7 ms·
> what exactly is over-engineered and why we as users would even care if it's overengineers somewhere under the hood? Log4J has been a major embarrassment for
by grumpyprole 4y ago
> what exactly is over-engineered and why we as users would even care if it's overengineers somewhere under the hood?
Log4J has been a major embarrassment for the Java community. I suggest you Google it, if you don't know why.
> It's hard to criticize Spring Core
Spring Core is at best a dynamic (reflection based) band-aid to work around Java's lack of expressiveness. It comes at a significant complexity cost and loss of static guarantees. You cannot both love Spring and Java. So which is it? :)
- democracy 4y agoOh, please, ok, there was a security flaw - how does it prove that it is over-engineers? If anything it is too flexible and gives developers too many features so that one of them was compromised.
- grumpyprole 4y ago> If anything it is too flexible and gives developers too many features Over-engineering: "the act of designing a product or providing a solution to a problem in an elaborate or complicated manner"
- kaba0 4y agoAnd that is very much false in case of log4j, it’s likely you just have a mismatch regarding the requirements of enterprise logging — far from trivial. Of course log4j is an overkill for a simple terminal app that could just write to stderr/out just fine. But it is not an overkill at all for an enterprise business app doing millions of transactions each second with multiple instances, with n+1 kinds of config requirements. So for you to be able to call it over-engineered by your definition you would have to know whether the implementation it provides is more complicated than necessary, which I’m fairly sure you can’t know without having taken a look at the actual code. There is essential and accidental complexity as two terms for a reason.
- grumpyprole 4y agoLog4J doesn't just log strings, it has an evaluator that can execute the strings and invoke arbitrary code. There is no enterprise that needs this feature. Describe the actual problem, and let's work out how it can be solved without stuffing a new programming language into a string.
- democracy 4y ago>> a major embarrassment for the Java community Nope, it was not
- grumpyprole 4y ago"The Log4j Vulnerability: Millions of Attempts Made Per Hour to Exploit Software Flaw - Hundreds of millions of devices are at risk, U.S. officials say" https://www.wsj.com/articles/what-is-the-log4j-vulnerability-11639446180 https://www.wsj.com/articles/what-is-the-log4j-vulnerability...
- matsemann 4y agoHow is a library with flaws most of us is not using an embarrassment to the whole community? > If you cannot admit this, then perhaps you are part of a "cultural problem"? I'm sorry, but this edit from you is just stupid.
- grumpyprole 4y agoNot as stupid as claiming it's just another security flaw. Some of us also aspire to better.
- watwut 4y agoYes they had vulnerability. It is embarrassment when you have too many of them or when you dont fix them. The "hundreds of millions of devices are at risk" thing happened only because log4j is used a lot. That is pretty much opposite of embarrassment.