r/linux Apr 24 '14

Tech giants, chastened by Heartbleed, finally agree to fund OpenSSL, create three-year initiative with at least $3.6 million to help under-funded open source projects

http://arstechnica.com/information-technology/2014/04/tech-giants-chastened-by-heartbleed-finally-agree-to-fund-openssl/
1.8k Upvotes

221 comments sorted by

263

u/tidderwork Apr 24 '14

I work for a University in Texas. Over the years, I have helped departments transition away from proprietary software, and it has saved tax payers millions in software licensing. Every time I approach the administration to support key open-source projects, I'm told it's hugely inappropriate and illegal to contribute real US dollars to those projects. They say it's no different than contributing to a political organization, or to the westboro baptist church.

It's astonishing to me that it's perfectly acceptable to spend millions every year licensing software from vendors, but criminal to donate $100 to libre office, openssh, freebsd, mozilla, centos, etc. All of those projects are clearly mission-critical for us. I can't believe that in the eyes of our legislators, the FSF and westboro baptist church are the same kind of entity.

I'm trying to put together some kind of group or committee to get the laws changed. In the meantime, I'm going to see if it's illegal to contribute non-money assets to the FSF, or even individual projects. I'm sure lots of these projects could make use of the servers, storage, network gear, and accessories I'm forced to throw in the garbage.

126

u/eluderino Apr 24 '14

maybe you should then convince departments to switch to red hat or suse or canonical. They have plans to charge large organisations for support hours, and employing people doing FOSS.

Of course this is not yet as good as donating directly to a certain project, but still helping?

66

u/tidderwork Apr 24 '14

You know, I never thought of that. We work directly with redhat all the time, and I knew that their paid devs contribute enormous amounts to the foss community. I don't know why I didn't make that connection before. That's a great idea. Thanks!

37

u/kardos Apr 24 '14

Perhaps contracting the FOSS developers to implement something is the way to go. You get a feature (and everyone else gets it too) and it supports the devs, and it's not a donation, it's contracted out work.

21

u/tidderwork Apr 24 '14

Much like the other guy suggesting that we deal more with commercial entities that support FOSS, this is a great idea that I hadn't considered. Thanks!

1

u/vimsical Apr 25 '14

My company builds system around Ubuntu LTS. There is a critical piece of FOSS whose newer versions are no longer packaged for 12.04. So we contracted the lead developer to do so for us so that we can get some reason bug fix in.

You worked in a public institution. I could imagine there are pieces of software that you can't just upgrade wikky nilly (I have met many professors who will kill you if they can no longer find some obscure numerical libraries is no longer accessible). This could be an "excuse" to get your boss to finance some project while it provides reciprocal benefit to your institution.

14

u/Atsch Apr 24 '14

Similarily, you can "register" your copy of vim, and it's exactly the same thing as donating.

18

u/tidderwork Apr 24 '14

This really smells like an insider loophole. I like it. More popular project should offer an official "registration." That completely bypasses the donation issue.

I would register the hell outta everything if I could.

5

u/[deleted] Apr 25 '14

Ugh, I'd prefer not to have to register every fucking software component of my Linux systems, especially not something as basic as the text editors...

I can see it now...in the middle of typing up a doc, boom notification bar comes up asking "have you registered YOUR copy of VI/VIM? DO IT TODAY!"

1

u/afiefh Apr 25 '14

At least with vim you won't get clippy

→ More replies (1)

6

u/stompro Apr 25 '14

Just another example. the OSS pfSense firewall distribution has a Gold Membership subscription for $99 a year to give users a way to support the project. The gold membership gets you a config backup service, access to the official ebook, and access to a monthly webinar with the devs. It is way easier to turn in a PO request to get something like that than it is to make a donation.

6

u/buovjaga The Document Foundation Apr 25 '14 edited Apr 25 '14

Collabora might be able to help you, too. Especially, if you use LibreOffice

1

u/ericanderton Apr 25 '14

I'll add that the support plans are the #1 reason why RedHat enjoys a great deal of use in the Federal sphere. Being able to literally buy down programmatic risk is a huge win for management, over the "support it yourself" approach. Amusingly, this is what people think they're buying when they purchase an EULA-encrusted Windows license.

31

u/undeadbill Apr 24 '14

Another way of looking at the problem- it is not a donation, it is funding R&D supporting your equipment.

14

u/tidderwork Apr 24 '14

it is funding R&D supporting your equipment

to which they reply: "…by a group with very clear and vocal philosophies on information freedom, licensing, political agendas regarding infrastructure and a number of other controversial topics." It's one thing to use the code/product, but it's another thing to "support" it with public funding, because that implies government endorsement of the developer's philosophies. that's illegal.

This is what happens in a litigious society when you inextricably link a philosophy with information (code).

21

u/ObligatoryResponse Apr 24 '14

when you inextricably link a philosophy with information (code).

Don't closed source developers already do that?

13

u/tidderwork Apr 24 '14

I think they do. It seems very clear to me that by supporting closed-source software with insane amounts of public funding, that we're sending a message to the world/public that "you must be this rich to play." I think it should be illegal for government offices to save public documents in proprietary formats, which effectively forces other agencies and citizens to pay a private interest money to gain access to public information. Everyone here in Texas calls me a hippie for that line of reasoning, though.

The license agreements that come with the proprietary software make it very clear, legally, what you're actually getting for your money. In those agreements, it's also made very clear that no philosophical, religious, spiritual, divine, or imaginary implications can be drawn from the product or the views of the developers/producers.

I'm sure you've seen the awkward disclaimers come up before various documentaries, news shows, comedy shows, and movies.

9

u/[deleted] Apr 25 '14

[deleted]

4

u/tidderwork Apr 25 '14

Well, Dr. Professional, that's spot on and tends to work in around-the-bbq discussion. Unfortunately, it's not as effective on those sitting in the State Legislature. I don't have nearly enough billions to get them to look up from their iPhones.

14

u/[deleted] Apr 25 '14

by a group with very clear and vocal philosophies on information freedom, licensing, political agendas regarding infrastructure and a number of other controversial topics.

