Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Monday, January 25, 2010

David Seigel on Improving Launchpad Bug Workflow, or "Developer, Developers, Developers"

Mark Shuttleworth and Canonical Ltd. employees...Image via Wikipedia
David Seigel has a great post, called Improving Launchpad Bug Workflow for Opportunistic Programmers < The Plenitude of Arboreal Beauty. It's not great in that I like the exact solution proposed, but it highlights some important points about Free software development, and the comments are equally interesting.

First, a summary for those not wanting to read the post. David proposes adding a simple link to Launchpad which will help opportunistic programmers fix simple bugs like the ones in 100 Papercuts without having to worry about setting up the proper build environment. Clicking "Quickly fix this bug" installs the proper dependencies and source, opens the preferred editor, and creates a patch when finished.

In effect, David is proposing that Ubuntu prescribe a specific method for bug fixes, including the IDE used. (He proposes using Eclipse.) While this type of policy is likely to rankle many programmers, I believe that having a preferred IDE, language, and toolkit for Ubuntu would be a big step forward. In fact, when Ubuntu started in 2004, I remember Shuttleworth stating that all new work should be done in Python, and that Canonical would be hiring based on this principle. SchoolTool was developed from Zope (IIRC) for this exact reason.

While there certainly have been many new additions to the Ubuntu project which rely on Python since then, we also have GTK-sharp, C, and ECMAScript or JavaScript (e.g. Seed or Gjs). Ubuntu has failed to have a single, defining vision for its product (which Shuttleworth claims he wants) with a preferred development method. I'm not suggesting that there be only one method for development, but both Microsoft and Apple have shown that providing standard tools and languages (VS/.NET and XCode/ObjectiveC, respectively) can create a great developer base. The easier to get involved, the better.

Ubuntu could have a special developers' release which includes all the standard tools necessary to set up and connect to a Launchpad account (for bug fixing and publishing via PPA), an IDE with Ubuntu- and Launchpad-specific plugins, and complete developer documentation. Of course, programmers can continue to use Vim or Emacs or whatever, then use Bazaar from the command line, but new developers would likely just accept the default method Ubuntu provided, and puting "Ubuntu" into the "integrated" part of an integrated development environment would lure many developers. (I had in my notes but forgot to mention that Ubuntu currently is developing Quickly, which appears to be going in the direction I'm proposing. Or it could die like so many other other projects. Wait and see.)

More interesting stuff comes up in the comments section: what is the responsibility for upstreaming? Should bugs be fixed upstream first? Should patches be preferred for upstream? I think these kinds of arguments overlook the strength of FOSS. Ubuntu should fix bugs as it sees fit locally first, and submit those patches or make them easily available (something Launchpad is working hard on). Ultimately, though, many proposed patches will not be accepted by upstream, or they might be delayed by years waiting for a release. If Ubuntu wants to progress, it needs to take responsibility for its own problems and not state that it is waiting on upstream to integrate or fix a patch.










Thursday, July 9, 2009

This is Why "Responsible Disclosure" is a Joke.

Windows Internet ExplorerImage via Wikipedia
Responsible Disclosure:
Responsible disclosure is a term concerning the subject of computer security. It is like full disclosure, with the addition that all stakeholders agree on a period of time to wait before patching the security vulnerability and publish the details. Developers of hardware and software often require time and resources to repair their mistakes. Hackers and computer security scientists have the opinion that it is their social responsibility to make the public aware of vulnerabilities with a high impact. Hiding those fact could suggest a feeling of false security. To avoid this, the involved parties join forces and agree on a period of time for repairing the vulnerability and prevent any future damage. Corresponding to the impact of the vulnerability it may require a period between a few weeks and several months. It is easier to patch software by using the internet as distribution channel. [1]
Full Disclosure:

Full disclosure requires that full details of a security vulnerability are disclosed to the public, including details of the vulnerability and how to detect and exploit it. The theory behind full disclosure is that releasing vulnerability information immediately results in quicker fixes and better security. Fixes are produced faster because vendors and authors are forced to respond in order to save face. Security is improved because the window of exposure, the amount of time the vulnerability is open to attack, is reduced.

In the realm of computer vulnerabilities, disclosure is often achieved via mailing lists such as Bugtraq and full disclosure by other means. [2]
Microsoft requires "responsible disclosure" in order for security experts to get any credit for discovering vulnerabilities. I put the phrase in quotes because, based on the definition above, RD has an agreed upon time limit, but while Microsoft calls their process RD, the company doesn't commit to any time frame and generally holds the secret until a patch is released. Some researchers have waited years for a patch from MS, decided to disclose the vulnerability to the public, and been denied credit from MS because of the disclosure.

Now, it appears that the awful Internet Explorer / Windows XP (or Server 2003) exploit was known to MS since at least December, 2007. We'll never know exactly how long because the report (CVE-2008-0015) is protected by a non-disclosure agreement.

Attacks have been going on for at least a month (who really knows?). There's still no patch and there's no time-frame for one, either. There's a workaround, but no patch.

Disgusting. People have been vulnerable for way too long, and MS knew it. This is why I and many others support full disclosure. Patches are released quickly and users are aware of the danger.

Reblog this post [with Zemanta]

Monday, February 9, 2009

How do you beat free?

Ubuntu logoImage via Wikipedia
Before I start rolling, I'd like to make it clear that I understand the difference between freeware and Free software. I've used Linux for eleven or so years and have been MS-free for basically all of it. Now, on with the show.

A common talking in tech blogs is the MS Windows and Office pair against a Linux distro (generally Ubuntu or Fedora) and OpenOffice.org. Linux activists state that the dropping cost of computers will force Microsoft into a corner and it will be unable to compete with low-cost alternatives on either the MS Office or the MS Windows front. While this has been a talking point for years -- ever since laptops started dropping below US$1000 -- it hasn't happened much at all to this point. In fact, hardware with a Linux distro is often either more expensive or the same price as hardware with MS Windows. Why is that?

How do you compete with free? Free here means no-cost. The answer is simple: you make your product cheaper. Let me explain.

There has been freeware available for computers for many years. Somehow, it has never gotten a foothold on mainstream boxes. While the OEM could create a full-featured computer using freeware whenever possible and keep their costs down, too, they didn't. They didn't do that because they were paid to install trial software from non-freeware vendors. A trial version of Norton is cheaper than a free version of Clamwin. AOL goes on. AT&T goes on. In some cases, it's not a trial version of software, but some company which sought to increase market share. RealPlayer comes to mind. The total payment for that software can be tens of dollars, perhaps even a hundred.

That hundred dollars pays for the MS Windows license (maybe $30) and leaves you some profit -- profit which you aren't making on the hardware because the market's so tight. Give up MS Windows, and you've given up that source of income.

You can't beat free? Au contraire!
Reblog this post [with Zemanta]

Other I' Been to Ubuntu Stories

Related Posts with Thumbnails