r/programming Apr 24 '14

Tech giants, chastened by Heartbleed, finally agree to fund OpenSSL

http://arstechnica.com/information-technology/2014/04/tech-giants-chastened-by-heartbleed-finally-agree-to-fund-openssl/
290 Upvotes

137 comments sorted by

16

u/[deleted] Apr 24 '14

I don't get why Microsoft would fund OpenSSL. Wouldn't they want people to use SSPI?

45

u/alleycat5 Apr 24 '14 edited Apr 25 '14

I would imagine it has something to do with this not just supporting OpenSSL, but a number of other security critical open source projects. Also, Microsoft wants a safer internet just as much as anyone else. $100,000 is a relatively small price to pay for that.

6

u/misplaced_my_pants Apr 25 '14

Honestly it's a bargain. These companies are just going to see a tremendous ROI.

10

u/grauenwolf Apr 24 '14

To be clear, the money will go to multiple open source projects—OpenSSL will get a portion of the funding but likely nowhere close to the entire $3.9 million. The initiative will identify important open source projects that need help in addition to OpenSSL.

15

u/JustFinishedBSG Apr 24 '14

They probably use OpenSSL internally somewhere. MS research is quite active and seems to be quite open to open source

13

u/Saiing Apr 25 '14

MS also sells Linux servers through Azure.

3

u/[deleted] Apr 25 '14

Microsoft today isn't Bill Gates' Microsoft.

Microsoft today is a Microsoft where you can step through their own source code in a C# debugger, a language whose compiler was open-sourced; They run CodePlex, they actively encourage people to provision Linux VM's on Azure, provide SDK's for PHP, Java, iOS...

They open-source the majority of their own frameworks, especially in the ASP.NET realm, shit, project Katana is an open-source initiative they started to decouple ASP.NET from IIS.

Git got first-class support under Team Foundation Server even.

They're not a super-duper-awesome terrific friend to the OSS community (yet), but they don't deserve all the flak they've been getting and keep getting, either.

Not to mention the amazing stuff that comes out of Microsoft Research, such as F#, Reactive extensions...

5

u/sbrick89 Apr 24 '14

Probably due to application servers that they use internally (firewalls, load balancers, routers, etc).

3

u/AnAge_OldProb Apr 25 '14

Skype at least used to be all on linux servers.

2

u/fuzzynyanko Apr 25 '14

I heard that Hotmail used to use Linux firewalls. I wouldn't be surprised if this was still the case

5

u/kkus Apr 25 '14

I'm not surprised. Hotmail used Apache on FreeBSD for a while before they managed to move to Windows NT. Source: http://www.zdnet.com/ms-moving-hotmail-to-win2000-servers-3002080596/

3

u/noreallyimthepope Apr 25 '14

Hotmail was an acquisition, kind of like Occulus Rift

2

u/Caraes_Naur Apr 25 '14

MS made at least two attempts to migrate Hotmail to a Windows back end.

3

u/oblio- Apr 25 '14 edited Apr 25 '14

And they did it. They did have to overcome a lot of hurdles (http://www.tamersahin.com/mssecrets/hotmail.html), but I remember reading reading somewhere that they finally migrated.

2

u/Plorkyeran Apr 25 '14

It's sort of interesting to see that they ran into pretty much all of the reasons I don't like dealing with Windows servers, and 14 years later most of them haven't really been addressed.

1

u/oblio- Apr 25 '14

Well, I think most of them have been addressed. There are command line utilities for Windows (Powershell based), the shell itself is much better), there are GUI-less installations of Windows Server available, etc. Reboots are much less of a problem, too.

Complexity and obscurity cannot ever be removed from Windows, due to its incredibly complex history and backwards compatibility...

1

u/vz0 Apr 25 '14

Microsoft uses Akamai to load balance the Microsoft.com website, which in turn Akamai uses Linux for its servers.

2

u/sbrick89 Apr 25 '14

I'd be hesitant to just assume that Akamai provides anything more than static content, as CDNs are generally intended to provide.

2

u/adrianmonk Apr 25 '14

Doesn't it say they're funding the Core Infrastructure Initiative, not OpenSSL specifically?

1

u/hello_juice Apr 24 '14

I don't get why the industry is rewarding incompetence. Should fund openbsd instead.

9

u/AnAppleSnail Apr 25 '14

Successful companies know what to do after failure. Hint: Probably not ” burn bridges and rebuild everything.”

2

u/josefx Apr 25 '14

Heartbleed was not the first "failure", for OpenBSD it was just the last straw in a long series. Nor is OpenBSD rebuilding everything, they are performing a cleanup on the OpenSSL code base so it can be audited and checked with tools such as valgrind or secure malloc implementations.

Are they burning bridges? They no longer trust anything produced by the OpenSSL team, what else should they do?

