HN user

matt__rose

235 karma
Posts1
Comments68
View on HN

Is there some point to posting this Wikipedia entry? Is there new info or insight into the event? Do you think this is interesting? If so, why?

Please, before posting links to Wikipedia entries, give it some context!

Let me see: I came across a bug in adobe flash (I know, evil) on linux one day where it came down to a change in memcpy in glibc.

https://bugzilla.redhat.com/show_bug.cgi?id=638477

comment 129 https://bugzilla.redhat.com/show_bug.cgi?id=638477#c129

---

Quite frankly, I find your attitude to be annoying and downright stupid.

How hard can it be to understand the following simple sentence:

   THE USER DOESN'T CARE.
Pushing the blame around doesn't help anybody. The only thing that helps is Fedora being helpful, not being obstinate.

Also, the fact is, that from a Q&A standpoint, a memcpy() that "just does the right thing" is simply _better_. Quoting standards is just stupid, when there's two simple choices: "it works" or "it doesn't work because bugs happen".

Standards are paper. I use paper to wipe my butt every day. That's how much that paper is worth.

Reality is what matters. When glibc changed memcpy, it created problems. Saying "not my problem" is irresponsible when it hurts users.

And pointing fingers at Adobe and blaming them for creating bad software is _doubly_ irresponsible if you are then not willing to set a higher standard for your own project. And "not my problem" is not a higher standard.

So please just fix it.

The easy and technically nice solution is to just say "we'll alias memcpy to memmove - good software should never notice, and it helps bad software and a known problem".

---

This is why Linus is widely considered a good steward, and Ulrich had to be removed from glibc.

Yes, they both had abrasive mannerisms, yes they sometimes said things that wouldn't pass fortune 500 HR policy.

The difference is: Ulrich seemed to care more about some kind of technical "correct-ness", and anything that didn't fit in his mental model was considered wrong, and nothing else mattered.

Linus deeply cares about the user experience. the kernel has a strict no-regressions policy for this reason. If it used to work before and now it doesn't, this needs to be fixed in the kernel

Like this case, most of the cases where Linus uses salty language comes down to various kernel developers not following this policy, then complaining when their patch doesn't get accepted.

Edited for formatting

Never delete code. This is why you have git or svn, or whatever your tool of choice is. Never, ever delete code. You may think it's dumb, you may think it's crap, or useless or whatever, but in 2 years, you'll think. "Damn, I remember doing this already, don't I have some code in somewhere?" And you will.

You may look at it and rewrite huge chunks because you're a far better programmer now, but trust me, re-writing code is way easier than writing it from scratch

Fascinating insight into a bit of Jobs life that is mostly overlooked, except as a "He used to be a hippy" anecdote. Steve Silberman does a good job of teasing out the bits and assembling a better vision of Jobs's belief system, and how it informed his work at Apple and NeXT

SF can suck you in, but there are loads of people in SF that have nothing to do with Tech at all. When I lived there my friends included a guy who worked on the Bay Bridge, a Hotel Manager, a financial advisor, a set designer, and a couple of musicians. The only tech people I talked to were at work. Those people are easy to find if you look.

Buddhist Massacre: Look up the end of the Civil War in Sri Lanka, where the Buddhist government pushed hundreds of thousands of Tamil refugees onto the Jaffna peninsula, and then bombed it to smithereens.

Hindus denying rights to women and allowing atrocities like rape and honor killings? Basically the BJP platform in India. Oh, and mass killings of Moslems in the 80s thrown in for good measure.

There is no Zoroastrian or Taoist state, but I'm sure if there was, there would be atrocities there.

Oh, and before anyone says that this is just an anti-religious rant: Pol Pot killed millions, and he was a nominal atheist.

People can and will kill and subjugate people for pretty much any reason. Usually they call it "The Greater Good"

Most inter-city roads in Sweden were 2-lane roads, where to overtake, you needed to swerve into oncoming traffic, 2+1 roads means that even if you're stuck behind an RV or truck, it won't be long before you can safely overtake. At least that's my assumption...

As also noted, pretty solid arguments can be made that the OpenBSD approach is the better approach. My point was that they're not mutually exclusive, and this is definitely a win-win scenario, as we have the potential to get 1. A rock-solid open source SSL library 2. Less surprises in the future.

Basically, through a combination of clever marketing and actual impact, Heartbleed hit the Open Source community HARD, and left most people in the Open Source Community asking two questions: 1. How did this happen? 2. How can we stop this from happening again?

LibreSSL and openSSLRampage is the OpenBSD response, and, it's absolutely in keeping with their character. I admire the "Fuck it, let's just fix this shit" attitude that goes along with it.

The Core Infrastructure Initiative is the Linux Foundation's response.

They're two valid ways of dealing with the problem. the LibreSSL way is more direct, targetted, and, in a way, satisfying, especially if you run OpenBSD, and can gain from these efforts relatively quickly.

The "Core Infrastructure Initiative" is looking at it from a more holistic perspective and saying: OK, OpenSSL was in trouble and nobody noticed, what other projects are in the same situation, and how can we prevent what happened to OpenSSL from happening to other projects.

Neither way is necessarily "The only right way", or even better than the other way. In fact, both approaches complement each other. OpenBSD fixes the actual current problem child, Linux Foundation is on the hunt for the next problem child

1. Always maintain a TODO list. I usually have it as part of the README for the project I'm working on, after that...

Just open up the editor and start coding. Pick something off that list, and hammer away at it. It may suck, but just keep going, re-write it, pick something else on your todo list, but keep going. The secret is: There is no "zone", there's hard work, and perseverance. The "zone" is just a figment of your imagination.

You need a degree for any technical occupation under TN. The only category for which a degree is not necessary is "Management consultant". Honestly it is best for someone in your situation to work remotely from Canada for a year after the company gets set up, then go to the states under an L-1 Visa[1]. Do not attempt to go under a TN-1 visa as they are very strict, and if they do not let you in, you could be barred from entering the US at all.

Africa is a big place. From what I hear, Nairobi is one of the most interesting places to be an entrepreneur these days. Yes, there are huge challenges all over africa including, but not limited to, corruption, unreliable power, political instability, and terrible infrastructure.

But this very constraint is what drives projects like M-PESA, and Ushahidi, and BRCK.

Also, Software Developers in the US and Europe don't necessarily make 100,000 Dollars. In some spots you'd be luck y to make half that.

Unfortunately, if you follow that train of thought to it's logical conclusion, such a place is a contradiction. If everyone wanted to live in a low-density suburban area, these low-density suburban areas have to be built farther and farther away from the city, well more than "a few minutes" drive. To see the fallacy of this you only have to look at places like Toronto, or Atlanta.