22 ms·
Theo de Raadt: "You've been smoking something mind altering" (2007)
- cptroot 2mo agoI would love to know how OP came across this email nearly 20 years after the fact
- deleted 2mo ago[deleted]
- SoftTalker 2mo agoIt's one of Theo's more famous dismissals/takedowns.
- DonHopkins 2mo agoSome people keep classic flames alive to deploy in times of need. Theo's good, but he can't hold a candle to the late Marc Cripsin railing about emacs line-mode-visual. Grr. https://www.reddit.com/r/emacs/comments/1tf1iy/imap_inventor_emacs_oldbie_mark_crispin_died_1956/ https://www.reddit.com/r/emacs/comments/1tf1iy/imap_inventor... >From: Mark Crispin, To: comp.lang.emacs >What mindless cretin thought that it should be a good idea to make line-move-visual be the default in emacs 23? I just found out about this charming "improvement" in the worst possible way. Investigation determined that a "routine" software update had just installed emacs 23 and gave me this "improvement". >People wonder why everybody hasn't dumped proprietary desktop software. This is an example why. Emacs' line behavior has well over 30 years of history, and some bagbiter goes and changes it BY DEFAULT. >Add all the cute new features you want. But leave the goddamn defaults alone. >If you want to have your own playpen where you twiddle defaults to your hearts content, have at it. But don't pretend that you produce software for a production environment, and stop telling the Linux distributions that they should "upgrade" to your "improved" versions. People doing real work depend upon those distributions. >It does no good to say "read the release notes" when the affected users don't get the release notes and don't even know that a new release happened. It is also unreasonable to expect users to subscribe to every obscure newsgroup, forum, and wiki to hear about changes that will turn their expectations upside down. >Yes, I fixed my .emacs file. And I'm putting in the same change to all the .emacs files on all the dozens of other machines I use, even though they still have emacs 22, because otherwise this unpleasant surprise will repeat itself over and over again. >Grr. >From: Mark Crispin, To: comp.lang.emacs >They made the wrong decision. Changes to default behavior are a bad idea. Changes to default behavior of the most basic functionality are an extremely bad idea. >I don't care if M-X fart-noisily-with-spray changes its default scent from skunk to lemon. But I damn well do care about the most basic operations: all CTRL single letter and ESC single letter. After 33+ years of using emacs, I expect these to be reliable and not suddenly change. >I wasted hours trying to figure out what the hell was wrong with my file, or my terminal emulator window, or my system. The fact that the problem went away on a different system added further confusion. It was only when I did ESC <n> CTRL/N and saw that it moved me the wrong number of lines, but only on one system, that I realized that emacs changed. And that's when I did ESC X describe-key CTRL/N and read about line-mode-visual, although it did not mention that this was now the default. >Surprise. Grr.
- em-bee 2mo agoi don't know that crispin rant sounds pretty reasonable to me. it's not insulting and the argument is coherent. he has a point.
- DonHopkins 2mo agoTheo's rant about what a hypocritical idiot ESR is also sounds pretty reasonable to me: he has a good point. https://news.ycombinator.com/item?id=48883342 https://news.ycombinator.com/item?id=48883342 ESR's free to make ridiculous laws about eyeballs that aren't true and nobody follows while never actually reviewing any code himself (except for the climate scientists' code which he totally misunderstood and dishonestly misrepresented), but blaming it on Linus was a dick mode. https://rationalwiki.org/wiki/Eric_S._Raymond#Climategate https://rationalwiki.org/wiki/Eric_S._Raymond#Climategate >During the Climategate fiasco, Raymond's ability to read other peoples' source code (or at least his honesty about it) was called into question when he was caught quote-mining analysis software written by the CRU researchers, presenting a commented-out section of source code used for analyzing counterfactuals as evidence of deliberate data manipulation. When confronted with the fact that scientists as a general rule are scrupulously honest, Raymond claimed it was a case of an "error cascade," a concept that makes sense in computer science and other places where all data goes through a single potential failure point, but in areas where outside data and multiple lines of evidence are used for verification, doesn't entirely make sense. (He was curiously silent when all the researchers involved were exonerated of scientific misconduct.) porridgeraisin: Speaking of ICCCM (aka I39L) and X11 selections, have you seen David Rosenthal's glorious rant about the Sun Desktop that somebody leaked to the unix-haters mailing list (who, moi?), which comes straight from the author of the ICCCM and co-developer of Andrew, X10, X11, and NeWS. The Roy Lichtenstein line is classic. What he's touching on by "Why can't they just shut up and do their job efficiently and inconspicuously?" is Mark Weiser's "Ubiquitous/Calm Computing". He's married to Mark's widow Victoria Reich, and they both work on LOCKSS ("Lots of Copies Keep Stuff Safe"). https://en.wikipedia.org/wiki/David_S._H._Rosenthal https://en.wikipedia.org/wiki/David_S._H._Rosenthal https://en.wikipedia.org/wiki/LOCKSS https://en.wikipedia.org/wiki/LOCKSS https://news.ycombinator.com/item?id=44045304 https://news.ycombinator.com/item?id=44045304 PS - I notice that someone filed a bug today pointing out that even your example of dropping a mail message on CM doesn't work if CM is closed. That's a symptom of the kind of arrogance that all the deskset tools seem to show - they're so whizzy and important that they deserve acres of screen real estate. Why can't they just shut up and do their job efficiently and inconspicuously? Why do they have to shove their bells and whistles in my face all the time? They're like 50's American cars - huge and covered with fins. What I want is more like a BMW, small, efficient, elegant and understated. Your focus on the whizzy demos may look great at trade shows, but who wants to have their tools screaming at them for attention all the time? It's like having a Roy Lichtenstein painting on your bedroom wall. Check out his blog, recently he's been writing about his introduction to computer graphics, hacking late at night in the basement of the lab on the PDP-7 connected to the Titan at Cambridge University, and how Coprophagia Is Bad For You! He was employee #4 at NVIDIA. https://blog.dshr.org/ https://blog.dshr.org/ >We managed to get the game to be sort-of playable provided you let the machine win.