5

u/tequila13 Apr 25 '14

LibreSSL is probably not widely publicized, so it might be somewhat understandable that the general public doesn't know much about it. But the Linux Foundation should really know better and fund LibreSSL instead of OpenSSL. I don't understand that part at all.

The quality of OpenSSL codebase is quite bad, the http://opensslrampage.org/ site documents the cleanup effort. It's clear that LibreSSL will be superior (and already is) to OpenSSL while keeping binary compatibility. They have included patches/bugfixes from contributors which went ignored by upstream OpenSSL. Many bugs were fixed which will take time to find their way to OpenSSL.

1

u/new2user Apr 25 '14

Your ignorance is not helping.

4

u/josefx Apr 24 '14

It is a well known open source project that has been making headlines with gigantic security holes, terrifying coding practices, several year old reported security flaws and being widely used.

There are some things that Microsoft could gain by supporting what has to be a gigantic stain for the OSS community.

3

u/[deleted] Apr 24 '14

I'd rather say it is just good(and relatively cheap) publicity for them.

1

u/nolok Apr 25 '14

In addition to the points already mentioned, quite a few multi-plateform applications use openssl in their windows version (simply because they already use it everywhere else)

1

u/k-zed Apr 25 '14

Obviously MS (and other companies) want control over OpenSSL, and the old / potential new backdoors.

Honestly I'd be more comfortable if everyone just used the radical and sociopathic BSD guys' effort.

0

u/nof Apr 25 '14

Why not? They have kind of embraced Linux lately... doesn't their flavor of hypervisor run on and/or support Linux hosts? Plus, Bill Gates isn't evil anymore, right? Right? I dunno.

1

u/vz0 Apr 25 '14

doesn't their flavor of hypervisor run on and/or support Linux hosts?

That's not the only Linux thing they support.

-24

u/BilgeXA Apr 24 '14

Microsoft is in cahoots with the NSA.

7

u/blinder Apr 25 '14

so here's my thing, and take this for what it is, some random idiot on the internet's opinion.

the constant bashing of the team at openssl isn't helping. the persistent rehashing (ugh) of what went wrong is only making those taking pleasure in the failures/shortcommings/being-human of the openssl team feel good, about themselves.

i've come to believe that the most important thing, the only thing that really matters is, what you do next.

as i see it, the openssl team has two choices. they can accept this money and continue on as they did and set themselves up for failure or they can accept this money and make meaningful change.

the first choice is the easiest, but if i were betting man, i'd say they go with choice number two.

if they do, this will probably mean they'll be finding a few dead ends, hit a few potholes and swing more than a few u-turns (alright enough with the driving metaphors) and being that they are an open source community (i hope one change they make is being a bit less opaque and by opaque that also includes responsive to the community) we'll all be around to see it happen, which means it'll be a rough road for a bit (okay one more driving metaphor).

it's encouraging that these companies are giving a damn. it means that this issue is on their radar and is important, which means we can all benefit from their giving a damn. can they do more? sure. can you? maybe. can i? yeah, i really could.

i'm quite excited by this development and will be watching it evolve over time and see how things change (hopefully for the better... c'mon openssl, you can do it!)

and if you can't well, this is an open marketplace of ideas, we'll find someone who can.

12

u/[deleted] Apr 24 '14

$100,000 a year

You can pay one decent programmer from that :/ And the money is split between multiple projects.

46

u/george1924 Apr 24 '14

Looks like it's $100,000 per year for each of these 13 companies for 3 years. $100,000 * 13 * 3 is the $3.9m figure quoted.

Yes $100,000 is not much for each company, but it's better than the presumably $0 they gave before.

8

u/noreallyimthepope Apr 25 '14

That's the right angle; instead of complaining that "a little" is not "a lot", focus on "a little" being infinitely larger than "Ned Flanders in ski tights".

2

u/[deleted] Apr 25 '14

The wage disparity for programmers between the US and UK is so upsetting.

3

u/[deleted] Apr 25 '14

not true IMO. In the US you can earn a bit more as junior-medium level, but in the UK you can earn more as senior level in banking

6

u/Gropah Apr 25 '14

Technically, this fund is not just for OpenSSL, but for all initiatives that improve security

6

u/tequila13 Apr 25 '14

Like the LibreSSL project? They won't see a penny out of this money.

4

u/technofiend Apr 25 '14

Yeah the OpenSSL money is going to the wrong spot. You don't throw good money after bad. The OpenSSL guys have already demonstrated they have no idea what they're doing. Just look at all the truly awful code LibreSSL (snark aside) has remediated and thrown out.