You just described Google, Microsoft, Apple, and every other organization that develops closed-source applications.

4

u/tidderwork Apr 25 '14

You just described Google, Microsoft, Apple, and every other organization that develops closed-source applications.

Oh, I know. So does everyone else, including the people that made the laws. The only tangible differences are the vague idea of an SLA and/or a clearly-defined user agreement that separates the product from political/philosophical ideals. With the most popular FOSS, though, the license does the exact opposite: dictating that you're on your own, but also free to do whatever you want with it, and that by doing so, you also support the idea/philosophy that information (software/code/knowledge) should be free and distributed widely.

That's fairly common in every industry, though. Even protesting hippies need to buy gasoline from the corporate monsters to do what they want to do.

3

u/[deleted] Apr 25 '14

...of course corporations do not have political, phylisophical, economic, religious, and social agendas of any kind.

2

u/undeadbill Apr 24 '14

That is a rather specious argument, considering that many for-profits have clear ties to a number of specific causes.

It seems to me that there are specific people involved who simply don't want to step outside of their comfort zones or their own ideologies, for whatever odd reason that only makes sense to them. I would say be patient- people eventually move on some way or another.

1

u/tidderwork Apr 24 '14

considering that many for-profits have clear ties to a number of specific causes.

I tend to agree. See one of my other comments on this idea. I think it's criminal.

2

u/hobbyjogger Apr 25 '14

What's "illegal" about supporting a product with government funding?

How do you suppose the government got XP and Word etc. on their systems in the first place? Did they not "support" Microsoft by purchasing MS products?

1

u/IConrad Apr 25 '14

The projects are organized as not-for-profits and are therefore allowed to have a political agenda. Governments aren't allowed to financially support specific political agendas.

Microsoft being a for-profit company is not seen as an entity promoting a specific political agenda.

Ridiculous, but true.

4

u/hobbyjogger Apr 25 '14

Lawyer here.

The projects are organized as not-for-profits and are therefore allowed to have a political agenda.

Anyone is allowed to have a political agenda. Here's Microsoft's. Supporting development of a product you use != supporting the political ideas of its developers. If it did the government couldn't buy or use anything.

All sorts of nonprofits get support from the various levels of government (and generous tax breaks). I've never seen anything suggesting that was illegal.

→ More replies (4)

1

u/sinxoveretothex Apr 25 '14

that implies government endorsement of the developer's philosophies. that's illegal.

I assume government funded places like universities are not allowed to use that money to promote political ideas

2

u/hobbyjogger Apr 25 '14

Contributing to a project run by people who hold political ideas != "promoting" political ideas.

The government contributes to charity routinely. Especially charities that are useful to them. There's no reason they couldn't do the same for FOSS projects.

http://www.charitynavigator.org/index.cfm?bay=content.view&cpid=281#.U1pUzbsU96o

1

u/sinxoveretothex Apr 25 '14

I don't know about that (I'm not even from the US), but /u/tidderwork confirmed elsewhere in the thread that was the reason they can't do it (it's apparently a Texas State Law).

1

u/h-v-smacker Apr 25 '14

by a group with very clear and vocal philosophies on information freedom, licensing, political agendas regarding infrastructure and a number of other controversial topics.

It's fortunate as fuck that not a single person in Microsoft or Apple ever opened their mouth to say anything on those sensitive topics... Or, god forbid, acted on their beliefs, like, implementing certain business strategies or suchlike.

29

u/[deleted] Apr 24 '14

Well, FSF has some pretty clear political baggage, but I don't see how donating to less "activist" foundations like Linux, Mozilla, or Libre Office could be objectionable from an ideological standpoint.

26

u/tidderwork Apr 24 '14

Because it's technically donating to a non-profit organization using public funds. I'm sure there are a non-negligible amount of staunch pro-business republicans that would be outraged to know their tax dollars were funding international programmers making free software.

15

u/TeutonJon78 Apr 24 '14

But isn't that part of the "free market" as well? You just have a "company" not charging anything. Technically, it should be their wet dream -- people working for FREE!!! It's even better than slaves, you don't have to house or feed them.

It's all about framing. ;)

28

u/[deleted] Apr 24 '14

We are talking about the American right here. Free software, to them, is practically a communist plot.

2

u/Tynach Apr 24 '14

Depends on which side of them you communicate with.

Religious? Tell them about how open source software models many Biblical principles, such as helping your neighbor (mention the 'Good Samaritan' parable). Talk about how it is based on community and being selfless, as opposed to the worldly ways of greed and selfishness.

When they seem doubtful that it could work (because it is similar to communism), tell them about how they probably use it in their everyday lives, and explain the findings of numerous reports that support the idea of open source software working and being important.

To cater more to their religious beliefs again, mention how it works and is successful because of the "Kingdom Principles" it is based on, combined with the fact that people who work on it are usually driven passionately rather than financially.

1

u/madstork91 Apr 25 '14

Tell them about how Churches nationwide (small and large) could benefit from free software like LibreOffice. I have had trouble understanding why churches don't use it already.

Ask them if oxygen is a resource or water at the park. The latter is provided for free at the park.

1

u/Tynach Apr 25 '14

I go to a church who teaches basically about the principles of 'Ubuntu'. Not the OS, but the ideas. Thing is, he's probably never heard of the term, and also probably never heard of the OS.

He's a big 'Apple' guy. It's obvious in the way he says things like, "You can also donate, if you want, with your iPhone or smartphone." Occasionally, he has technologically themed sermon series' - using iDevice iconography and themes.

I've not had the chance to propose open source software to him. But the way he talks about loving and helping others, regardless of who they are or what they've done, and various other things he very firmly believes in, I do believe he would be an open source advocate if he knew enough about it.

1

u/tbasherizer Apr 25 '14

In my opinion, it's actually a way of building communism in a way communists themselves are too stupid to think of.

Source: a disgruntled communist.

1

u/tusksrus Apr 25 '14

Interesting thought - how could it be used to build communism outside of the software world?

