10 ms·
LibreSSL: More Than 30 Days Later
- bickfordb 12y agoIt's pretty surprising that they are using CVS for a new project
- 1ris 12y agoI think it fits their development process very well.
- wereHamster 12y agoI assume they don't use branches, or merges, or any of the other VCS features which git/mercurial have and which are difficult to do or even impossible in CVS.
- ams6110 12y agoIncorrect, partly. The release cycle is illustrated here: http://www.openbsd.org/papers/asiabsdcon2009-release_engineering/mgp00016.html http://www.openbsd.org/papers/asiabsdcon2009-release_enginee... They do branch and tag the tree for releases, but development is done in HEAD not in branches as would be customary for git. I'm not an OpenBSD developer but my understanding is that the branches are used for subsequent patching of that release, not as part of "normal" new development work.
- tptacek 12y agoYou really think big projects didn't branch or merge before git was developed?
- wereHamster 12y agoI'm sure they did. But wasn't it painful before git/mercurial? That's what I heard from people who used CVS in the past.
- vidarh 12y agoIt is/was painful if you try to merge multiple diverging branches. The CVS solution to that is generally "don't do that", or for everyone on long lasting branches to rebase as frequently as possible. But this is not all that much of a problem in small cohesive teams where everyone with commit rights knows what the others are likely to be working on.
- kasey_junk 12y agoCVS was difficult but there were non distributed vcs that had easy branching.
- tptacek 12y agoIn practice, a lot of the stuff that was difficult about branching and merging was just handled outside the VCS, and projects had rules about what you'd do inside the VCS. It worked, and still does for OpenBSD. At Arbor, the last CVS job I worked (back in ~2003), we did release and dev branches no problem. I don't remember fretting about it much. The big issue I remember is, it was a much bigger deal not to break the build.
- deleted 12y ago[deleted]
- vezzy-fnord 12y agoOpenBSD is developed as a complete operating system following a cathedral model. LibreSSL is part of the OpenBSD base system (as libssl), which is hosted on CVS. Naturally, so will LibreSSL.
- sigzero 12y agoIf you know anything about the OpenBSD project it really isn't surprising at all.
- Touche 12y agoNot everyone does "know anything about the OpenBSD project". So instead of the smug comment, why not just explain why this isn't surprising?
- pestaa 12y agoTo me the comment didn't sound smug at all -- instead it was sort of an insider joke referring to OpenBSD's philosophy to use only heavily battle tested, rock solid software not unlike CVS.
- ams6110 12y agoIt works well for the way they do development and releases, and all their build and test infrastructure is built to use it. And part of it is it's "the devil you know." I have heard that a lot of their devs will use git or hg on their local checkout to help manage their own dev environment. You can find out more about the openbsd philosophy by reading some of the presentations on it at http://www.openbsd.org/papers/ http://www.openbsd.org/papers/
- xorcist 12y agoThey've always held on to CVS, taking it so far that they've taken upon themselves to support their own fork of CVS going forward.
- bakareika 12y agoFun fact: they are not alone in this, I am aware of at least two startups that do the same thing to CVS (one already acquired by Cisco, the other one is ongoing). And having used CVS myself, I strongly disagree with any connotation of "productivity loss because of old SCM" etc. — it all depends on workflow. Kind of like Vim certainly isn't inherently less productive than a shiny new Visual Studio 2022.
- X-Istence 12y agoEvery single last thread about OpenBSD or one of their projects has this same exact statement in it ...
- kchoudhu 12y agoJesus, what is it with this place and any source control system that isn't onboard with the git circlejerk?
- segmondy 12y agoWhat's so surprising? OpenBSD folks don't fall for the next new shiny thing. 10 years from now, something else might take over git, and everyone will jump to it. OpenBSD folks don't care, if what they have works, they stick to it.
- Peaker 12y agoDo you consider "git" a shiny new thing? Using CVS over git in this day and age is a very dumb decision. They may make up for it in other, good decisions. But this decision is a dumb one.
- currysausage 12y ago> But this decision is a dumb one. What is it with this obsession with telling people how to get sh't done? If they write their code on used kleenex using wax crayons and share that using carrier pigeons, I don't give a sh't as long as the finished product is fine.
- deleted 12y ago[deleted]
- danielweber 12y agoIt's a perfect example of bike-shedding. Most readers have no way of evaluating their crypto primitives, or their nuclear power plant, or a zillion other things. But we can evaluate their source control!
- EdwardDiego 12y agoThat bike shed would be way more robust if you used FP to paint it.
- orblivion 12y agoThat's fine, but if (and I have no idea if this is the case here) their reason for not wanting to switch to a new source control system is mere stubbornness, they might find that switching to a more efficient source control system frees them up to write even more good code, fix more bugs, etc.