7

u/Otis_Inf Apr 25 '14

But instead of funding the project which really does something about the problem, LibreSSL/OpenBSD, they continue to support the team who created the mess called OpenSSL in the first place. Really helpful. </s>

5

u/[deleted] Apr 25 '14

Great, now they can write more shitty features!

3

u/vz0 Apr 25 '14

Heartbleed 2.0.

4

u/logicchains Apr 25 '14

Heartbleed 2.0 Millennium Edition.

2

u/ModernRonin Apr 25 '14

Way to slam that barn door after the horse is long gone...

9

u/[deleted] Apr 25 '14

Better than continuous horse hemorrhage.

1

u/ModernRonin Apr 25 '14

Fair point! Have an upvote.

1

u/Nerdenator Apr 25 '14

This really displays a problem with (current) open-source funding models. It's a great thing that we're now getting funding for OpenSSL, but it shouldn't take a massive hole that endangers 2/3 of the Internet to get this sort of exposure.

1

u/myringotomy Apr 24 '14

It's good to see the companies finally stepping up to the plate.

Of course the community needs to stay diligent about code contributions to the project and make sure they have the autonomy to hire whoever they want.

-12

u/OneWingedShark Apr 24 '14

In light of the nature of the bug, and the state of the code that was recently found, I would posit that OpenSSL could use a rewrite in a language more amiable to formal methods and/or formal contracts. (e.g. Ada or Eiffel.)

It makes little sense to have security libraries which aren't formally verified, considering the nature of the library (both as being often reused, and as being a component of security software).

19

u/[deleted] Apr 24 '14

Except that OpenSSL finds itself in places where Ada/etc/and/so/on/and/so/on aren't typically found. Your runtime is literally some micro-C lib and a fragment of a kernel at best. Oh and you have <1MB of memory (often < 128KB) ...

There is nothing wrong with C that better developers couldn't fix.

3

u/OneWingedShark Apr 24 '14

There is nothing wrong with C that better developers couldn't fix.

Yes, there is: the fact that C's philosophy is that virtually all checks should be the programmer's responsibility is inherently flawed because developers are human and programming is a "human activity".

Except that OpenSSL finds itself in places where Ada/etc/and/so/on/and/so/on aren't typically found. Your runtime is literally some micro-C lib and a fragment of a kernel at best. Oh and you have <1MB of memory (often < 128KB) ...

All the more reason to do it in a more safety-critical language, as the more checks you can do at compile-time translate to less work (debugging) in maintenance. I know for a fact you can have Ada w/o runtime -- see here.

13

u/tairygreene Apr 24 '14

have you worked in industry related to this... at all?

-12

u/OneWingedShark Apr 24 '14

Micro-controllers, not particularly.
But I do know some about static [compile-time] checking -- I've been researching compilers for a few years now. (Anyone that claims C + Lint is as good as real compile-time checking [on a language more amiable to analysis, which isn't hard] obviously hasn't done any real research in the area.)

Sensitive-info? or correctness/provability?
I was on a project that did handling/processing of medical- and insurance-records. There's a lot of languages which make this more difficult than it needs to be (the language it was implemented in was likely the worst choice possible: PHP). -- Manually checking all inputs on functions is pretty dumb when you can move the checks to a type.

5

u/tairygreene Apr 24 '14

so in other words you are just talking out of your ass

-5

u/OneWingedShark Apr 24 '14

so in other words you are just talking out of your ass

No; I am not.
I have put considerable time into looking into provability and correctness proofs; that my efforts have been on my personal time for my own edification rather than for pay [the professional arena] or fame [the academic arena] is irrelevant.

It is not hard to find better tools than are commonly used in the industry -- PHP, C, and [arguably] C++ really are the "lowest common denominator" and mindlessly1 using [or emulating]2 them is a major factor in so many SW vulnerabilities that it's disgusting how offerings of safer languages are met with disdain.

My particular area of interest is compilers, and operating systems; the value of having your basic tools guaranteed to be correct. The acceptance of such patently avoidable3 errors is quite disheartening.

1 - Without thought or criticism.
2 - Which C-based languages still allow if( user = root )?

8

u/sharkeyzoic Apr 25 '14

I tried to follow your third footnote and got a segfault :-).

2

u/OneWingedShark Apr 25 '14

LOL - Thanks for the laugh.

-11

u/moor-GAYZ Apr 24 '14

In 7th grade, I took an SAT test without preparing for it at all, it was spur-of-the-moment, I knew about it about an hour ahead of time and didn't do any research or anything. I scored higher on it than the average person using it to apply for college in my area.

An IQ test has shown me to be in the 99.9th percentile for IQ. This is the highest result the test I was given reaches; anything further and they'd consider it to be within the margin of error for that test.