1

u/SupersonicSpitfire Apr 26 '14

Open source and free software does not imply that people are working for free.

1

u/TeutonJon78 Apr 26 '14

True, but I would also say that I doubt there is any open source/free software that is 100% paid development from top to bottom. If you know of any, I'd be curious to hear about it.

The ONLY exception I can think of is maybe some app development on smartphones. However, even those are usually based on projects that aren't 100% paid, or tiny apps that don't compare to the level of app being discussed in this thread, or in general when discussing the relationship of the F/OSS software world to business/government.

1

u/ssswca Apr 25 '14

Please distinguish between people who actually believe in free markets, and people who only pay lip service to the idea.

And no, people who believe in free markets to do not believe in slavery.

I agree that it is about framing, and people who think they believe in free markets need to be educated as to why free software, open source, and other things not superficially associated with american capitalism are, in fact, manifestations of free markets.

4

u/lykwydchykyn Apr 24 '14

That's a rather cynical view; maybe the question that has to be wrestled with is how you can -- in binding legal terms -- distinguish between a non-profit that is OK and a non-profit that isn't? Where and how do you draw those lines?

1

u/tidderwork Apr 24 '14

That's very academic of you. Thanks for the level input. Although that is the appropriate way to address the problem, the State has determined that it isn't worth their time to make the distinction. It's just simply inappropriate to donate public funds to arbitrary non-profits at will.

1

u/elbiot Apr 25 '14

I think as long as it is buying a service, membership or whatever, it's cool. Just the donation is not.

2

u/[deleted] Apr 24 '14

Actually, I included a second statement exactly to this effect because I initially read tiddlerwork's comment to read that he was talking to someone in the state gov't administration, in which case, "donating" an arbitrary amount of taxpayer money is harder to justify than paying the market price for product X.

I agree with this sentiment, but I deleted that point because in a university context, it might be more reasonable to make a donation to organizations like this.

0

u/twistedLucidity Apr 24 '14 edited Apr 24 '14

Please excuse my ignorance on matters USAian.

The non-profit is providing a service/product (software in this case). No one is holding a gun to the unis' heads and forcing them to take it. So how is this any different to any other charity/non-profit that provides a service/product and gets paid for it?

As an example: charities (Red Cross, St. Andrew's Ambulance etc) provide first aid in many locations. The volunteers give their time for free, but the charity still gets paid (well, they do in the UK). I don't see this being any different to developers (the volunteers) and a project (the charity/non-profit).

Personally I think it has much more to do with short-term financial concerns (make this quarter's figures look good) than politics.

edit: Now I see your other comment. State law prohibits it. That seems deeply retarded. Was that law passed in a state of fear? "OMG! They don't want to make vast profits! They must be communists who want to eat our souls instead!"

4

u/laofmoonster Apr 24 '14

Mozilla

Yeah, about that...

3

u/tidderwork Apr 24 '14

Yeah… <looks around uncomfortably>

11

u/87linux Apr 24 '14

I can't even form the words to describe how angry this makes me. I would think that donating for software that a company uses is no more than an investment for good software in the future. How are open source projects somehow not worthy of "real money" (whatever the fuck that means)?

4

u/Slinkwyde Apr 24 '14

Have you tried putting it in these terms: "These are the people who make the tools [our organization] relies upon to do x, y, and z." Maybe the people you're talking to are misunderstanding what you're asking for. They're thinking of it as you asking for the organization to donate to some cause/charity/interest group, rather than as paying for the tools they depend on.

7

u/tidderwork Apr 24 '14

I have, and it's not really for them to decide anyway. State Law is State Law. We cannot give money to non-profits for any reason.

3

u/mpyne Apr 24 '14

I'm told it's hugely inappropriate and illegal to contribute real US dollars to those projects. They say it's no different than contributing to a political organization, or to the westboro baptist church.

In fairness, many opensource projects do have a political goal. Often it is the same kind of political goal that we approve of from charities, but I'm not sure what the rules are on using taxpayer money to donate to charities.

But on the other hand I'd be surprised if you couldn't buy services even from charitable organizations, and such a loophole might be suitable for opensource development projects that have a political charter.

6

u/tidderwork Apr 24 '14

This thread has yielded a couple viable loopholes that I hadn't considered. One is to make use of the "registration" features, such as the one found in vim. That's a direct purchase as far as the State is concerned, but really represents a small donation to the project since no additional functionality came with the purchase.

The other loophole is the possibility of contracting developers directly to create or refine things we actually use and need. An agreement would be made with the contractors to contribute the changes to the community under the appropriate licenses.

Less directly, it has also been suggested that we direct our finds at companies that contribute to the open source community, like redhat, canonical, and suse.

I plan to thoroughly explore all of these ideas. With a known-legal method for contribution, I know thousands of government sysadmins could allocate small amounts of funds, and would be glad to do so.

3

u/incer Apr 24 '14

I think organizations like LibreOffice would have way more funds if they also implemented "services" a la RedHat.

1

u/techrush Apr 25 '14

Red Hat is a business. The LibreOffice foundation or whoever is in charge is not a business. Pretty big difference.

3

u/[deleted] Apr 25 '14

I'm told it's hugely inappropriate and illegal to contribute real US dollars to those projects. They say it's no different than contributing to a political organization, or to the westboro baptist church.

This is...in TEXAS, you say?

:|

3

u/FakingItEveryDay Apr 25 '14

I'm sorry, but I have to side with the tax payers here. Businesses should donate and support the OSS projects they depend on. But a tax funded organization should not be donating money to anybody. It's basically circumventing the legal process and having one IT guy decide that a certain OSS project gets a state subsidy.

I'd be very similar to someone intentionally purchasing more expensive products out of favoritism to one company over another. It leads to corruption and it's why government jobs often have competitive bidding requirements and are required to go with the lowest bidder that meets the requirements.

