Linus Torvalds – All Bugs Are Created Equal
Linus is the creator of the Linux kernel and pretty smart guy, everyone knows that. Everyone also knows that he doesn’t care who he insults and feels free to give his opinion filter-free whenever he likes. It’s not a bad thing, he’s obviously really smart and he’s accomplished more than most people ever will. He created the most popular software kernel in the world so he gets to rant about whatever he pleases and, more than that, people should listen to what he has to say.
Still, I disagree with what he says about security here.
The Bits I Disagree With
In fact, all the boring normal bugs are _way_ more important, just because there's a lot more of them. I don't think some spectacular security hole should be glorified or cared about as being any more "special" than a random spectacular crash due to bad locking.
I actually do think that security bugs are more important regardless of number. A system crash annoys me, a compromise can ruin me. If we measure bug importance by effect on the user I think it’s fair to say that having your system hacked is worse than having your system crash, in fact I’d say that having a single system hacked is worse than a thousand systems crashing.
I just really disagree with what he’s saying there and I think that he was probably just pissed off and mid-rant. I wouldn’t really try to understand the motivation but I can definitely say I don’t agree with it.
The Rest
Security people are often the black-and-white kind of people that I can't stand. I think the OpenBSD crowd is a bunch of masturbating monkeys, in that they make such a big deal about concentrating on security to the point where they pretty much admit that nothing else matters to them.It makes "heroes" out of security people, as if the people who don't just fix normal bugs aren't as important.
I can agree here. Bugfixing is important. It’s really important. I hate crashes and I hate lockups and I hate instability. Developers who fix bugs should get lots of praise. Are bug fixes as important as security fixes? There isn’t really a way to measure this, of course. Who am I to say that one is greater than the other? Obviously I believe so but that isn’t the point. It’s varying degrees of importance.
As for OpenBSD I don’t like the project or the attitude behind it. Looking at their page claiming absolute security and then a bit of research into exploits on the system is enough to understand that.
I just stumbled across this while looking up some other stuff. I’m not trying to call Linux out or something silly like that, I just don’t agree with that point.
blog comments powered by Disqus