3 ms·
FSF statement on the Bash “shellshock” vulnerability
- cjensen 12y agoThere is a time and a place for banging the Free Software drum and pointing out the deficiencies in proprietary software. This is not the time. The statement is incredibly tone-deaf.
- blcknight 12y agoCare to elaborate? IMHO, it's always the time to advocate libre software.
- RobotCaleb 12y agoThe page read like a pile of propaganda.
- jimktrains2 12y agoWhy though? I have no affiliation with Red Hat, yet the work they do also helps everyone using bash, including me. Additionally, I have the ability to inspect the code to patch it myself (with someone else's patch or my own). I don't need to wait for my vendor to deliver a solution to me; I have the ability to provide the solution for myself (and others). That is what Free Software is about.
- drivingmenuts 12y agoDo you actually have the ability to understand exactly what the patch is doing and all of the potential future ramifications? One thing the Open Source guys just don't frickin' get is that only a very few people have the time or the energy to fully understand everything that goes into their software. Sure, all the source is available, but if I had time to look at it and digest it, I wouldn't have time to do my real, paying job, nor would anyone else. Which is why we have commercial software. Open or closed source doesn't matter if you don't have time or the background to deal with it. Open Source comes from an academic culture where results don't have to produce economic benefits and people have (or had) plenty of time to bang on this stuff until it works (for a given value of works, that they made up). I won't say I'm not grateful for what the Open Source guys and gals have done, but damn, people. Can't you at least recognize that the world more closely resembles Hell than Utopia?
- clavalle 12y agoDo you believe that commercial software shops are dedicating resources to completely understand their software and 'all of the potential future ramifications'? Or are resources dedicated to pushing out product and moving on to the next? Better a hell I know and can see than one hidden. At least there is a chance of seeing the demons before they strike and exercising them without relying on a priesthood, to stretch the metaphor.
- jimktrains2 12y agoIn addition to what clavalle said: > Do you actually have the ability to understand exactly what the patch is doing and all of the potential future ramifications? Do you even get that _chance_ with proprietary software? (Note: I didn't say commercial; you can have commercial, open-source software.) > Open or closed source doesn't matter if you don't have time or the background to deal with it. Yes, yes it does. Mostly because I can pay someone else who does or gain the background myself. This especially true for custom equipment with custom drivers and software. Once the company goes under there isn't a chance at all of getting anything fixed. > Can't you at least recognize that the world more closely resembles Hell than Utopia? If Hell means having access to the shear abundance of software I do, then yes. Take QGis as a singular example. I couldn't pay for Arc; I just don't have those funds. QGIS gives me all the same features for free. While I can't contribute much in the way of code, I do try to help up doing support, helping with docs, writing tutorials, and evangelizing. Ditto for PostGIS (and by extention PostgreSQL) and Grass If free software didn't exist, a lot of the types of work I do just wouldn't be possible.
- holri 12y agoRed Hat found the bash bug and is a successful commercial company with paid developers. Commercial and free software (freedom) is no contradiction.
- ninkendo 12y agoAt least they didn't seem to try and make a point that the bug was discovered quickly. There have been "enough eyeballs" on this bug for 22 years and that still didn't help anybody actually spot it. Their tone seems to be more geared towards "look at how easy it is for anyone to get the fix", which isn't really all that great: most people don't have a toolchain in place that allows them to deploy new versions of bash from source in any automated fashion, so at the end of the day everybody just waits on a "vendor" fix anyway.
- bronson 12y agoOof, you're right. Two paragraphs of content, then five paragraphs of advocacy. The FSF needs to concentrate on the task at hand. Leave the marketing somewhere else.
- Sanddancer 12y agoAye. Especially given how the patch was pretty much just as exploitable, and the patched patch looked just moderately so. Were this more than a press release, it would be discussing a plan of action as to any sort of auditing plan to make sure bugs like this in the future are discovered /before/ they start causing trouble. OpenBSD has shown that small organizations can audit and maintain code with a focus on security and correctness. Why hasn't the FSF, with its greater level of resources, managed to do the same?
- jiggy2011 12y agoThe FSF does not maintain the software, it is a purely political organisation. The GNU project is responsible for bash.
- Sanddancer 12y agoThe FSF owns the copyrights, controls the licensing, etc. They are they corporation that owns the software under the GNU banner.
- jiggy2011 12y agoDoes copyright really mean much if all the software is GNU? Do they both share the same source of funding? How much is spent on political activities (that openbsd does not engage in)?
- ultramancool 12y ago> OpenBSD has shown that small organizations can audit and maintain code with a focus on security and correctness, why hasn't the FSF, with its greater level of resources, managed to do the same? It's simply a matter of different goals. The OpenBSD project has security as a primary goal. They often throw out features, flexibility or portability on the grounds of preserving security. GNU instead prioritizes those features, flexibility and portability, occasionally losing out on security. Security is hard and involves a lot of sacrifice with little evidence of success aside from "oh look, we haven't had any vulnerabilities for a while".
- jiggy2011 12y ago"banging the Free Software drum and pointing out the deficiencies in proprietary software." is exactly the FSF's purpose. It is literally what they are set up to do.
- ChuckMcM 12y agoThey make an interesting point that such responses are harder in the proprietary world, but the counter argument is that security bugs in Windows (as an example) get hotfixed and pushed via the update mechanism pretty quickly. I believe a better message would be that "Even when the vendor who supplied you bash isn't helping you can fix it." but that will depend on what the Apple experience is with bash, which is currently not so hot.
- netcraft 12y agoHas apple released a shellshock bash fix yet? A little googling doesn't show one, just a bunch of hand waving saying most users aren't affected.
- zz1 12y agoBut at least 3 OS of Apple are affected. And Apple didn't make a move. This is going to take more time than gotofail…
- drivingmenuts 12y agoThere's a more-current version of Bash available thru Homebrew, though I'm unsure if it completely fixes the issue or not. I'm leaning more toward "not", since apparently, no patch completely fixes the issue yet.
- deleted 12y ago[deleted]
- IvyMike 12y ago> the solution is to put energy and resources into auditing and improving Sadly but not surprisingly, when your labor pool consists of volunteers, few of them sign up for this thankless task. I don't know how to solve this problem. I never liked "given enough eyeballs, all bugs are shallow". In the worst case, it devolves into "someone else will do it".
- blcknight 12y agoI think it's a big misconception that the labor pool for libre software is volunteers, it's paid -- by Red Hat, IBM, Intel, Canonical, etc. In this case, bash had plenty of resources to be fixed quickly, it wasn't a problem at all. There's unwieldy projects like OpenSSL that probably have far too critical of a task for few too few developers, but generally, most open source products are developed by paid developers and are doing just fine
- IvyMike 12y agoWhen you've got that many people in charge of security, nobody's in charge of security. In the end, who is responsible for this bug being out in the wild?