- Gualdrapo 2mo ago"Torvalds, via e-mail, says De Raadt is “difficult” and declined to comment further." https://www.forbes.com/2005/06/16/linux-bsd-unix-cz_dl_0616theo/ https://www.forbes.com/2005/06/16/linux-bsd-unix-cz_dl_0616t... Imagine being so hard you're labelled as "difficult" by no other but Linus Torvalds
- TylerE 2mo agoI mean, Torvalds has called basically every person on earth an asshole at some point, hasn’t he? He’s the opposite of being sparing with critisicism, and frankly has historically often used his bully pulpit to do it.
- metoobruh 2mo ago[flagged]
- deleted 2mo ago[deleted]
- ryanmcbride 2mo agoPersonally I believe being an asshole to people is doing something wrong.
- tverbeure 2mo agoThere are many extremely competent engineers who can’t deal with the idea of exposing themselves to public humiliation. That’s especially true in today’s environment where these kind of bully rants have become a spectacle for outsiders. Just google the name of the person who was the subject to one of Linus’ rants about a year ago. Despite being a very accomplished figure in the RISC-V world, top results for his name are links to Linus calling him an idiot. That’s a mark he will have for life. I would die of embarrassment. It’s perfectly possible to critique without being a bully. What Theo and Linus are doing wrong is scaring away a large pool of potential contributors who don’t want to take that risk.
- deleted 2mo ago[deleted]
- oooyay 2mo agoEven very smart, very accomplished people can be very wrong. Xen is seeing a resurgence from Xen Orchestra and I've used it in my homelab. It's quite pleasant. I also, of course, use de Raadt's software as well.
- estebank 2mo agoI think that everyone has the power to be wrong, but to be very wrong with convincing arguments, you must be smart. A smart person can come up with post-hoc rationalizations that hold up under some scrutiny, to the point it is very hard to convince them otherwise. Add to that people who became famous or successful on the back of "being right" on some subject matter, getting used to "being right even in the face of overwhelming push back", and you have a recipe for very smart people being very wrong in very visible/loud ways.
- tptacek 2mo agoOne of his dumber takes. Virtualization replaces an ultra-functional general-purpose kernel evolved over decades to support every conceivable application with a drastically smaller "kernel" (KVM and the userland hypervisor). It's a drastic attack surface reduction, and the empirical data bears that out: kernel LPEs aren't even newsworthy (there's whole repos full of unnamed, unremarked-upon LPEs), and KVM escapes are very rare.
- ummonk 2mo agoHow big is the OpenBSD kernel and userland actually compared to a virtualization layer?
- boricj 2mo agoDoesn't that message date back to a time that either predates or is almost concurrent with the introduction of x86 hardware-assisted virtualization? I wasn't around playing with VMs back then, but I'm not sure that the track record of x86 virtualization 20 years ago was that great.
- tptacek 2mo agoIt does, but that's an argument about implementations, and his comment is an argument about design. Just read it again and see if you think it's reasonable. Pay attention to the tone and (especially) the conclusory certainty he deploys.
- SoftTalker 2mo agoAnd since then, OpenBSD has developed its own VM subsystem vmm(4), vmd(8), vmctl(8).
- tptacek 2mo agoSure, I mean, he was wrong, and I assume he knows he's wrong, and wouldn't say the same thing today. He's not dumb. Just this take is.