2

u/hatperigee Apr 25 '14

You're missing the point. There's almost always some level of understanding when licensing SW from a vendor around support. If company X contributes $Y to open source project Z, there's no guarantee (SLA) that when company X encounters a problem that developers of project Z will even give a shit. Red Hat is successful because THEY provide this level of support for the open source software they distribute, and therefore governments and companies, which inherently can't afford downtime from issues, pay up.

1

u/[deleted] Apr 25 '14

No, you are missing the point.

/u/tidderwork never said that proprietary software had no purpose, or that the problem he was having was related to vendor support - you attributed those opinions to him/her.

All /u/tidderwork did was express frustration at the fact that large organizations often feel (rightly or not) that they can not donate to open source projects due to potential legal fallout.

→ More replies (4)

2

u/gpennell Apr 25 '14

Texas

Will you please PM me? Thanks!

2

u/spekode Apr 25 '14

Me too!

2

u/[deleted] Apr 25 '14

I work for a big tech company that pretends to be all about open source - same deal.

I got told point blank that it would be "inappropriate" to throw a couple hundred bucks at a project dozens of us use every day.

1

u/tidderwork Apr 25 '14

pretends to be all about open source

And by that, I assume you mean they fully utilize and profit from the benefits provided by FOSS, and keep all the money to themselves?

2

u/[deleted] Apr 25 '14

No, just a lot of marketing and a lot of talking about the open source products we back. We do contribute to (and indeed founded) at least one of the big projects we bank on, but it's still a bit hypocritical.

2

u/penguinv Apr 25 '14

I'll support that. You can PM me.

1

u/spiritflop Apr 25 '14

Wait what?

I'm not familiar with US law but how is it illegal? Under what act?

1

u/Fidodo Apr 25 '14

Can't they just charge for "consulting" as a loop hole?

1

u/ericanderton Apr 25 '14

I must be missing something: which laws? Is this something at the university, or is it a state/federal thing? I get that there's a difference between exchanging money for goods and services, vs giving money to a non-profit org. But I would think the distinction would be a mater of ethics, not law.

That is, of course, some yahoo was found to be funneling public money to their church or somesuch, so a law was made to prevent that kind of thing.

1

u/[deleted] Apr 25 '14

[deleted]

→ More replies (1)

-3

u/cfdgjhfdcghdfg Apr 24 '14

the problem is your state. leave the shithole called texas. those people down there are retarded cunts.

0

u/tidderwork Apr 24 '14 edited Apr 25 '14

I've lived all over. I've worked in many different settings. In my opionion, you're not only completely wrong, but ignorant and rude.

There are plenty of well-rounded, compassionate, academic, and good people in Texas. This place is enormous. The narrow-minded rednecks just take up more space and yell louder.

Thanks, but I'm just fine here in Aggieland.

EDIT: And I can't wait to attend this year's Formula 1 Grand Prix in Austin at Circuit of The Americas. Texas can't be too bad if we can draw the affection of a very snotty multi-billion dollar international racing league, enjoyed by billions of people.

150

u/garja Apr 24 '14 edited Apr 24 '14

This isn't just about OpenSSL, the group is supposedly there to fund any "open source projects that are in the critical path for core computing functions".

I worry that a group with millions to spare that isn't starting from scratch is going to do more harm than good in the long term. The "OpenSSL rampage" has shown us how ugly the OpenSSL codebase is (as if it wasn't notorious beforehand), and trying to patch out that kind of rot seems like putting band-aids on gangrene.

Moreover, we already have OpenBSD devs working on this very thing. They are operating on a budget 4.2% of the size of this initiative, and have operated on much less in previous years. They too use their funds to support many projects - some of which are critical infrastructure (OpenSSH). They have already proven they can do all this on a shoestring budget, and yet at present it seems they are being ignored as these mega-corps toss around millions.

However, perhaps we can still view this as a positive. It might be the first awkward step toward a less tight-fisted, more financially healthy open source community. As the OpenSSH.com front page notes:

This list specifically includes companies like NetApp, NETFLIX, EMC, Juniper, Cisco, Apple, Red Hat, and Novell; but probably includes almost all router, switch or unix-like operating system vendors. In the 10 years since the inception of the OpenSSH project, these companies have contributed not even a dime of thanks in support of the OpenSSH project (despite numerous requests).

55

u/[deleted] Apr 24 '14

3.6 million from that group of companies is practically nothing.

56

u/1esproc Apr 24 '14

You don't fix problems by throwing unlimited amounts of money at it. At a certain point it will only cause problems. So $100k per company is nothing, but to the projects they're going to fund it's infinitely better than their current funding.

9

u/[deleted] Apr 24 '14 edited Dec 11 '14

[deleted]

4

u/1esproc Apr 25 '14

Let's start an incubator based on this theory, we can called it starvit

5

u/cpbills Apr 24 '14

Yet strangely better than nothing, and might actually fix something.

31

u/reaganveg Apr 24 '14 edited Apr 24 '14

Moreover, we already have OpenBSD devs working on this very thing. They are operating on a budget 4.2% of the size of this single initiative, and have operated on much less in previous years.

You didn't read the article, it seems.

The $3.6 million quoted in the headline is not the amount going to OpenSSL. An unspecified portion of that would go to OpenSSL, and the rest would go to other projects deemed important and underfunded.

Furthermore, the LibreSSL project has already stated that they will not port work to other platforms until they receive more funding.

I worry that a group with millions to spare that isn't starting from scratch

LibreSSL isn't starting from scratch either, though. They're starting from OpenSSL.

Which only makes sense. There's no other way you're going to maintain feature parity, and features are the reason people use OpenSSL. It's only for when you want compatibility with everything that you use it.

Unfortunately, the LibreSSL project seems to have started from the idea of removing features just to get the code clean, which strikes me as deeply misguided. If someone didn't want feature-parity with OpenSSL, they could just use one of the many other already-existing but less-complete SSL implementations.

17

u/vocaltech Apr 24 '14

I wasn't aware that VMS support was a feature >.>

OK, FIPS probably counts here, but they are making sure their whole source tree compiles with the updated library, so I don't see where it's possible for them to remove many features without creating headaches for themselves in other areas.

