Re: References Are Needed

Laurent Bercot <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
> Mark Johnson is a distributor of DJBDNS-based code, so this discussion
> is indeed on-topic to the DJBDNS list.

 Talking about Mark Johnson's code is relevant.
 Talking about his background is not.


> Code has quality and reputation. Quality and reputation require
> references, background and biographical data. I can find none of this on
> Mark Johnson

 If what you're interested in is the quality of the zinq-djbdns package,
why don't you audit the code yourself instead of asking for references?
You would have to trust the references, too. Would you ask for references
on references? Where is your chain of trust rooted?

 I would also argue that quality and reputation do not go hand-in-hand,
far from it. DJB has a bad reputation among mainstream software
developers, because most mainstream software developers do not understand
DJB's design decisions. But would you pretend said design decisions are not
justified?


> As shown above, it is relevant to the practical choice of
> a distribution.  It certainly factors into my decisions about whether to
> create a another distribution or trust his because I expect others won't
> trust his if there is no quality and reputation behind his code.

 What is more important to you: quality of code, or widespread usage?
Anyway, I maintain there's an easy way for you to make a decision: study
the distribution yourself. One of djbdns' advantages over other DNS
software is that the code base is small, and wholly understandable by
one person.
(I consider it a flaw in zinq-djbdns that autotools-generated code is
added to the djbdns base, because it precisely forfeits that advantage.)


> While your dog can indeed distribute code, and can even get credit
> cards, others may not want to use his code, nor take his credit card.  

 And that would be their loss.
 Because I'm fairly certain that my dog could produce better code than
you would. :P


> Likewise, no one wants to take code from a
> dog (or a sock puppet) because if that code contains security
> vulnerabilities added by the dog, the dog (or sock puppet) can't be held
> responsible.

 Every free software developer in his right mind, be it human, canine, or
Martian, makes sure that he *cannot* be held responsible for his works.
Don't you read disclaimers in software distributions? Have you ever read
the GPL?
 There is no such thing as holding someone responsible for vulnerabilities
in the free software world. Dedicated, benevolent programmers will offer
support for the software they write; they will maintain it and correct
errors. Some will even offer cash prizes when someone discovers a
security hole. ;) But this is *no obligation*. Users of free software
should know the risks involved. Whether you use software written by me,
my dog, Mark Johnson, DJB or Paul Vixie, you have the exact same guarantee,
i.e. jack and sh*t.
 Even commercial software comes with non-liability clauses. If your
computer gets infected because of a security vulnerability in a 
Microsoft product, you can't sue Microsoft. It's in every EULA.

 All you have is good will; all you can do is hope that people will
actually maintain their code. And nobody can give you any certainty
about that. DJB doesn't maintain his code as much as you would like;
I'd wager that Mark Johnson won't maintain his code in the way you would
like, either. The only person that does things exactly the way you want
is yourself; and people's reputations and backgrounds have absolutely
nothing to do with that.

-- 
 Laurent's dog.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.