6 ms·
This comment from Coda Hale is worth a look: https://github.com/antirez/lamernews/pull/8#issuecomment-2481391 https://github.com/antirez/lamernews/pull/8#issuec
by timf 15y ago
This comment from Coda Hale is worth a look: https://github.com/antirez/lamernews/pull/8#issuecomment-2481391 https://github.com/antirez/lamernews/pull/8#issuecomment-248...
- llambda 15y agoLooks like an unfortunate interaction all the way around: I have to admit reading the blog post I felt that the "dogma" lay on the other end of the table...now this link seems to confirm that suspicion. There is a reason people said, "use bcrypt," and certainly Coda is well qualified to elucidate the details. Side note: It's a little disappointing to see this kind of negativity shoot up on the front page. But by the same token I'm glad that HN readers are so observant and timf linked to a more complete history of what went down.
- antirez 15y agoYou can't evaluate the interaction reading that pull request comments. The key point is that I was marked as clueless for the idea of iterating SHA1. I was replied that it was ok only after other guys showed it was a proven and ok alternative. I don't like when people turn down learning. I don't like dogmas. I also have the bad habit of reacting in a non kind way after being stretched too much, read the insults I got on twitter. I'm usually very kind but there is a limit to what I tollerate.
- ohashi 15y agoReading the discussion comes off as you getting very personal in the attacks while most of the comments were centered around code/crytography. I also am confused by you stating that 'resorting to best practices can be dangerous.' If they are the best practices, they should be the least dangerous one would think? I've got no horse in this race but that's my opinion and confusion.
- nknight 15y agoThings that get the "best practices" label slapped on them are not inherently "best". At best, they reflect conventional wisdom in a particular field. Unfortunately, conventional wisdom is often wrong, and rarely challenged. Eventually, things called "best practices" become the basis of hysterical and utterly worthless Pavlovian responses as occurred en masse here.
- tptacek 15y agoThis particular conventional wisdom was not wrong. Your comment, which consists largely of innuendo, is part of the problem, not part of the solution.
- nknight 15y agoI didn't say it was wrong, I said it was useless. Screaming "use bcrypt" is no more helpful than screaming "don't use goto", and being an ass when someone tries to figure out what the actual problem is just turns them off to your "wisdom".
- tptacek 15y agoYour comparison is false. "goto" is a stylistic nit. Insecure password hashes are not.
- nknight 15y agoForest for the trees. This isn't about technical details, it's a question of psychology. Screaming platitudes at people and being a jerk when they ask "Why?" will not result in them following your advice, regardless of its correctness.
- ohashi 15y agoI understand your argument and I think I understand why you make it. We're trained to be skeptical (as scientists of one sort or another), but in reality, I really do wonder if most best practices actually have inherent flaws or if its a perception issue because we notice the times its wrong and not the overwhelming number of times it is right?
- boundlessdreamz 15y agoantirez was very civilized initially. That pull request has a wall of "use bcrypt" comments. It is just a despicable instance of mob mentality.
- adestefan 15y agoIt's cargo cult cryptography. Saying "use bcrypt" is fine, but understand why you say "use bcrypt."
- icey 15y agoI've seen this a few times on Github^H^H^H^H^H^H the internet - someone makes a snide comment on an thread, tweets about it, and then a flood of dipshit pile-on comments follow.
- tptacek 15y ago"Despicable"? Are you sure that's the word you want to use? I'm not fully on Coda's side on this (it's a silly news site, and I've told more than one HN'er to just stretch SHA1 with iterations), but a great way to guarantee that I end up there is to polarize the discussion with comments like this. It's actually people like you who create stupid flame wars like this. Do you actually have an opinion about bcrypt versus PBKDF1? Or are you just sitting on the sidelines chanting "FIGHT FIGHT FIGHT"? Incidentally: in the fully polarized discussion, Salvatore loses.
- nknight 15y agoIf my first exposure to the world of cryptography and information security had involved someone like that, I'd have written them all off as arrogant quacks to be ignored.