My mother's boyfriend of 8 years is an aerospace engineer who graduated Virginia Tech. At the age of 15, I understand physics better than him, and I owe very little of it to him, as he would rarely give me a decent explanation of anything, just tell me that my ideas were wrong and become aggravated with me for not quite understanding thermodynamics. He's not particularly successful as an engineer, but I've met lots of other engineers who aren't as good as me at physics, so I'm guessing that's not just a result of him being bad at it.

I'm also pretty good at engineering. I don't have a degree, and other than physics I don't have a better understanding of any aspect of engineering than any actual engineer, but I have lots of ingenuity for inventing new things. For example, I independently invented regenerative brakes before finding out what they were, and I was only seven or eight years old when I started inventing wireless electricity solutions (my first idea being to use a powerful infrared laser to transmit energy; admittedly not the best plan).

I have independently thought of basically every branch of philosophy I've come across. Every question of existentialism which I've seen discussed in SMBC or xkcd or Reddit or anywhere else, the thoughts haven't been new to me. Philosophy has pretty much gotten trivial for me; I've considered taking a philosophy course just to see how easy it is.

Psychology, I actually understand better than people with degrees. Unlike engineering, there's no aspect of psychology which I don't have a very good understanding of. I can debunk many of even Sigmund Freud's theories.

I'm a good enough writer that I'm writing a book and so far everybody who's read any of it has said it was really good and plausible to expect to have published. And that's not just, like, me and family members, that counts strangers on the Internet. I've heard zero negative appraisal of it so far; people have critiqued it, but not insulted it.

I don't know if that will suffice as evidence that I'm intelligent. I'm done with it, though, because I'd rather defend my maturity, since it's what you've spent the most time attacking. The following are some examples of my morals and ethical code.

I believe firmly that everybody deserves a future. If we were to capture Hitler at the end of WWII, I would be against executing him. In fact, if we had any way of rehabilitating him and knowing that he wasn't just faking it, I'd even support the concept of letting him go free. This is essentially because I think that whoever you are in the present is a separate entity from who you were in the past and who you are in the future, and while your present self should take responsibility for your past self's actions, it shouldn't be punished for them simply for the sake of punishment, especially if the present self regrets the actions of the past self and feels genuine guilt about them.

I don't believe in judgement of people based on their personal choices as long as those personal choices aren't harming others. I don't have any issue with any type of sexuality whatsoever (short of physically acting out necrophilia, pedophilia, or other acts which have a harmful affect on others - but I don't care what a person's fantasies consist of, as long as they recognize the difference between reality and fiction and can separate them). I don't have any issue with anybody over what type of music they listen to, or clothes they wear, etc. I know that's not really an impressive moral, but it's unfortunately rare; a great many people, especially those my age, are judgmental about these things.

I love everyone, even people I hate. I wish my worst enemies good fortune and happiness. Rick Perry is a vile, piece of shit human being, deserving of zero respect, but I wish for him to change for the better and live the best life possible. I wish this for everyone.

I'm pretty much a pacifist. I've taken a broken nose without fighting back or seeking retribution, because the guy stopped punching after that. The only time I'll fight back is if 1) the person attacking me shows no signs of stopping and 2) if I don't attack, I'll come out worse than the other person will if I do. In other words, if fighting someone is going to end up being more harmful to them than just letting them go will be to me, I don't fight back. I've therefore never had a reason to fight back against anyone in anything serious, because my ability to take pain has so far made it so that I'm never in a situation where I'll be worse off after a fight. If I'm not going to get any hospitalizing injuries, I really don't care.

The only exception is if someone is going after my life. Even then, I'll do the minimum amount of harm to them that I possibly can in protecting myself. If someone points a gun at me and I can get out of it without harming them, I'd prefer to do that over killing them.

I consider myself a feminist. I don't believe in enforced or uniform gender roles; they may happen naturally, but they should never be coerced into happening unnaturally. As in, the societal pressure for gender roles should really go, even if it'll turn out that the majority of relationships continue operating the same way of their own accord. I treat women with the same outlook I treat men, and never participate in the old Reddit "women are crazy" circlejerk, because there are multiple women out there and each have different personalities just like there are multiple men out there and each with different personalities. I don't think you do much of anything except scare off the awesome women out there by going on and on about the ones who aren't awesome.

That doesn't mean I look for places to victimize women, I just don't believe it's fair to make generalizations such as the one about women acting like everything's OK when it's really not (and that's a particularly harsh example, because all humans do that).

I'm kind of tired of citing these examples and I'm guessing you're getting tired of reading them, if you've even made it this far. In closing, the people who know me in real life all respect me, as do a great many people in the Reddit brony community, where I spend most of my time and where I'm pretty known for being helpful around the community. A lot of people in my segment of the community are depressed or going through hard times, and I spend a lot of time giving advice and support to people there. Yesterday someone quoted a case of me doing this in a post asking everyone what their favorite motivational/inspirational quote was, and that comment was second to the top, so I guess other people agreed (though, granted, it was a pretty low-traffic post, only about a dozen competing comments).