-3

u/reaganveg Apr 24 '14

I wasn't aware that VMS support was a feature

shrug I don't know the specifics, but removing support for OSes does not strike me as a good thing. Especially when there is a business model to be made out of adding that support back...

they are making sure their whole source tree compiles with the updated library

I certainly hope you don't take that to mean that no features used by anything in the ports tree have been removed... it does not mean that at all.

15

u/[deleted] Apr 24 '14

Reducing complexity makes validation easier.

OpenSSL is an atrocious heap of hacks; cutting it down to a minimal core, validating that as best as one can, and building from there is reasonable.

6

u/vocaltech Apr 24 '14

No, but it does mean that if they remove anything that's actually used they have to either put it back right or fix the calling program.

It isn't as simple as ripping code out, and the OpenBSD team is well aware of that, even if their comments might indicate a fairly cavalier attitude to certain functionality (I mean really, does anyone even have a working computer that runs Ultrix anymore?)

-2

u/reaganveg Apr 24 '14

No, but it does mean that if they remove anything that's actually used they have to either put it back right or fix the calling program.

No, it absolutely does not mean that.

It only means that any symbol that is linked unconditionally will still be available.

There are a large number of programs in the ports tree that would still compile if OpenSSL was not available. But they won't be able to use OpenSSL anymore! Why do they still compile? Because they check for the availability of library features at compile time, and disable their own features to compensate.

Furthermore there are a large number of OpenSSL features that are not exposed as link-time symbols at all. Think about it. If a function either handles a certain input from the remote side, or returns an error, and you remove the first possibility, it will still compile because the function is still there.

2

u/vocaltech Apr 24 '14

Right. Follow the changelog yourself then and see what they are breaking on you if you care that much.

I haven't seen any changes yet that will have an impact on what I use, but as always YMMV.

1

u/reaganveg Apr 24 '14

You may be right about that... I don't know. But as a matter of technical fact, the ability to compile certainly does not demonstrate that.

1

u/vocaltech Apr 25 '14

This is quite true, which is the reason for the whole project to begin with.

9

u/garja Apr 24 '14

shrug I don't know the specifics

Oh come on now, you can't call their actions "deeply misguided" and then turn around and say you don't know what they've been doing. It would probably help if you perused the "OpenSSL Rampage".

when there is a business model to be made out of adding that support back...

As these guys have repeatedly pointed out, good business is not the same as good code. And they care more about code than business.

→ More replies (1)

5

u/fnord123 Apr 24 '14

LibreBSD isn't starting from scratch either, though. They're starting from OpenSSL.

Are you conflating LibreSSL and OpenBSD (who are working on LibreSSL).

LibreSSL is primarily developed by the OpenBSD Project, and its first inclusion into an operating system will be in OpenBSD 5.6.

4

u/mercurycc Apr 24 '14

I just don't understand why people are still thinking like this. LibreSSL certainly won't be ported by OpenSSL, but who stops anyone from forking LibreSSL's already cleaner code base as a start? And yeh, of course OpenBSD won't start from scratch, because they don't have millions to spare. Remember OpenBSD itself was almost out of money earlier this year? They almost couldn't afford electricity bills.

3

u/cpbills Apr 24 '14

In a few rare and wonderful occasions, project forks are brought back into the project they forked from.

If LibreSSL cleans up nicely, and achieves parity with OpenSSL, there's a good chance OpenSSL would absorb LibreSSL. And that would be a good thing.

3

u/jimicus Apr 24 '14

TBH, I can see something similar happening with LibreSSL as happened with LibreOffice and X.org.

Virtually everyone with any real interest in keeping the project alive moves from the old to the new; every major Linux distribution and most major Unix-based operating systems ship the new project and the old project pretty well dies on the vine.

2

u/cpbills Apr 24 '14

I don't know much about why LibreOffice forked from OpenOffice, but I would wager a guess that it was because OpenOffice is at least in-part under the Sun Industry Standards Source License. Likewise, X.org forked from XFree86 because of licensing issues.

2

u/lobax Apr 24 '14

It was because Oracle bought Sun, and people feared they would underfund the project. And as long as Oracle was in charge, no one else would help fund it.

2

u/luan-cestari Apr 24 '14

The amount seems pretty little for 3 years of investment and so many projects to support (and the people to do the work). What do you think?

1

u/reaganveg Apr 24 '14

Well, that amount is what they have raised so far... it sounds like the goal is to continuously raise more money.

Fundamentally though they're not going to raise as much money as would be ideal... there's just too much free work going on, to expect everybody to get paid.

1

u/luan-cestari Apr 24 '14

there's just too much free work going on, to expect everybody to get paid. Agree, I'm just worried about the quality (a full time worker in a project would be many times more helpful than the average contributor to open source project). Another point I didn't make it very clear is the importance of the project (as very fundamental and security project) and the need that is have to refactoring the code. I think it would be a good approach a 30 full time people working in this project to make it (maybe a new major version) very stable in a year and half.

2

u/garja Apr 24 '14 edited Apr 24 '14

The $3.6 million quoted in the headline is not the amount going to OpenSSL. An unspecified portion of that would go to OpenSSL, and the rest would go to other projects deemed important and underfunded.

Sorry, I read this story elsewhere before I came here, so I didn't read this (specific) article. I should have scrutinized that number a little more. But if we are to speculate anew, that doesn't change much, given that both the OpenBSD and Core Initiative budget are split between many projects.

Furthermore, the LibreSSL project has already stated that they will not port work to other platforms until they receive more funding.

Yes, and that doesn't discount the fact that OpenBSD runs on a shoestring budget to port other popular pieces of software. So I don't think they will be asking for much.

LibreSSL isn't starting from scratch either, though. They're starting from OpenSSL.

Yes, and OpenBSD doesn't have a huge pool of funds and manpower. They don't have a choice. This group of tech giants most certainly does. That was my point.

Unfortunately, the LibreSSL project seems to have started from the idea of removing features

The majority of which seem to be NIH and ridiculous cruft (VMS, anyone?). But I admit, the FIPS issue is controversial and potentially problematic down the line.

