29 ms·
It is scary to think about how much of web relies on projects maintained by 1 or 2 people.
by 687m786m78 3y ago
It is scary to think about how much of web relies on projects maintained by 1 or 2 people.
- hadlock 3y agoThis is your semi-annual reminder to fork and archive offline copies of everything you use in your stack.
- Dylan16807 3y agoThere's plenty of copies of the code. That doesn't help with the actual problems with the setup.
- ironmagma 3y agoNot that scary when you remember there are some systems that haven't been significantly updated for decades (e.g. the Linux TTY interface). A lot of stuff can just coast indefinitely, you'll get quirks but people will find workarounds. Also this is kind of why everything is ever so slightly broken, IMHO.
- yjftsjthsd-h 3y agoThat only helps if it stays static. For example, if the Linux TTY interface was unchanged for decades to such a degree that nobody worked on it, but then had a vulnerability, who would be able to fix it quickly?
- ironmagma 3y agoPerhaps someone with more knowledge can chime in. But, my impression is that there are vulnerabilities with TTY, it's just that we stay educated on what those are. And we build systems around it (e.g. SSH) that are secure enough to mitigate the effects of those issues.
- codetrotter 3y agoSSH was a replacement for Telnet. But any weaknesses at the TTY level is orthogonal to that, right? Unless you mean, having thin clients use SSH as opposed to directly running serial cables throughout a building to VT100 style hardware terminals, and therefore being vulnerable to eavesdropping and hijacking? But I think when we talk about TTY we mostly don’t refer to that kind of situation. If someone talks about TTY today, I assume they mean the protocol and kernel interfaces being used. Not any kind of physical VT100 style serial communication terminals.
- tingletech 3y agoI miss rooms of green and amber screen terminals hooked up via serial cable. As an undergrad I remember figuring out how to escape from some menu to a TTY prompt that I could somehow telnet to anywhere from. Later, I would inherit a fleet of 200 of them spread across 12 branch libraries. I can't remember how it worked except that somehow all the terminals ran into two BSDi boxes in the core room of the central library, and it had been hardened so you could not break out of the menus and telnet to arbitrary places. Over a year I replaced them all with windows machines that ran version of netscape navigator as the shell with an interface that was built in signed javascript. It was the early days of the web, and we had to support over 300 plug ins for different subscriptions we had. The department that ran the campus network didn't want to let me on the network until I could prove to them everything was secure.
- ciceryadam 3y agoSSH was a replacement for RSH, not telnet.
- hnfong 3y agoThis was on HN two(?) days ago: https://news.ycombinator.com/item?id=39313170 https://news.ycombinator.com/item?id=39313170 > I wrote the initial version of SSH (Secure Shell) in Spring 1995. It was a time when telnet and FTP were widely used. > Anyway, I designed SSH to replace both telnet (port 23) and ftp (port 21). Port 22 was free. It was conveniently between the ports for telnet and ftp. I figured having that port number might be one of those small things that would give some aura of credibility. But how could I get that port number? I had never allocated one, but I knew somebody who had allocated a port. Emphasis mine. Cheers.
- TylerE 3y agoI wonder how many of these things that are just coasting are gonna have issues in 14 years.
- korhojoa 3y agoThis already happened with the kernel console, no more scrollback. https://security.snyk.io/vuln/SNYK-UNMANAGED-TORVALDSLINUX-3005497 https://security.snyk.io/vuln/SNYK-UNMANAGED-TORVALDSLINUX-3...
- ale42 3y agoI recognize it fixed a security issue, but nonetheless it's very inconvenient. I don't always have tmux at hand, especially when the system is booting in some degraded mode...
- ngetchell 3y agoThey're open source.
- szundi 3y agoNot the web though
- ironmagma 3y agoCertainly the web can mostly coast indefinitely. There are webpages from decades ago that still function fine, even that use JavaScript. The web is an incredibly stable platform all things considered. In contrast, it's hard to get a program that links to a version of Zlib from 10 years ago running on a modern Linux box.
- quickthrower2 3y agoThe web is the calm looking duck that is paddling frantically. You want to be using SSL from the 90s, or IE vs. Netscape as your choice etc. Nostalgia aside!