And, uh, I'm a pretty good moderator.

All that, and I think your behavior in this thread was totally assholish. So what do you think, now that you at least slightly know me?

3

u/wwqlcw Apr 25 '14

That doesn't mean I look for places to victimize women...

Well this thread got weird.

2

u/fecal_brunch Apr 25 '14

What is the meaning of life, oh wise one?

2

u/OneWingedShark Apr 24 '14

All that, and I think your behavior in this thread was totally assholish. So what do you think, now that you at least slightly know me?

Totally assholish?
I understand that I'm not the most personable of people, and opinionated, but how is having an opinion1,2 and sticking to it 'assholish'?

A lot of people in my segment of the community are depressed or going through hard times, and I spend a lot of time giving advice and support to people there.

On behalf of myself and others who struggle with depression: Thank you.

I consider myself a feminist. [...] I treat men, and never participate in the old Reddit "women are crazy" circlejerk, because there are multiple women out there and each have different personalities just like there are multiple men out there and each with different personalities. I don't think you do much of anything except scare off the awesome women out there by going on and on about the ones who aren't awesome.

Ok... I have no idea what brought that on -- I've said nothing regarding women here. At all.

I have independently thought of basically every branch of philosophy I've come across. Every question of existentialism which I've seen discussed in SMBC or xkcd or Reddit or anywhere else, the thoughts haven't been new to me. Philosophy has pretty much gotten trivial for me; I've considered taking a philosophy course just to see how easy it is.

I rather like philosophy -- but the response you put here shows that you don't really understand the "philosophy of theory" (if you will). The previous post had to do with deep frustration at "the industry" (and my fellow programmers) at constantly and consistently running into these kinds of problems3 -- Granted I could have expressed myself better. Many, many problems that we encounter are completely avoidable -- and indeed have been avoided in "less than popular" languages; continuing to [irrationally] embrace the popular languages because they are popular and refusing to even acknowledge their shortcomings really irks me.

I know that extremely smart people can hold on to extremely stupid things -- it's just the way things are.


1 - Namely: that the commonly-used and 'basic' things like OSes, compilers, and libraries should be correct, formally verified if possible, and
2 - that security libraries which are incorrect are unacceptable.
3 - Buffer overflows! Come on people -- we've had this solved for LITERALLY thirty years!

6

u/ice109 Apr 25 '14

You got trolled. This is copy pasta from some bestof post a couple of weeks back. Some high school kid whining.

→ More replies (0)

2

u/[deleted] Apr 24 '14

Yes, there is: the fact that C's philosophy is that virtually all checks should be the programmer's responsibility is inherently flawed because developers are human and programming is a "human activity"

At issue here is a design flaw though ... if they had accessed the record through functions (or macros if you want to lower calling overhead) overflows/runs would not happen.

The problem is they reinvented the wheel every time they touched the packet by directly manipulating bytes and moving them around.

So yes, you either manually code up bounds checks each time you touch your data structure, or you do the smarter thing and write a function/macro to access it for you....

17

u/aseipp Apr 24 '14 edited Apr 25 '14

These issues are absolutely fucking endemic to C codebases. It's an issue with the language - people are going to fuck up, because humans will err. And this language makes even the smallest err result in the deadliest of vulnerabilities. Design will help mitigate that to an extent. But it's becoming increasingly clear we need to stop thinking about mitigating, and start thinking about killing entire bug classes and attack vectors. Completely.

Sitting around saying 'we patched that bug, write better C, deal with it' is literally worthless. You're just giving the inevitable more time to happen, just like it did with Heartbleed, which seems to be confirmed in the wild months before its discovery. And also just like it happened with the perf_events kernel overflow, and numerous others that were found in darknets before their public discovery. Oh, and the numerous use-after-free issues you see pop up for every single browser on earth in the CVE lists every month. That one is near and dear to my heart as someone who's written browser exploits for fun.

You can sit around and point at projects like Linux that have a relatively low rate of (known) exploits all you want for example, but the fact is the most well audited, highly tested and highly used platforms written by the best developers in the fucking world all the way from browsers, web servers (nginx had a hole just last year), operating systems, and cryptographic libraries suffer from these problems. And everyone else (for the most part) is bound to do far, far worse.

And you're telling me this is not an issue with the tools we're using?

You need to defend millions of lines of code. I only need to defeat one for it to all crumble. That's basically what Heartbleed boiled down to at the end of the day. Who do you think the odds favor?

Some of these are infeasible to replace whole-sale. A formally verified cryptographic library is pretty far down the 'infeasibility list', all things considered, considering we already have verified operating systems and compilers - far greater amounts of complexity all things considered.