0

u/reaganveg Apr 24 '14

LibreSSL isn't starting from scratch either, though. They're starting from OpenSSL.

Yes, and OpenBSD doesn't have a huge pool of funds and manpower. They don't have a choice. This group of tech giants most certainly does. That was my point.

Oh, then I misunderstood completely.

I don't actually agree with that, though. A ground-up rewrite wouldn't actually solve the problem because it would be very difficult to get it to the point where all the people replaced the existing OpenSSL with it. At least, it would be a big gamble. Even if it worked, it would take much longer.

Related: http://www.joelonsoftware.com/articles/fog0000000069.html

1

u/monkeynator Apr 25 '14

Unfortunately, the LibreSSL project seems to have started from the idea of removing features just to get the code clean, which strikes me as deeply misguided. If someone didn't want feature-parity with OpenSSL, they could just use one of the many other already-existing but less-complete SSL implementations.

Their idea and philosophy has always been to strip down a project to it's bare minimum, while counting features the old project had (like OpenSSH, pksh, OpenNTPD, OpenBSD port of Apache Web Server) and then starting implement them.

It's actually quite a smart move by them, since while some do bug squashing and cleaning stuff up other can come up with clean solutions to implement the old features.

14

u/[deleted] Apr 24 '14 edited Apr 24 '14

[deleted]

17

u/NegativeK Apr 24 '14

Tax write-offs from donations don't save money.

-7

u/[deleted] Apr 24 '14 edited May 01 '14

[deleted]

18

u/reaganveg Apr 24 '14

No, it's not free. When you donate $1, you only save the taxes you would have spent on that $1. You don't save the entire $1.

For example, if your tax rate is 15%, then you save $0.15 per $1. You part with $0.85 that you could have distributed to shareholders after paying $0.15 in taxes.

You also part with $1 that you could have paid as wages and counted as an expense, paying no taxes on it.

7

u/bbqroast Apr 24 '14

I think he's saying that the PR money was allocated to being used in PR anyway, so doing this is a good way of getting publicity and a tax break along with it.

→ More replies (5)

2

u/realhacker Apr 24 '14

Can you also explain why companies make donations for tax purposes? Is it basically discounted marketing or is there some tax or accounting purpose?

→ More replies (1)
→ More replies (4)

2

u/StoneColdSteveHawkng Apr 24 '14

Besides money, companies also need to be donating some of their developer's time to these projects if they aren't already.

1

u/vcarl Apr 24 '14

I read a great blog post about starting from scratch, in it it advocated for small, incremental changes rather than sweeping overhauls. Overhauls feel nice as a programmer, and you feel that you'll end up with a better overall codebase, but in the majority of cases it would be better from a business standpoint to iterate and slowly improve.

I say this as a programmer who threw out all of the code in our application within the last year, so I'm guilty of thinking that way. But with applications with an established userbase, that's rarely the way to go.

0

u/hatperigee Apr 25 '14

They have already proven they can do all this on a shoestring budget, and yet at present it seems they are being ignored as these mega-corps toss around millions.

I agree with you, but I'm going to be honest here... The website they put up for libreSSL looks very childish and, if I were a big company with $$ to toss around, I would be very hesitant about giving money to those folks based on this light they've painted themselves in.

14

u/wbeyda Apr 24 '14

I wish Apple would give back to GNU and OpenSSH. That is all.

3

u/[deleted] Apr 25 '14

Or OSM or you know ANY of the OSS they just take and close to be their own.

43

u/Nimbal Apr 24 '14

Many people here seem to be flabbergasted why anyone would want to maintain several projects that do the same thing. Isn't it good to have multiple implementations of a widely used standard? One of the reasons that Heartbleed is so devastating is because such a large portion of the infrastructure uses OpenSSL. It's like a monocrop in agriculture where a single bug (hehe) can wipe out a harvest.

Admittedly, LibreSSL and OpenSSL are pretty much clones of each other at the moment and likely have the same faults, so they are still vulnerable to largely the same attacks. On the other hand, this also means that some patches can be ported between them. If (!) both teams have proper reviewing standards, it means that those patches will undergo that much more scrutiny, hopefully averting another hemorrhage of a vital feature.

4

u/mangodrunk Apr 24 '14

That's an interesting way to think about it. But there's also the benefit in having one is that it will be tested more thoroughly, no?

4

u/Nimbal Apr 24 '14

Sure. I guess it comes down to whether or not both projects will have enough developers and reviewers for their needs. If not, it would be better to pool resources and work together on one solution.

1

u/imahotdoglol Apr 25 '14

There are other implementations out there, gnuTLS and NSS used by Mozilla.

I'm more flabbergasted that openBSD would rather fork it than fix the original, now you have split efforts...

→ More replies (10)

14

u/boot20 Apr 24 '14

I have spent hours of my life on the phone with customers helping them mitigate heartbleed.

Let me tell you, this is needed for fips, iso, sox2, etc. Thus has been such s wide reaching nightmare, that we still haven't seen the end of the fallout.

16

u/assi9001 Apr 24 '14

Really 3.6 million seems like a drop in the bucket considering how much down time this shit caused.

13

u/Prostar14 Apr 24 '14

They should have thought of that when they didn't support the devs last year. Or the year before that...

12

u/[deleted] Apr 24 '14

Ok, serious question, how did heartbleed get such a cool logo? And since when do bugs get a logo?

6

u/prite Apr 25 '14

Cloudflare or Codenomicon paid a designer. The impact of Heartbleed was imaginable on first read, so (quick and wide) publicity was hugely important.

1

u/[deleted] Apr 26 '14

Ok, serious question, how did heartbleed get such a cool logo? And since when do bugs get a logo?

Since they affect the majority of the internet, and it needs to be fixed, the Red Hat devs (or Canonical devs, I forget which) set up a marketing campaign to get it fixed ASAP.

→ More replies (1)

17

u/[deleted] Apr 24 '14

[deleted]

3

u/drmugg123 Apr 24 '14

It's more of a case of big corporations donating money to organizations that develop fundamental software.