- 5- 3y agothis problem -- great forward compatibility of the web -- has been taken care of with application layer encryption, deceitfully called "transport layer" security (tls)
- KronisLV 3y ago> Certainly the web can mostly coast indefinitely. I'm not sure about that, for anything besides static resources, given the rate at which various vulnerabilities are found at and how large automated attacks can be, unless you want an up to date WAF in front of everything to be a pre-requisite. Well, either that or using mTLS or other methods of only letting trusted parties access your resources (which I do for a lot of my homelab), but that's not the most scalable approach. Back end code does tend to rot a lot, for example, like log4shell showed. Everything was okay one moment and then BOOM, RCEs all over the place the next. I'm all for proven solutions, but I can't exactly escape needing to do everything from OS updates, to language runtime and library updates.
- colechristensen 3y agoHTTP 1.1 isn’t really changing is it? That and a small collection of other things are standards based and not going though changes.
- the_duke 3y agoNginx is still evolving a lot though. Eg: http3 support was stabilized with 1.25.1 , which came out June 2023.
- Gormo 3y ago> Also this is kind of why everything is ever so slightly broken, IMHO. OTOH, things that update too often seem to be more than slightly broken on an ongoing basis, due to ill-advised design changes, new bugs and regressions, etc.
- ironmagma 3y agoI am thinking with things that don't update often, we just get used to the broken parts. People learned to save every five minutes in Maya since the app crashes so often, for example. Every now and then, a PuTTY session will fill the screen with "PuTTYPuTTYPuTTYPuTTYPuTTY[...]" but it's been that way for at least 20 years, so it's not that remarkable.
- sitzkrieg 3y agotangent but i havent seen that happen on any of my putty clients in years and i use it everyday, so i think that finally got fixed? or maybe was a side effect of something stupid
- ikt 3y agonext question: why are people still using putty
- doublerabbit 3y agoWhy shouldn't people use putty? I still use putty because it does what I need for it to do. No need to change just because MS has their own terminals application, which besides I far from trust.
- mcsniff 3y agoYou trust them to run the entire OS and every stack included in it, but not to make an ssh client?
- stusmall 3y agoThis isn't one though. I think the issue he is talking about is around the CVEs that came out with the HTTP3 implementation. This is an area of very active and complex development.
- whatever1 3y agoMeanwhile my anaconda installation died after a casual apt-get update lol I now believe that every piece of software should be shipped as a container to avoid any system library dependencies.
- MightyBuzzard 3y ago[dead]
- ironmagma 3y agoThat is what Snap is for, but there are… issues
- Thaxll 3y agoFor the vast majority of use cases nginx from 10 years ago would not make a difference. You actually see the nginx version on some html pages and very often it's old.
- DarkmSparks 3y agonginx from 5 years ago has some pretty nasty actively exploited CVEs.
- jackcviers3 3y agoIt's not that scary. If a project everyone depends on is broken and unmaintained, someone else will manufacture a replacement fairly quickly and people will vote with their feet. NGINX is the de facto standard today, but I can remember running servers off apache when I began professionally programming. I remember writing basic cross-broweser spas with script.aculous, and prototypejs in 2005, before bundlers and react and node. Everything gets gradually replaced, eventually.
- quickthrower2 3y agoYou can also probably host without a reverse proxy. Also there are alternatives like Caddy. IIS!! And I imaging the big cloud would swoop in and help since their expensive CDNs and gateways will rely on it, or maybe Kubernetes maintainers, since most likely they use it.
- syslog 3y agoI still deploy Apache httpd, because that’s what I know best, and it works.
- deleted 3y ago[deleted]
- yard2010 3y agoBest memberberries ever
- mrtksn 3y agoObligatory XKCD: https://xkcd.com/2347/ https://xkcd.com/2347/
- EasyMark 3y agoI don't worry when it's open source, as if it's that valuable someone will pick it up, or corps would be forced to. I do wish those 1 or 2 devs got more support monetarily from the huge corps benefitting.
- maxamillion 3y agoEvergreen xkcd is evergreen. https://xkcd.com/2347/ https://xkcd.com/2347/
- up2isomorphism 3y ago[flagged]
- ARandomerDude 3y agoHad a nuclear launch code. He doesn’t remember it anymore.