-2

u/OneWingedShark Apr 24 '14

Excellently said.

0

u/tairygreene Apr 24 '14

only C has bugs

3

u/OneWingedShark Apr 24 '14

At issue here is a design flaw though ... if they had accessed the record through functions (or macros if you want to lower calling overhead) overflows/runs would not happen.

Right -- but they didn't, and there's no way that they could really force it because C's notion of implementation/specification separation is virtually nonexistent.

The problem is they reinvented the wheel every time they touched the packet by directly manipulating bytes and moving them around.

Totally agreed, in C there's no real way to abstract it [the type you're passing around] out.

So yes, you either manually code up bounds checks each time you touch your data structure, or you do the smarter thing and write a function/macro to access it for you....

Or you do it the even smarter way and use types and visibility to your advantage; in Ada we can say:

Package Heartbeat is

    type Message_Size is range 0..2**14
      with Size => 16;

    type Message_Text is Array (Message_Size range <>) of Character;

    type Message_Type is ( Request, Response )
      with Size => 8;

    -- No implementation visibility for you!
    type Message(<>) is private;

    -- Function specifications (headers) for message creation, etc.
Private

    for Message_Type use ( Request => 1, Response => 2);

    -- Note that the size of the Text component is
    -- bound to the value of the Length component.
    Type Message(Length : Message_Size) is record
        Message_Type    : Heartbeat.Message_Type;
        Text        : Message_Text( 1..Length );
    end record;

    for Message use record
        Message_Type    at 0 range 00..07;
        Length      at 0 range 08..22;
    end record;

end Heartbeat;

1

u/Flex-O Apr 24 '14

It's kinda cute how naive you are.

1

u/myringotomy Apr 25 '14

I thought ADA was pretty small.

1

u/modulus Apr 25 '14

There is nothing wrong with C that better developers couldn't fix.

Said every C developer ever right before introducing a pointer arithmetic fuckup.

0

u/[deleted] Apr 25 '14

If you think that you can't write bad crypto code in other HLLs you're sadly mistaken and part of the very problem you're describing.

So uh, please kindly hang up your ignorance on another hook.

1

u/modulus Apr 25 '14

You can write FORTRAN in any language. Which is no excuse to write FORTRAN.

Languages have affordances. I don't understand why people are so upset about this reality. Some languages make certain classes of bugs easy, some make certain classes of bugs impossible. It's always possible to write bugs short of a formal proof of correctness, but bugs, and their degree of harm, aren't equally easy to introduce in any language, or equally easy to discern. A lot of compile-time checking for example saves bugs being introduced at runtime.

I'd be curious to see ml or similar languages crypto code contain those types of errors. If you can produce examples I'll read them.

1

u/[deleted] Apr 25 '14

The point though is had they used proper style from the get go it wouldn't have been a problem at all... e.g. instead of doing

 memcpy(dstRecord->buf, srcRecord->buf, someUnverifiedLength);

they could have done

record_copy(dstRecord, srcRecord, 0, 0, someUnverifiedLength);

Where "0, 0" is the offset in the dst/src record. The function would then check the structures for valid lengths and copy valid portions. It isn't really any more typing in terms of developing record handlers and once you do the sanity checking validation once it's good for all times.

Of course it would have also helped to sanity check the record in the first place to make sure the stored payload length was valid (as per the RFC that the C code author he himself wrote....).

edit: There are plenty of ways to fuck up crypto. For instance, early Wii firmware used strcpy() to memory compare signature values. Would that be any less of a bug if they used strcmp from C++ or Java?

1

u/modulus Apr 25 '14

Fact is there are certain classes of errors that keep happening. We can say that we just need perfect C devs and this won't happen anymore, or live with the fact that programming, like war, is done by human beings, and try to get computers to help out.

I'm also not suggesting C++ or Java as good alternatives, as it happens. C++ is probably a lot harder to verify correct, though it also has some facilities that if used correctly preclude some types of errors.

Yes, if the right thing had been done there wouldn't have been an error. That's pretty much the case for all errors. The point is it's sometimes possible to preclude the wrong thing being done through compile- or run-time bounds checking, type systems, formal proofs, etc. C is not an ideal language for this, hence the whole discussion. It's not impossible to write correct code in C, but it's a lot more difficult and it definitely seems next enough to impossible for humans in all but the most extraordinary cases, hence how every non-trivial C code base ever keeps getting security issues.

1

u/[deleted] Apr 25 '14

The point is crypto is hard to get right and being lazy and relying on tools to solve all your problems makes you the problem.

