Re: References Are Needed
Laurent Bercot <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
> Mark Johnson is a distributor of DJBDNS-based code, so this discussion > is indeed on-topic to the DJBDNS list. Talking about Mark Johnson's code is relevant. Talking about his background is not. > Code has quality and reputation. Quality and reputation require > references, background and biographical data. I can find none of this on > Mark Johnson If what you're interested in is the quality of the zinq-djbdns package, why don't you audit the code yourself instead of asking for references? You would have to trust the references, too. Would you ask for references on references? Where is your chain of trust rooted? I would also argue that quality and reputation do not go hand-in-hand, far from it. DJB has a bad reputation among mainstream software developers, because most mainstream software developers do not understand DJB's design decisions. But would you pretend said design decisions are not justified? > As shown above, it is relevant to the practical choice of > a distribution. It certainly factors into my decisions about whether to > create a another distribution or trust his because I expect others won't > trust his if there is no quality and reputation behind his code. What is more important to you: quality of code, or widespread usage? Anyway, I maintain there's an easy way for you to make a decision: study the distribution yourself. One of djbdns' advantages over other DNS software is that the code base is small, and wholly understandable by one person. (I consider it a flaw in zinq-djbdns that autotools-generated code is added to the djbdns base, because it precisely forfeits that advantage.) > While your dog can indeed distribute code, and can even get credit > cards, others may not want to use his code, nor take his credit card. And that would be their loss. Because I'm fairly certain that my dog could produce better code than you would. :P > Likewise, no one wants to take code from a > dog (or a sock puppet) because if that code contains security > vulnerabilities added by the dog, the dog (or sock puppet) can't be held > responsible. Every free software developer in his right mind, be it human, canine, or Martian, makes sure that he *cannot* be held responsible for his works. Don't you read disclaimers in software distributions? Have you ever read the GPL? There is no such thing as holding someone responsible for vulnerabilities in the free software world. Dedicated, benevolent programmers will offer support for the software they write; they will maintain it and correct errors. Some will even offer cash prizes when someone discovers a security hole. ;) But this is *no obligation*. Users of free software should know the risks involved. Whether you use software written by me, my dog, Mark Johnson, DJB or Paul Vixie, you have the exact same guarantee, i.e. jack and sh*t. Even commercial software comes with non-liability clauses. If your computer gets infected because of a security vulnerability in a Microsoft product, you can't sue Microsoft. It's in every EULA. All you have is good will; all you can do is hope that people will actually maintain their code. And nobody can give you any certainty about that. DJB doesn't maintain his code as much as you would like; I'd wager that Mark Johnson won't maintain his code in the way you would like, either. The only person that does things exactly the way you want is yourself; and people's reputations and backgrounds have absolutely nothing to do with that. -- Laurent's dog.