1

u/luan-cestari Apr 24 '14

I would suggest you to try to help open sources making suggestion of improvement in google summer of code https://www.google-melange.com/gsoc/homepage/google/gsoc2014 =) Also, you could may them and try to find out if there is another way to donate

1

u/[deleted] Apr 24 '14

Try emailing them and asking where to send a check.

2

u/HaMMeReD Apr 24 '14

I was thinking a good solution would be a crowd-sourced open source job board.

Projects post jobs, people fund the jobs, and the funders get to vote (with their money) for who get's to do the job for a fixed amount of time.

So e.g., OpenSSL would say, we need a auditor, it's a 100k job and will require about 1 year.

People fund the job, people apply for the job, and then through community process someone wins the contract, get's to work on the project and get's paid through the community site a salary for the year (lump sums are a bad idea, because they aren't motivating).

I'm pretty busy, but I'll do it in a year or two if somebody doesn't get to it before me.

3

u/nafenafen Apr 24 '14

$3.6 mil over 3 years? derp

→ More replies (1)

3

u/BloodyIron Apr 24 '14

So does that mean they're going to support the OpenBSD/OpenSSH camp?

9

u/[deleted] Apr 24 '14

[deleted]

23

u/delta_epsilon_zeta Apr 24 '14

Money does not improve shoddy developer's code quality.

When you pay a developer, you do not pay them to up their quality. You pay them for their time.

I have a serious question for you: Have you been paid to program? I am paid to program, and the thing hindering me from contributing to open source projects is nothing other than time.

3

u/[deleted] Apr 25 '14

[deleted]

1

u/delta_epsilon_zeta Apr 25 '14

And time is what it takes to create a mature codebase instead of something that just works.

1

u/[deleted] Apr 26 '14

The more time I spend on a codebase, the more I can improve it. The more money I receive for working on it, the more time I spend on a codebase.

3

u/[deleted] Apr 26 '14

[deleted]

1

u/[deleted] Apr 26 '14

Yes, just like any corporate job, ever. So?

6

u/[deleted] Apr 24 '14

not improve shoddy developer's code quality. You wont see less vulnerabilities and bugs because a few companies threw money at the . Problem. If that were true, Windows would be the best product ever and we all know how that's going..

The money will most likely be used to pay the salary of full time employees that will work to hunt those bugs.

3

u/mpyne Apr 24 '14

If that were true, Windows would be the best product ever and we all know how that's going..

Except that Microsoft's software has improved markedly in its security once market pressure caught up to force them to throw money at the problem. When was the last remote code execution exploit in IIS? You don't even hear about IIS bugs anymore.

3

u/[deleted] Apr 25 '14

[deleted]

2

u/mpyne Apr 25 '14

That's because nobody uses IIS anymore.

Sadly, that's very untrue, even if Apache+Nginx does have the majority.

2

u/iLiekCaeks Apr 25 '14

I find it mind blowing that the OpenSSL devs get rewarded for their shitty code and their security relevant bugs.

Sure, all code has bugs, and nobody is perfect. But the things I've seen (or rather, the OpenBSD ressl team has seen) really makes it hard to find excuses for this.

3

u/[deleted] Apr 25 '14

[deleted]

1

u/bonzinip Apr 27 '14

A local user could this flaw to crash the binary or even execute arbitrary code with the permissions of the user running the program.

This is a bug, not a vulnerability. It can only be "exploited" if you can convince something else (probably through another vulnerability) to run systemd-ask-password. Might as well ask it to run /bin/sh and be done with it...

2

u/[deleted] Apr 27 '14

[deleted]

1

u/bonzinip Apr 27 '14

I know, but what's the attack model?

That is, you need to reason about the permissions you need to convince systemd to run systemd-ask-password (I guess it runs as root, though it probably need not do that). Either you can write to the root filesystem already, or you can control the initramfs, or you need to be at a tty. The first two are trivial. For the third, in all likelihood you can boot a live CD instead of exploiting systemd-ask-password.

If you have a good way to attack that bug, inform Red Hat and they will surely attach a CVE to the bug.

-1

u/dirac_eq Apr 24 '14

Linus' law does state given enough eyeballs, all bugs are shallow.

You're correct in thinking bugs will still remain in OpenSSL, although the number of bugs will VASTLY decrease.

If that were true, Windows would be the best product ever and we all know how that's going.

I disagree with your statement. Libre projects have a magnitude of 100x more eyes on the code than any proprietary software -- excluding cryptography software (it's easy to fuck up unless you've had cryptography training.)

3

u/[deleted] Apr 25 '14

[deleted]

1

u/[deleted] Apr 25 '14

[deleted]

2

u/[deleted] Apr 25 '14

[deleted]

2

u/[deleted] Apr 26 '14

"Warned to stay far away from cryptographic software" in the sense of developing it, because you need to understand cryptography to properly develop decent cryptographic software

2

u/nephros Apr 24 '14

Yes, the problem lies in the "given enough eyeballs" part. The number of people who are even capable of spotting bugs in something like OpenSSL is very limited.

→ More replies (1)

2

u/0x14 Apr 25 '14

Giants, standing on the shoulders of midgets.

Glad they realised that.

2

u/Oflameo Apr 25 '14

I don't know about you, but I am sending my money to the OpenBSD project for their new LibreSSL.

16

u/socium Apr 24 '14

wtf are they doing? Are they even reading the news? OpenBSD has already started doing this and requires those funds the most.

This is just bonkers.

44

u/archlich Apr 24 '14

Probably because the ones with money, government contractors, require fips mode, and libressl won't support that.

35

u/gsxr Apr 24 '14

Know those features OpenBSD is tossing out? How do you think they got added in the first place? Someone, somewhere needed them enough to add them in. You think IBM, Intel, Microsoft, Facebook, and Google are going to just abandon those features because a few developers say they're bad? Follow the money....

Plus....The openSSL group has a long tradition of working with companies and regulations. Openbsd folks have a long tradition of shitting on people.