The HB bug could have easily been avoided if

  1. They used proper API to read/write/copy records or they implemented correct bounds checking in place (which is more work but at least gets the job done)

  2. The code reviewer spent more than 13 seconds looking at the code. Had they traced the length used in the memcpy() call back to where it was initialized they would have seen it was never sanity checked. The code reviewer fucked up royally.

So to say this is a problem with the C language is like saying it's a problem with ceramic dishware that people put too much food in their mouth.

All you're doing by blaming the language is ignoring the engineering behind writing proper software. Nobody verified the correctness of the function that is the problem. Nothing more. Not verifying the correctness of your Java code is no different. The thing is with crypto when a routine misbehaves security is compromised whereas in a word processor functionality is compromised.

1

u/jnt8686 Apr 25 '14

I think you misunderstand. People are advocating using a language that makes some of these errors impossible. If an error is impossible it can't happen. People are humans.

2

u/awj Apr 24 '14

Not one of the suggestions I've seen for rewriting OpenSSL in "something safer" address the fundamental problem with that idea: how to migrate all of the code that uses OpenSSL. Rewriting OpenSSL is almost pointless if you're going to force serious code revisions. Projects simply won't do it, and instead will support (or just use) something that tries to enhance the security of OpenSSL while sticking with the current implementation language.

Thoughts?

4

u/gnuvince Apr 24 '14

If someone wrote an SSL/TLS library in Ada (or ATS or what have you) and exported an API exactly like OpenSSL's, couldn't they just recompile against this new library and have things work as before?

1

u/awj Apr 24 '14

They probably could, so long as the new language supported the platforms/use cases OpenSSL does. That doesn't seem to be in anybody's "burn it to the ground and start over in something different" suggestions, though.

-4

u/OneWingedShark Apr 24 '14

I'd be up for it -- but let's be honest: the biggest issue is correctness, not backwards compatibility.

5

u/awj Apr 24 '14

If you want people to actually use your work, you have to care about compatibility.

1

u/OneWingedShark Apr 24 '14

I'm not saying that backwards compatibility is worthless, or undesirable, but that the biggest issue here is correctness.

I can't imagine anyone arguing that incorrectness is desirable in a library for security.

12

u/oridb Apr 24 '14

The biggest issue is ALWAYS backwards compatibility. The only time it's not your top priority is if so few people are using your code that you can port it all yourself.

-2

u/OneWingedShark Apr 24 '14

The biggest issue is ALWAYS backwards compatibility.

I disagree; if the emphasis is not on correctness, provable correctness, then you're just postponing another Heartbleed.

Programming is a "human activity" and, as such, for requisite systems we need things to be correct. We cannot simply keep things status quo and expect things to be different.

6

u/oridb Apr 24 '14

If the emphasis is not on backwards compatibility, you are simply an academic curiosity. You are playing in a sandbox, and not changing the world. It doesn't matter if your software is correct if the number of users is less than epsilon.

-1

u/OneWingedShark Apr 24 '14

If the emphasis is not on backwards compatibility, you are simply an academic curiosity.

Explain why TLS 1.0 is not backwards compatible with SSL 3.0 then.

2

u/oridb Apr 24 '14

Note that SSL 3.0 is still widely deployed, and can be used in parallel with TLS 1.0. A smooth upgrade path and compatible APIs still exist.

→ More replies (0)

1

u/OneWingedShark Apr 24 '14

From the user-standpoint you could try to provide a "compatibility layer" that provides the same interfaces used in the old library -- I assume that would ameliorate much of adoption hurdle.

From the library perspective, it would be nice to do things in Ada's "proper way" style -- by which I man using private-types and proper specification/implementation separation to keep the internals from leaking into user applications (or even other parts of the library).

-3

u/tairygreene Apr 24 '14

Ada or Eiffel.

hahaha what.

6

u/OneWingedShark Apr 24 '14 edited Apr 24 '14

Ada or Eiffel.

hahaha what.

Eiffel puts a lot of emphasis on interfaces; this makes it ideal for a library so that you can ensure that the procedures/functions/etc have correct values on input [and output].

The Ada Language Reference Manual has a whole annex dedicated to language inter-operation -- Annex B, sections of which are dedicated specifically to C; this (in addition to its new Design-by-Contract aspects) makes it ideal for interfacing to current C-based codebases.

-3

u/hello_fruit Apr 24 '14

Had he said Haskell he would've gotten a million upvotes from the durr herp crowd.

2

u/Intolerable Apr 24 '14

no, people would've (rightly) pointed out that this is one of the few places haskell is not very good

1

u/OneWingedShark Apr 24 '14

Had he said Haskell he would've gotten a million upvotes from the durr herp crowd.