- efreak 3y ago0000?
- mike_hock 3y agoAnd physical access to the football.
- phkahler 3y ago>> It is scary to think about how much of web relies on projects maintained by 1 or 2 people. This is one reason maintainability is very important for the survival of a project. If it takes an extra person to maintain your build system or manage dependencies or... or... it makes it all the more fragile.
- 1vuio0pswjnm7 3y agoIME, the best software is written by "1 or 2" people and the worst software is written by salaried teams. As an end user, it's only the encroachment by the later that scares me.
- BigJono 3y agoYep. IME the only way to make a salaried team of 10 devs work efficiently is to have enough work that you can split it cleanly into 5-10 projects that 1-2 people can own and work on autonomously. Too bad every team I've ever worked on as a consultant does the opposite. The biggest piles of shit I've ever seen created have all been the product of 10 people doing 2 people's worth of work...
- cryptonym 3y agoOn one hand projects developed by 2 passionate devs ; on the other hand a team of entry to mid level devs working on someone else's project for the money. That team changes every 6 month when another company offers more money. If only one or two people are working on a project, that's a high risk for the company. If you got one or two highly skilled people in that team of 10, you are lucky. Managers don't want them to work alone on their project, they want them to help the team grow.
- mcv 3y agoYes and no. Small 2 person teams as vastly more efficient, but who will take over when they quit/retire/die? Larger teams have more continuity, I think.
- Waterluvian 3y agoI think if 2 people designed most of the world’s water treatment plants, that’s not scary. If 2 people are operating the plants, that’s terrifying.
- devwastaken 3y agoThat's why they work well. Not corrupted by corporate systems or group governance. Individuals have better vision and take responsibility.
- akira2501 3y agoHTTP/1, HTTP/2 and HTTP/3 are huge standards that were developed, considered and separately implemented by hundreds of people. It's built in C which has an even more massive body of support through the standard, the compilers, the standard libraries, and the standard protocols it's all implemented on. 1 or 2 people maintain one particular software implementation of some of these standards. It's interesting to think of what a large and massive community cheap and reliable computation and networking has created.
- azinman2 3y agoI mean at that point you might as well talk about the people building microchips and power plants. You can always abstract down, but you're ignoring the fact that nginx is ~250k very important LOC with huge impact on the world. That is non-trivial in its own right.
- akira2501 3y agoExactly, you might as well. It compares precisely to the original hyperbole that two people are somehow the linchpin to the entire internet. For example, how much of that code is the mail server component and how much is the http component? How much does http/1, or http/2 or http/3 take up? How much of that is necessary to keep the internet actually running? I'm not suggesting it's trivial but the original perspective was highly overblown. To think of it another way, if these two men died tomorrow, how much of an impact would it actually have? Some, to be sure, but the internet wouldn't even notice.
- ozim 3y agoIt is also why companies don’t buy SaaS services from single founders or small companies where risk of key people leaving is high impact.
- kjellsbells 3y agoExpand on that comment for me, because it has high impact. I dont doubt the surface logic, but the implication is that to succeed in B2B SaaS, you _must_ be sufficiently well funded to have a decently sized staff team. That is, there are no organic 2 person startups in B2B SaaS. Is that really true? (Obviously once bigco buys such a startup's offering, that startup needs to hire, fast)
- ozim 3y agoYou probably can get your foot in with $500 a month recurring payment if some dev/employee wants to do or try out stuff and his manager puts in credit card. But that is peanuts and for me basically no difference than B2C and that is not something you can put on "customers that trusted us" banner on your landing page. If you want big company to rely on your services and have 50-100 users each seat paid $500 a month form a single company, that is not just some manager swiping CC and for that you have to have a team and business continuity.
- rurban 3y agoNot scary at all. I think much better of such projects compared to ill-functioning multi-people projects which get worse and worse over time.
- enbywithunix 3y agoRelevant Xkcd comic: https://xkcd.com/2347/ https://xkcd.com/2347/
- dang 3y agoWe detached this subthread from https://news.ycombinator.com/item?id=39373804 https://news.ycombinator.com/item?id=39373804. Nothing wrong with it (well, it's a generic tangent but not a nasty one), but I'm trying to prune the large thread.