3 ms·
Can we just stop with the weaseling please? > Fundamentally, a scalar multiplication function was returning the wrong value for a very specific input because o
by fefe23 3y ago
Can we just stop with the weaseling please?
> Fundamentally, a scalar multiplication function was returning the wrong value for a very specific input because of a combination of the pre-existing complexity and unsafety of some optimized assembly, of undocumented assumptions, and of the neverending state of flux of open source code.
So, basically, it's everybody's fault except for the maintainer of the go crypto code. Which, coincidentally, is the guy writing this blog post.
Oh, pre-existing complexity, huh? I wonder who put that there. It probably fell from the heavens.
I would certainly feel much safer using code from someone who is able to say they made a mistake. This is not about blame. This is about being able to take responsibility.
I wouldn't have said anything if the whole tone of this blog post wasn't "here, children, let me tell you something you can learn from". How about you learn from it first, Obi Wan?
Now feel free to downvote me, you hypocrites.
- aflag 3y agoDo you know for a fact that it was all written by the current maintainer? Though, even if it was. I'm not sure they are intentionally not admitting a mistake. When you work in a shop with blameless culture, you end up learning to always talk like that and you don't even notice.
- baby 3y agoI have to admit I don’t understand your comment. I’ve looked at the Golang stdlib and its crypto parts (disclaimer, I found a CVE in the math parts), and found the assembly code pretty awful. This was before filippo was working at Google. It’s all about performance, similar to how openssl has fast but unauditable code for crypto. There’s no documentation and it’s hard to understand how that code was produced. From some discussions I had with filippo years ago it sounded like he agreed and was trying to clean parts of these now that he was working there. It looks like progress is being made, and if he can share his learnings along the way let’s benefit from that instead of being mad at him no? Sharing is caring. I mean even in a world where he would have written that code originally, what’s wrong with being transparent about it? Everybody writes bugs.
- traceroute66 3y ago> This was before filippo was working at Google As a fan of filippo and and avid hater of evil-Google, I am pleased to point out that.... "Last May I left my job on the Go team at Google"[1] [1] https://words.filippo.io/full-time-maintainer/ https://words.filippo.io/full-time-maintainer/
- fefe23 3y agoSo you are saying while he worked there he didn't do anything about the problem, and now that he's gone he's shit-talking his old employer? I have no beef with either Filippo or Google or Go. Or you for that matter. But this weaseling needs to stop. Now feel free to downvote me, you hypocrites.
- traceroute66 3y ago> So you are saying while he worked there he didn't do anything about the problem, and now that he's gone he's shit-talking his old employer? Huh ? When did I say that ? I posted what I did because the OP made it sound like filippo was still working at Google. I just wanted to point out that as of next month it will have been a year since filippo left. Beyond that, I was NOT proferring any sort of opinion on what fillipo may or may not have done whilst wearing the Google hat.
- Xylakant 3y agoEven if we assume that all of the code was written by the author of the post, it‘s much more helpful to reason about how the mistake happened than just bluntly saying „I made a mistake and it will never happen again.“ Because it will, at least if you don‘t understand where that mistake came from, what underlying assumptions were made and not documented at the time, how the code evolved so that the assumptions were no longer valid. All of the code that‘s involved in this bug probably seemed reasonable at the time, all decisions made have sound reasons. Making the non-constant-time code constant time? Reasonable security practice. Implementing the code in assembly for performance reasons? Sounds about right. Implementing the incomplete formulas? Makes sense, complete formulas were not available. And so on. Every step reasonable, and yet, a bug happened. And that‘s the valid learning, and I‘m fairly confident that most of us can learn from being reminded of that.
- fefe23 3y agoIt's not about who wrote that code. It's about responsibility. If you are the maintainer of shitty code, then at the very least communicate that publicly. Don't come out with how bad your code is after the fact! After he was responsible for that code for years, he now goes public and matter of factly states that all the code was shit the whole time. Well why didn't he do anything about it then? What did he think the job description of being maintainer entailed? Filippo wasted no time shitting on other crypto projects, like GnuPG, from what then looked like the high ground. And now he leaves Google and by the way the supposed high ground was an optical illusion (and that's the charitable phrasing). My theory is that you people like this kind of story because it helps you cope with your own mediocrity. If Google and Golang have this kind of laissez-faire approach, why should I have higher standards? We'll just call it a life lesson as if it was handed down from heaven, as if things HAD to be this bad. Sprinkle some "bugs happen to anyone" and "you can't have 100% security anyway" on top and your shit burger is finished. Now feel free to downvote me, you hypocrites!
- affinepplan 3y ago> Sprinkle some "bugs happen to anyone" and "you can't have 100% security anyway" on top and your shit burger is finished. I mean, yeah. both of these statements are unconditionally true.