3 ms·
It we start naming and shaming the coder for each flaw instead of working on fixing the process that allowed it to sneak through, we'll see a chilling effect on
by krstck 13y ago
It we start naming and shaming the coder for each flaw instead of working on fixing the process that allowed it to sneak through, we'll see a chilling effect on open source software. There's a reason we have tests and code reviews and security audits...
- talmand 13y agoUnfortunately the tech industry seems to be in mob mode recently so I would think the chilling effect is already well underway. The fact that it has been suggested this was done intentionally before they know the whole story suggests this to me. Never mind the fact that the code was apparently reviewed, so I guess the reviewer would have been in on it as well. There are always people who prefer to play the blame game instead of actually working to solve the problem.
- danielweber 13y agoPart of me wants to see the team give the industry a big middle finger and quit the project, and now companies relying on it have to start spending money to keep it up instead of expecting it to be provided for free. If something is important to you, you should spend more resources than zero on it.
- talmand 13y agoDoes anyone know of a resource that shows who contributed and how?
- phazmatis 13y agoThat would be great. Maybe we could get some TDD people in there. Some competent c engineers, rather than code cowboys.
- MetaCosm 13y agoBecause TDD is the "new" magic bullet, replacing all the magic bullets before it. Also, TDD works great retroactively on large open source projects with vast histories.
- DanBC 13y agoBanks spend a lot of money on their login stuff. Some of those are really awful. Be careful what you wish for.
- nikcub 13y agoI just happen to be speaking to the very reporter who wrote this article prior to him publishing this report. I told him that in 'our world' we don't really emphasize or make much of who introduced the bug, since it is understood that writing secure code is hard. But what required the denial from the developer (and I feel horrible for him) is that this bug gained so much mainstream attention and speculation. It was only a matter of time before a reporter wanting to further the story got in touch with him. He was in a bad situation - don't respond and have that misconstrued or respond and deny and give credence to the theory. We all know that he didn't do it intentionally and in absence of any supporting evidence in all cases these are simple mistakes, but the general public who are currently whipped up in a frenzy around NSA revelations don't know that.
- mcherm 13y ago> We all know that he didn't do it intentionally Actually, I hadn't known that. But this article gave me strong reasons to believe that it was, indeed, accidental. I certainly recognize that this is the sort of mistake that is extremely easy to make.