- deleted 12y ago[deleted]
- brynet 12y agoOpenBSD was one of the first open source projects to make their CVS repositories public, you can read more about it in Chuck Cranor and Theo de Raadt's paper on Anonymous CVS. http://www.openbsd.org/papers/anoncvs-paper.pdf http://www.openbsd.org/papers/anoncvs-paper.pdf http://www.openbsd.org/papers/anoncvs-slides.pdf http://www.openbsd.org/papers/anoncvs-slides.pdf It makes sense, if you consider the fact they have been using for the last ~18 years.
- Panino 12y agoAmong the good and bad stories this year, so far, LibreSSL is the good story of the year. Also happy to hear a bit about the ressl API. To me it sounds like a focused, high-level API that makes it easy to get right and hard to get wrong. So kind of like NaCl. It's clearly the future -- look at the huge amount of software being written for Sodium now, for example. It's huge.
- rakoo 12y agoThe very same tedunangst wrote a piece about this API: http://www.tedunangst.com/flak/post/goreSSL http://www.tedunangst.com/flak/post/goreSSL In which you can see the clear focus on usability rather than capability. To examplify how easy it is, he actually implements the API with a go "backend". I also really like the concept of a simple API where you can't go wrong by default, hope it can make its way into other pieces of software as well.
- ianlevesque 12y agoRelatedly is there an SSL implementation based on NaCL anywhere?
- jfindley 12y agoNot exactly the same thing, but there's CurveCP which is essentially a TCP replacement for creating encrypted communication tunnels. It is part of NaCL and uses the same crypto primitives. It's a really interesting project, but it's not ready for production use just yet, and even when it is I don't think that replacing SSL is necessarily what it's targeting.
- MoOmer 12y agoInteresting and quick work. The story of the libcrypto SRP glass house makes me feel like a little kid who just heard a ghost story. Is OpenSSL being notified of security bugs you all find in your pairing down process?
- clarry 12y ago> Is OpenSSL being notified of security bugs you all find in your pairing down process? Determining whether a bug can actually be exploited (on what system, under what configuration?) is hard work, and it's harder still to prove a negative. Mostly the OpenBSD devs just fix the bug and move on. If it looks like the typical kind of a bug that could lead to crashes, they release a patch against the previous two releases (assuming the code is present there). A lot of the bugs they fix turn out to be "security bugs" only long after someone else finds that out on a version of the code running on another system not hardened by the OpenBSD devs. After 5.6, if any serious bug is found, you can expect to find a patch for it on http://www.openbsd.org/errata56.html http://www.openbsd.org/errata56.html ; however, as the code between LibreSSL and OpenSSL diverges, it won't be obvious whether they apply to OpenSSL at all.
- peatmoss 12y agoI've said this before, but kudos to the OpenBSD Project for shouldering a disproportionate share of the burden of maintaining core bits of our libre/open infrastructure. I can't think of anyone in tech who has not benefited mightily from OpenSSH and who will not benefit mightily from LibreSSL. This article is a good reminder for me to get off my arse and cut my meager grad-student checks to the EFF and OpenBSD project.
- riffraff 12y ago> disproportionate share Disproportionate based on/compared to what? (I agree that the openbsd folks do a ton of good, I am just trying to understand your references here)
- spindritf 12y agoMarket share, funding... Pretty much any metric.
- xnull2guest 12y agoWell, they take on responsibility as stewards, which means they will be the target of criticisms and backdoor attempts, and will need to meet the demands of downstream demand for fixes, requests and help. They also need to (have already) spend time on understanding the code, development and integration. They need to communicate the problems with OpenSSL and what they've done to other people within the ecosystem.
- peatmoss 12y agoWhat spindritf said. OpenBSD has an extraordinarily high impact-to-X ratio, for many values of X (funding, notoriety, number of contributors, unnecessary problematization, glamor, etc.). Even though I'm more likely to use OS X or Linux these days than OpenBSD, OpenBSD would fare better in the absence of most Linux distros, than most Linux distros would fare without OpenBSD.
- dobbsbob 12y agoYou're probably using plenty of OpenBSD software anyways like pf in OSX
- illumen 12y agoSo... * it's broken on other platforms * they broke features in their releases (no QA/testing?) * they're making a new API based on requirements of their own programs that doesn't provide many of the OpenSSL features. * they're using CVS, no public code reviews available. There's no evidence some of the changes were reviewed by someone other than who made the commit. (OpenSSL now does reviews) * no public audit available. * they have some hateful note about hipsters on their web page as an excuse after 5 months to not make it readable. So unprofessional it hurts. * Most changes were done five months ago, with not much at all done for two months. * The test/ directory has very few changes at all. No extra tests have been added. * I can't find a release plan, architecture documentation, or any documentation a serious software project should have. (OpenSSL is working on these though) Finally... their official distribution website doesn't use SSL. That's a major security issue of the face palm variety. Not. Inspiring. Confidence. The OpenSSL project on the other hand has been doing some good work. Please see the projects road map from July to see what they are changing. https://www.openssl.org/about/roadmap.html https://www.openssl.org/about/roadmap.html
- kome 12y ago> they have some hateful note about hipsters on their web page as an excuse after 5 months to not make it readable. So unprofessional it hurts. Are you talking about this http://www.libressl.org/ http://www.libressl.org/ ? That's one of the most readable webpage ever.