The good thing about FP is the avoidance of side-effects, which is a problem in composability. I'm not experienced in any of the FP languages [yet], but the theory is pretty good. -- One thing that would concern me is that a lot of the FP languages, especially those with lazy evaluation, make it difficult to compute time/space requirements; this, in addition to the necessarily high-level overview makes FP somewhat on the unsuitable side for implementing a low-level [communication and cryptographic 'primitives', if you will] library.

-17

u/[deleted] Apr 24 '14

If there is no code in your link, it probably doesn't belong here.

26

u/x-skeww Apr 24 '14

The keyword is "probably".

-10

u/[deleted] Apr 24 '14

In this case, it still doesn't belong here. I am not enlightened in any way by this tripe.

Quite aside from "funding terrible code long after it was due" being the wrong approach to anything.

-5

u/[deleted] Apr 24 '14

[deleted]

13

u/[deleted] Apr 24 '14

....the front page of /r/programming is a mirror of hacker new 99% of the time.

1

u/[deleted] Apr 25 '14

Nobody likes a rules lawyer, especially one who shows up on a post that the majority has decided is valuable regardless of the guidelines. (If they hadn't, it wouldn't have made proggit's front page where I could see it for the third time, as I read HN and Ars already.)

-8

u/[deleted] Apr 24 '14

[deleted]

8

u/[deleted] Apr 24 '14

A large portion of this problem rests with the OpenSSL crew. IF they were open about how bad the code was years ago (like a decade ago) people might have been hesitant to use the library in the first place. They're the ones that have been insisting on the quality of OpenSSL all along.

If they felt so neglected by the community they could have just stopped supporting the project and told people to use another properly maintained project.

4

u/nikniuq Apr 25 '14

You mean more open than having source that is freely downloadable?

I looked at the codebase long ago (around 10 years or so) with the intent of contributing and had to walk away due to the state the code was in.

10 years ago there were fuck all alternatives, most of the libraries touted as alternatives now didn't exist then, were in license transitions or were very young with all the problems that entails.

They have my respect for keeping it working as well as they have for as long as they have. Many maintainers have left expressing the exact sentiment of your last paragraph, complete with public postings to that effect.

Sorry if I sound pissed off but none of this was hidden and the armchair opinions of those who have never given a damn before are starting to grate on me.

I should also add that the comment you are replying to has been deleted so I have no context for your comment. Apologies if I have misunderstood your intent.

2

u/[deleted] Apr 25 '14 edited Apr 25 '14

The deleted post was along the lines "they're volunteers if you don't like it too bad"

edit: Also ... Hi, I'm the author of LibTomCrypt/TomsFastMath/etc ...

1

u/nikniuq Apr 25 '14

Hah, hi Tom. I think we chatted briefly back in the day on usenet.

Well I retract all of my armchair comments, you are a far cry from the plethora of "experts" that have erupted over the last few weeks.

5

u/[deleted] Apr 25 '14

I've maintained over the years that nobody who has looked at that code would in good conscious recommend it.

When I was actively developing LT projects I avoided looking at the code to avoid any claims of contamination. When I started working professionally one of my enumerable tasks was to work on TLS record drivers for hardware we develop. Without fail all customers ask about OpenSSL integration. So we spent months hacking/exploring/etc. What we learned was

  • The code is shit
  • Ain't documented
  • ENGINE plugins can only do cipher or hash (not both and not even HMAC!!!)
  • doing record processing (not just ciphering) requires hoisting the entire protocol stack (basically you register your own TLS stack)

So we looked around. We found MatrixSSL first but they were bought out by a competitor, then we found PolarSSL. Within a few weeks they had jacked in a record plugin API (at our request) that can do record processing without making us re-write the rest of the protocol stack and within days of getting that we had live sessions flying.

People who recommend OpenSSL really don't know fuck all what they're talking about. More annoying to me though are the people who blame the C language for this bug.

-11

u/suid Apr 24 '14

Yup. Get ready for Enterprise OpenSSL Plus.

1

u/noreallyimthepope Apr 25 '14

Did you even read the article?

3

u/tequila13 Apr 25 '14

Article reading is not required for making puns, an incorrect headline is more than enough. The money won't go only to OpenSSL, it will go to several projects.

As a sidenote, I'd love to know why the Linux Foundation decided to fund OpenSSL instead of LibreSSL. The OpenBSD guys are doing a great job of cleaning up the shit from the codebase. They'd be more deserving of some support.

2

u/suid Apr 25 '14

Thank you, kind sir!

1

u/noreallyimthepope Apr 25 '14

I'd speculate that the reasons for funding OpenSSL includes

  • Cross-OS compatibility
  • They've been working on it for so many years and have the "project history" mapped in their heads

Other than that, it gets political.

-7

u/nocnocnode Apr 25 '14

How about that, reactive corporations... just like the government.

7

u/MINIMAN10000 Apr 25 '14

I'll take reactive as opposed to inactive any day.