- vlovich123 2mo ago> A simple tool was presented, iofuzz, that exposes exploitable security flaws in most, if not all, virtual machines available today. To the knowledge of the author, no similar research has been conducted before. The results produced by crashme, a tool well known for over a decade, locating trivial flaws dem- onstrates this. No virtual machine tested was robust enough to withstand the testing procedure used, and multiple exploitable flaws were presented that could allow an attacker restricted to a vir- tualised environment to reliably escape onto the host system. The results obtained demonstrate the need for further research into virtualisation security and prove that virtualisa- tion is no security panacea. https://taviso.decsystem.org/virtsec.pdf https://taviso.decsystem.org/virtsec.pdf He’s not wrong based on the research at the time. The mistake is presenting this as if it’s something that will be true for all time. Is virtualization a panacea? No. CPU manufacturers can’t even protect against side channel attacks. But it’s completely missing what this provides which is that the difficulty and cost of creating an exploit is higher today than 20 years ago. And it’s amusing to hear someone blasting away at the security of others when BSD has its own share of problems and architectural weaknesses are discovered through popularity of your system being an attack target, not because you’re smarter than everyone else and made better choices (sometimes it can be true in places, but harder to maintain for a big piece of software like an OS)
- DonHopkins 2mo agoMy favorite Theologism: "My favorite part of the "many eyes" argument is how few bugs were found by the two eyes of Eric (the originator of the statement). All the many eyes are apparently attached to a lot of hands that type lots of words about many eyes, and never actually audit code." -Theo de Raadt https://en.wikipedia.org/wiki/Linus%27s_law https://en.wikipedia.org/wiki/Linus%27s_law
- znpy 2mo agoI think de Raadt and OpenBSD are hugely overrated and some takes are as dumb as the one in the post. OpenBSD is only secure because because it does pretty much nothing and does it very slowly (its firewall just recently broke the 4gbps firewalling capabilty, for example) but somehow a cult has formed around it ¯\_(ツ)_/¯
- bawolff 2mo agoIn fairness, minimizing surface area (doing nothing unless you need to) is security 101, so i hardly think that is a criticism.
- znpy 2mo agoYeah it’s one way to look at it for sure…
- hylaride 2mo agoCounter-take: Linux is only secure because of OpenSSH. In all seriousness, the OpenBSD guys are very conservative with technology. The OpenBSD pf stack (as well as much of the kernel) isn't heavily threaded due to the risk of race conditions. They also (correctly) predicted a lot of the speculative CPU attacks by not supporting it by default. They've done a lot of security research and pioneered a lot of open source work around OS-level stack smashing technologies, like memory executable-space protection (W^X), early process privilege separation, memory space randomization, etc. Some of these features are not great for performance, but do help and have been adopted by other systems. You're basically arguing that an armoured car sucks because a Ferrari can smoke it on a race track. There are times you want a Ferrari and there are times you want a Brinks truck.
- rustcleaner 2mo agoIf OpenBSD pretended Qubes OS was a feature prototype/reference OS build and made a fork of OpenBSD to feature-match Qubes OS (calling it QuBSD or something), that would be great!
- jurgenaut23 2mo agogod bless usenet. The good ol' flame wars aren't what they are used to anymore with all this moderation and trolling feeding each other around here.
- deleted 2mo ago[deleted]
- Gud 2mo agoI don't understand the constant (almost always unsubstantiated) criticism of the *BSDs from many Linux advocates. Personally I evaluate each OS by it's merit, and I've concluded that OpenBSD, FreeBSD and some Linux distributions(I use arch btw) are solid operating systems. On the server I prefer FreeBSD because of it's amazing flexibility, and stable yet evolutionary base system and in my opinion, superior init system. Simple RC scripts FTW. I use Arch Linux for superior software and hardware support, related to client usage. I use OpenBSD for various network appliances.
- dlcarrier 2mo agoIf you like Arch and init systems with simple RC scripts, check out Artix Linux (https://artixlinux.org/ https://artixlinux.org/), which is an Arch-based Linux distribution that supports multiple options for init systems.
- ranger_danger 2mo agoI wished more people would take issue with developers' bad attitudes. I know this is an extremely unpopular take, but I refuse to use software where the main dev(s) are openly abusive to others. Sadly this includes the majority of open source operating systems and many other very popular applications... but it's my decision and you're welcome to disagree with me. I am not trying to prevent others from using said software, and I don't look down on them for it. I think if everyone was always forced to separate the art from the artist, then boycotting wouldn't even be a thing, so there should probably be some kind of middle ground.
- rurban 2mo agoThere was no abuse and bad attitude. He was telling the truth about Linux hypervisors. And it got worse since then. Then they talked Xen, which at least has a security boundary. Now everybody switched to kvm with none. Only speed matters, security not at all.
- mvdtnz 2mo ago> You are absolutely deluded, if not stupid .. is abusive.
- ranger_danger 2mo agoDisagree, but regardless, both Theo and Linus have long, storied histories of prolonged habitual abuse without much remorse. Even after Linus "stepped back", it never really stopped after he came back. We'll probably also disagree on what is abuse or not, but that's ok.
- dstnn 2mo agoDude is 100% right
- worik 2mo agoThat is old news, Theo was harsh, arrogant and rude. He was not always right, but always RIGHT!! But ten years ago. What is the point now?
- jraph 2mo agoDon't take this personally, but I am sorry to have to inform you that it was, in fact, almost 20 years ago. Just months after Rihanna released Umbrella, and a year after Mika released Relax.
- dredmorbius 2mo agoI hate to break it to you, but 2007 is rather closer to twenty years ago.
- mvdtnz 2mo agoI don't know who this guy is but this is just a shitty way to interact with people. Presumably he's successful or we wouldn't be talking about him without any introduction, but I wouldn't hire this person to sweep the floors at my office.