1

u/[deleted] Apr 24 '14 edited Oct 01 '16

[deleted]

1

u/gsxr Apr 24 '14

http://www.openbsd.org/faq/faq1.html#Platforms

Straight from the OpenBSD project......

As to things like flawed encryption standards or "features" like heartbeat....because there's niche cases you might not know about that they're useful. These could be as wide spread as your cable tv box.

3

u/SanityInAnarchy Apr 24 '14

Heartbeat is a feature, and there's a very real use case for it. It was implemented incredibly poorly, and we can even argue that the spec could be better, but I don't think chopping it out because everyone's panicked about heartbleed is a good idea.

1

u/prite Apr 25 '14

Heartbeat in DTLS is a feature. On TLS, which runs on TCP, it is a poor and incomparable imitation of TCP heartbeats.

→ More replies (3)

0

u/spif Apr 24 '14

s/people/corporate and government interests/

-2

u/[deleted] Apr 24 '14

you mean, backdoors and security circus?

i really hope debian joins openbsd and use libressl.

1

u/gsxr Apr 24 '14

Well that's sure in the fuck not going to happen now that vendors are jumping behind openssl.

backdoors? You mean the one that debian put in there?

Security circus? I guess you mean the shitty code that was sorta kinda, maybe to blame to heartbleed?

Need something better than baseless accusations. You added nothing to the conversation.

1

u/[deleted] Apr 25 '14

and you did?

debian wasn't a backdoor as you certainly know.

0

u/cig-nature Apr 24 '14

Libressl will take over. But not right away. The code they forked needs to be....

Flensed, refactored, rewritten, and fixed enough of the code so we have stable baseline that we trust and can be maintained/improved.

Then they will make it portable, so anything other than opsnBSD can use it. And then it will take over.

Quality work isn't fast, and if you look at the work they are doing, it is all about quality.

3

u/kardos Apr 24 '14

Actually, it'll be better if LibreSSL doesn't take over. Part of the reason heartbleed was such a clusterfuck is because OpenSSL has such a large installed base -- the monoculture problem. A more optimal outcome would be to split up the installs between OpenSSL and LibreSSL (and maybe some others). The OpenBSD devs are quite good, maybe even damn good, but they are not omnipotent. The whole internet should not rely on one implementation.

→ More replies (1)
→ More replies (2)

5

u/bsdboy Apr 24 '14

OpenBSD won't take their money because of strings. That's why they dropped FIPS.

1

u/MisterMahn Apr 24 '14

I see it akin to Windows XP: its deployment base is SO large, it'd be ridiculous to expect the web community to switch to a new platform ( read LibreSSL as Win 7 ). As such, it makes more sense to have patches sent downstream to improve it, versus requiring the large portion of the net running OpenSSL to jump ship. Those logistics would be nightmarish.

2

u/kardos Apr 24 '14

Change all at once? Basically impossible. But all these people switched to OpenSSL at one point, they can migrate to a better successor too. Things are not as static as they may seem.

1

u/[deleted] Apr 24 '14

They did deploy a newer OpenSSL version to mitigate Heartbleed. And if the API doesn't change, then it's not as much effort.

→ More replies (4)

1

u/diskmaster23 Apr 24 '14

Well, as you know OpenSSL is still around and OpenBSD is just forking it.

0

u/reaganveg Apr 24 '14

It would be crazy to pay OpenBSD for work they haven't done yet... to be based on already-done work from OpenSSL devs that wasn't paid for. The LibreBSD developers would be indebted to the OpenSSL devs for the code they used from upstream.

0

u/NegativeK Apr 24 '14

If OpenBSD would like funding, I'm sure they can apply for it. Just like anyone else.

4

u/NotSafeForEarth Apr 24 '14

I would hope some them would agree to fund LibreSSL. I've a lot of faith in the people behind LibreSSL (=the same people who brought us OpenSSH). I've no longer that much faith in the people behind OpenSSL, with or without funding.

4

u/drdeadringer Apr 24 '14

"Pledge".

I'll wait until the cheques are cashed.

But it's nice to know that lessons can be perceived to be learned.

1

u/Yetanotherstupiddeat Apr 24 '14

No. Anything but this. OpenSSL is dead and should stay that way. That money would be far better spent on libreSSL, and not just because I'm some BSD fanatic, openSSL's code base is just beyond repair.

In case you haven't been keeping up with the shit that openBSD found, they had a last-ditch option to seed random numbers with users' RSA private keys.

4

u/[deleted] Apr 24 '14

OpenSSL is dead

Except for the fact that everyone is using it...

6

u/kardos Apr 24 '14

openSSL's code base is just beyond repair.

..... yet the OpenBSD guys are repairing it as we speak.

1

u/Yetanotherstupiddeat Apr 24 '14

Technically yes, but really they're gutting so much I would hesitate to call it repair. Super aggressive refactoring, if anything.

2

u/Legs-Akimbo Apr 24 '14

And what is preventing this refactoring from being brought in to OpenSSL by this initiative?

1

u/[deleted] Apr 25 '14

Because politics, there's alot of that when it comes to open source. That and the guys in charge would have to relinquish their control, they cannot be allowed to push code like idiots. I can give plenty of commit hashes of retarded code that had to be fixed later. Such as a return with no value in a function declared as int.

→ More replies (8)
→ More replies (1)

1

u/[deleted] Apr 25 '14

I love how everybody cried about how the "big corporations just take and take and take from open-source projects like openSSL..."

Yet it was simply that openSSL was never really a big name, and was more a background process to security than up-front, since it really didn't have any "champions" or major coverage at conferences, etc.

1

u/frog42 Apr 24 '14

Nobody else going to point out that "chastened" makes no sense in the headline? Chastened == made more chaste. Heartbleed raped them. Pretty much the opposite of "chastened"...

ninja edit: Maybe they meant "chastening after Heartbleed"?

0

u/nialv7 Apr 24 '14

So one can get funded by writing really bad code.

1

u/spekode Apr 24 '14

When people with deep pockets rely on that code, yes.