cause. Why should I show respect for software I hate using and that causes problems for the entire tech community? I appreciate that they built it for free. I write open source code too, and glady accept criticism if I release something that sucks (which I do often) This saga is a lesson in choosing the right tech, and switching off libraries built for use cases 100x more complex than what 99.9% users need.
- samhw 5y agoI'm not a Java developer, but I don't quite understand your complaint. You haven't used the library in question, you don't have any experience beyond the 'smell of the ecosystem' two decades ago, but you're opining at length on its 'poor design' and proneness to security disasters. What knowledge do you have, about this library which you've never used, which qualifies you to say that it's especially prone to security vulnerabilities - other than hindsight bias?
- ivan_gammel 5y agoMost of the Java software is in fact not affected because it is using different logging solutions. It is not „default“ as you say and in many cases it was still a reasonable choice made by people with a lot of experience, because the library isn’t bad. It has plenty of useful features, and the fact that once in a decade someone found a vulnerability in an obscure part of it does not mean they have to switch now or reinvent the bicycle with own logging. As for respect… did you do the code review and security audit of every dependency that you use? Do you do it regularly with all updates and patches? What makes you confident, that this is not going to happen with your favorite tech of choice?
- kbenson 5y ago> Why should I show respect for software I hate using and that causes problems for the entire tech community? You aren't expected to. You're expected to show respect for the medium with which you are expressing those thoughts (HN), and the other people you are communicating with on that medium, by keeping the discussion civil and doing your part to keep it from devolving I to a flame-fest. Almost nobody cares that you have and express dislike for this software. They care that you're doing it in a way which encourages additional discourse which isn't useful and wastes everyone's time. At extremes it's the difference between staying you think a person is immoral or untruthful with reasons and calling someone an asshole. One of those is easier to have an actual discussion over than the other.
- jacquesc 5y agoYou're right, it was a bad take based on an old, strangely emotional experience I remember. Apologies
- stefan_ 5y agoOf course the ecosystem is toxic. Java is literally the only ecosystem in the world where people regularly run into classloader issues because of conflicting logging libraries. And when it happens, that is a smash the fucking computer moment for the momentous stupidity that lead to it. Yes, it's free. No, the vast majority of users never actively opted into it. No, it's not disrespectful to suggest that a log library that interpolates parameters was never fit for purpose.
- ivan_gammel 5y agoI’ve been writing on Java since v1.0, and had the mentioned classloader issue probably once - in mid-2000s with something on JavaEE. This class of problems was back then called DLL hell, and guess where the „DLL“ comes from? Hint: not Java. In any case, it is quite rare by now and calling ecosystem „toxic“ because of that?.. Pretty sure you haven’t seen the others long enough.
- itronitron 5y agoIn many ways it was a trailblazer for npm and the modern javascript 'ecosystem'