4 ms·
OpenSSL release announced for Mar 19. Fixes “high” severity security defects.
- peatmoss 12y agoI wonder if any of these will have been already resolved in LibreSSL through their codebase cleanup.
- protomyth 12y agoI wonder if the ones that aren't resolved have been communicated to the LibreSSL team?
- alanpost 12y agoThey have not: "The OpenSSL group do not tell the LibreSSL group about vulnerabilities that they are fixing in upcoming releases." https://marc.info/?l=openbsd-misc&m=142654095813320&w=2 https://marc.info/?l=openbsd-misc&m=142654095813320&w=2
- protomyth 12y agoWell, I had hoped they had changed their ways, but I guess we'll see what the damage is.
- rodgerd 12y agoIt's almost like belittling and mocking people makes them disinclined to work with you.
- protomyth 12y agoIf you are in high risk computing (or any number of fields) and screw up that bad, you better be able to handle being mocked. You should also sift through the mocking and learn something.
- akerl_ 12y agoThis is a pretty toxic part of our industry. Everyone, in every position or role, should be able to accept constructive criticism of their work. Likewise, everyone should give constructive criticism. If your role involves "high risk" $x, you should hold yourself to exceptionally high standards, but that doesn't include the expectation that folks should fling non-constructive mockery at your work. To your second point, learning from other peoples less-than-constructive criticism does not require going out of your way to help those people in the future.
- protomyth 12y agoPeople get mocked for failure. You cannot do anything of any decent impact without getting mocked. Toxic or not that is how it is. You can try to shield everyone or you can deal with it. Heck, this board allows "mocking" in a nice, neat mechanical fashion via down voting. If saying something sucks isn't acceptable then down voting isn't either. The high risk isn't just $. The time people had to spend fixing the last problem was painful. You can bet people will want to vent. > To your second point, learning from other peoples less-than-constructive criticism does not require going out of your way to help those people in the future. Its not going out of your way, its being responsible. Not informing people of danger because they were mean to you is just bad karma on your part. I might not like someone, but I will tell that same someone about any danger. Any other behavior diminishes you as a person.
- rodgerd 12y ago> Any other behavior diminishes you as a person. So does gleeful toxic shittery like mocking people, which you (apparently) support. It's worth noting this sort of attitude doesn't cut it in actual high risk professions, like flying planes. The worst air disaster in history was caused in large part by one pilot belittling another, and the industry has moved away from such modes of operation.
- protomyth 12y agoI do not support the mocking of anyone except politicians (because if you cannot mock your leaders then the canary just died). I can understand how it happens and have slipped myself. I also do not support the withholding of information from a group in danger like you (apparently) do. Sometimes you suck it up and prioritize safety above vengeance.
- protomyth 12y agoThe other e-mail announcing "LibreSSL 2.1.5 released" http://marc.info/?l=openbsd-tech&m=142655686417434&w=2 http://marc.info/?l=openbsd-tech&m=142655686417434&w=2 [ edit: submitted as https://news.ycombinator.com/item?id=9215915 https://news.ycombinator.com/item?id=9215915 ]
- rlpb 12y agoThis is because the LibreSSL group choose not to participate: http://lwn.net/Articles/601958/ http://lwn.net/Articles/601958/
- jquast 12y agoOpenSSL cannot share with OpenBSD team because the OpenBSD team would not think twice about committing those fixes, making those issues public. [A founding value of OpenBSD is about making anonymous access to their code repository: they develop the same tree that we see. Believe it or not, this was a radical stance for its time. This is contrary to NetBSD's policy at the time of the fork: their code was only published at time of release, making contributions very difficult for outsiders, and withholding security fixes. Theo suspected people with commit access developed attacks based on these changes prior to next release.] I can't recall any time where OpenSSH security fixes were withheld. Although OpenBSD developers do not take the time to evaluate whether a bug may always be exploitable, they do not hesitate to announce the possibility. http://www.openbsd.org/errata.html http://www.openbsd.org/errata.html This is contrary to the approach by Linus on the linux kernel, where security issues "are just normal bugs", placing the responsibility of downstream vendors (and attackers) to evaluate whether they are also a security issue, https://lkml.org/lkml/2008/7/15/648 https://lkml.org/lkml/2008/7/15/648
- tptacek 12y agoI do not remember Theo ever telling me in the 1990s that he believed NetBSD team members were using their access to develop attacks. His opinion of the NetBSD team was far too low to give them that much credit. Theo was much more likely to believe that the concepts behind attacks were invented in the OpenBSD tree, and if he had a problem with how NetBSD managed its tree, it was that they wouldn't track OpenBSD fixes. I don't know what Theo's saying these days. It's been over a decade since I talked to him. But I talked to him a lot in the earlier days of the project, during the original audit, during which time I wrote the OpenBSD advisories, sometimes at the Ship & Anchor in Calgary with him. I would remember this accusation. I never heard it.
- 616c 12y agoEvery time I read one of your comments, it is a fascinating look into cryptography. Now you're telling me you were part of the OpenBSD team? I guess I need to search through your past comments, and a quick Google indicates I missed this. Every time you comment here you make me feel so lazy. Haha.