- DanBC 12y agoOn iOS the font used to be a horrible script - really hard to read. Currently it's comic sans (or a clone of it). I personally fucking love the site and wish wish wish more people would stop throwing weird stuff in websites. I do think the dig at hipsters is pointlessly antagonistic. Isn't there an evangelism guide for people in open source projects?
- pgeorgi 12y ago> evangelism guide for people in open source projects There are, tons of them. OpenBSD traditionally doesn't give a fuck, and backs up that attitude by shipping solid products. Not exactly surprising given the history of the project (started by de raadt after being kicked out of NetBSD for being hard to work with). If external reviews, github pull requests and documentation galore are important to the GP, they better stop using OpenSSH, which is developed using the same unfathomable development methods as libressl.
- IshKebab 12y ago> Look at all the points where memory is allocated, and then make sure it is freed, exactly one time, no more, no less. C is clearly the wrong language for something this security critical if that's where your bugs are. C++ solved this many years ago.
- AceJohnny2 12y agoWhile I agree that C is the wrong language for security-critical applications (and I write this as a mostly C developer myself), I strongly disagree that C++ is a better language. Sure, it has constructors and destructors and pass-by-reference, but that's not enough, and cons/destr's don't fit the common memory usage-model of performance-critical applications (where an SSL library is often used), which use preallocated memory pools.
- wtetzner 12y agoSeems like an area where Rust could really shine.
- programminggeek 12y agoGood pun.
- tormeh 12y agoHow about Ada?
- krylon 12y agoI think - please correct me if I'm wrong - that Ada has pretty much the same problems as C if you use manual dynamic memory management. Ada supports Garbage Collection in theory, but it is optional, and I don't think many implementations actually supply a GC. Especially since Ada apparently is often used in realtime systems where dynamic memory management is usually avoided altogether (there is a subset of Ada specifically designed for building realtime software that explicitly prohibits any dynamic memory management). Ada is - as far as I remember - much safer with regards to buffer overflows and bounds checking. But the bigger problem is probably that far more developers know C than Ada, and that something like an SSL library intended for widespread use needs to work with many different compilers and linkers. If you use GCC, I think it is possible to compile Ada code using the GNU Ada compiler and link it to C code compiled using the GNU C compiler, but I am not sure how things look if you use some other C compiler.
- felixrabe 12y agoIt kinda bugs me when time-sensitive articles (like those about software) are published without a date on them. The article does not mention a date when it was written, I assume it was recently. It mentions "2014-09-09 FreeBSD advisory", and the date today is 2014-09-28, so September 2014 is a good bet.
- Twirrim 12y ago> In particular, we answer the question "What would the user like to do?" and not "What does the TLS protocol allow the user to do?" This makes me think of the laudable approach taken by the developers for the Cryptography library for python. Expose functions to users with sane and safe settings to users, and provide the abilities to override the defaults if you really must (but in such a manner that it's extremely clear that you're stepping into dangerous territory)
- rocky1138 12y agoOff-topic, but the markup of that page is really interesting. I've never seen someone do this before: <h1>LibreSSL: More Than 30 Days Later</h1> Ted Unangst<p> tedu@openbsd.org<p> LibreSSL was officially announced to the world just about exactly five months ago. Bob spoke at BSDCan about the first 30 days. For those who weren't there, I'll quickly rehash some of that material. Also, it's always best to start at the beginning, but then I'll try to focus on some new material and updates. <h1>openssl</h1>
- _ZeD_ 12y agoWhat's so strange about this markup? It's plain html.
- cygx 12y agoHe's probably unaware of tag omission[1]. The site uses it incorrectly, though: The <p> tag belongs at the start of a paragraph - it is not a separator like <br>. [1] http://www.w3.org/TR/html-markup/p.html#p-tags http://www.w3.org/TR/html-markup/p.html#p-tags
- deleted 12y ago[deleted]
- imanaccount247 12y agoIt is wrong in a rather odd way. Whoever did it seems to think paragraph tags are just line breaks.
- adamrt 12y agohttp://www.w3.org/TR/html-markup/p.html#p-tags http://www.w3.org/TR/html-markup/p.html#p-tags <p> don't need closing tags i prefer closing tags personally, but its not required.
- imanaccount247 12y ago
- Beltiras 12y agoThere is some agonizing done over the rewrite culminating in the need for a redesign of the API. I've wondered why there wasn't a light-weight library that simply implemented the smallest number of protocols to delivered the necessary components for a secure HTTPS connection. You'd have some other library for other protocols, but this one should have the feature of being as light-weight (and small) as possible. Wouldn't that be the cyphersuite of choice for most hosting facilities?