Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think you're missing the point here. It's not helped by the way Linus has expressed himself here. The truth is that there's a fundamental philosophical disagreement here: Linus prioritises not breaking userland, GR security doesn't. Their patches are "crap" because they're large and not in the correct style, not because they don't achieve what they set out to do. Sometimes people take subsets of those patches, clean them up and get them put into the kernel, which is the source of GRS's accusations of "stealing".

The short version is that GR Security have personalities and behaviors very like Linus' own. There's value in GRS, and a fair amount of bad behaviour, but let's be frank, the same's true of Linux.



> Sometimes people take subsets of those patches, clean them up and get them put into the kernel, which is the source of GRS's accusations of "stealing".

This is insane. If their argument had any legal merit, it is because of a bug in gpl and we should patch it. Just based on the accusation of theft, without knowing anything else about them or anything else, I can safely say they're scum bags and no I don't have a Fields medal but I don't retract it.

I do think Linus should have adopted "or later" a long time ago but that's a different discussion.


I think if we get into the technical side, there's a lot of question too.

It doesn't seem like they are very good at code review or testing, for example:

https://twitter.com/marcan42/status/724745886794833920?lang=...

And when called out on this, they simply block the people saying it.

I'd personally be very skeptical of any security company that values their own tolerance for dealing with people telling them their code sucks over finding out that their code sucks and fixing it. And a lack of good code review and testing is of huge import when it comes to security, at least in my opinion.

Then there's also their weird crusade against (e)BPF without any supporting evidence beyond "It adds more features so that's more attack surface and thus shouldn't ever be added or attempted and we don't believe anyone involved could ever make it secure so there."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: