Looks like an unfortunate interaction all the way around: I have to admit reading the blog post I felt that the "dogma" lay on the other end of the table...now this link seems to confirm that suspicion.
There is a reason people said, "use bcrypt," and certainly Coda is well qualified to elucidate the details.
Side note: It's a little disappointing to see this kind of negativity shoot up on the front page. But by the same token I'm glad that HN readers are so observant and timf linked to a more complete history of what went down.
You can't evaluate the interaction reading that pull request comments. The key point is that I was marked as clueless for the idea of iterating SHA1. I was replied that it was ok only after other guys showed it was a proven and ok alternative.
I don't like when people turn down learning. I don't like dogmas. I also have the bad habit of reacting in a non kind way after being stretched too much, read the insults I got on twitter. I'm usually very kind but there is a limit to what I tollerate.
Reading the discussion comes off as you getting very personal in the attacks while most of the comments were centered around code/crytography.
I also am confused by you stating that 'resorting to best practices can be dangerous.' If they are the best practices, they should be the least dangerous one would think?
I've got no horse in this race but that's my opinion and confusion.
Things that get the "best practices" label slapped on them are not inherently "best". At best, they reflect conventional wisdom in a particular field. Unfortunately, conventional wisdom is often wrong, and rarely challenged.
Eventually, things called "best practices" become the basis of hysterical and utterly worthless Pavlovian responses as occurred en masse here.
I didn't say it was wrong, I said it was useless. Screaming "use bcrypt" is no more helpful than screaming "don't use goto", and being an ass when someone tries to figure out what the actual problem is just turns them off to your "wisdom".
Forest for the trees. This isn't about technical details, it's a question of psychology. Screaming platitudes at people and being a jerk when they ask "Why?" will not result in them following your advice, regardless of its correctness.
I understand your argument and I think I understand why you make it. We're trained to be skeptical (as scientists of one sort or another), but in reality, I really do wonder if most best practices actually have inherent flaws or if its a perception issue because we notice the times its wrong and not the overwhelming number of times it is right?
"Despicable"? Are you sure that's the word you want to use? I'm not fully on Coda's side on this (it's a silly news site, and I've told more than one HN'er to just stretch SHA1 with iterations), but a great way to guarantee that I end up there is to polarize the discussion with comments like this.
It's actually people like you who create stupid flame wars like this. Do you actually have an opinion about bcrypt versus PBKDF1? Or are you just sitting on the sidelines chanting "FIGHT FIGHT FIGHT"?
Incidentally: in the fully polarized discussion, Salvatore loses.
Despicable to just add "use bcrypt" comment without understanding why antirez was against it and not responding to his comments. There were several people on that thread who corrected antirez but did it in a civilized manner. I was specifically talking about people who just added "use bcrypt" and not coda
What is "people like me"?
I don't have an opinion about bcrypt v/s PBKDF1. I have an opinion about how people should provide feedback. I don't know where you get the idea that I'm chanting "fight fight fight". Exactly the opposite actually. Provide constructive feedback and don't just mindlessly litter a discussion with "use bcrypt"
Since you don't have an opinion about the actual subject we're discussing, you're really only here to talk about people. People I assume you don't actually know. You think you're contributing, but you're just like the kids on the playground taunting the two kids who look like they're about to fight.
You are just trolling. Calm down! I don't think you are even reading my comments fully.
Again I don't know where you are getting the idea that I'm taunting anyone. Also I'm not commenting on people but their collective behaviour. It is an important difference. You are just making baseless allegations.
"two kids" ? If you are referring to coda & antirez, I specifically said I was not referring to coda.
When five people show up on a pull request, out of nowhere, unsolicited, and tell me to use a library that I don't know well, and the first one of them is the author of that library, then I expect some sort of reasonable explanation beyond "use my library." Cargo-culting library usage is just as bad as cargo-culting functions or classes. Just pointing that out.
I've seen this a few times on Github^H^H^H^H^H^H the internet - someone makes a snide comment on an thread, tweets about it, and then a flood of dipshit pile-on comments follow.
If my first exposure to the world of cryptography and information security had involved someone like that, I'd have written them all off as arrogant quacks to be ignored.
Comments
This comment from Coda Hale is worth a look: https://github.com/antirez/lamernews/pull/8#issuecomment-248...
Looks like an unfortunate interaction all the way around: I have to admit reading the blog post I felt that the "dogma" lay on the other end of the table...now this link seems to confirm that suspicion.
There is a reason people said, "use bcrypt," and certainly Coda is well qualified to elucidate the details.
Side note: It's a little disappointing to see this kind of negativity shoot up on the front page. But by the same token I'm glad that HN readers are so observant and timf linked to a more complete history of what went down.
You can't evaluate the interaction reading that pull request comments. The key point is that I was marked as clueless for the idea of iterating SHA1. I was replied that it was ok only after other guys showed it was a proven and ok alternative.
I don't like when people turn down learning. I don't like dogmas. I also have the bad habit of reacting in a non kind way after being stretched too much, read the insults I got on twitter. I'm usually very kind but there is a limit to what I tollerate.
Reading the discussion comes off as you getting very personal in the attacks while most of the comments were centered around code/crytography.
I also am confused by you stating that 'resorting to best practices can be dangerous.' If they are the best practices, they should be the least dangerous one would think?
I've got no horse in this race but that's my opinion and confusion.
Things that get the "best practices" label slapped on them are not inherently "best". At best, they reflect conventional wisdom in a particular field. Unfortunately, conventional wisdom is often wrong, and rarely challenged.
Eventually, things called "best practices" become the basis of hysterical and utterly worthless Pavlovian responses as occurred en masse here.
This particular conventional wisdom was not wrong. Your comment, which consists largely of innuendo, is part of the problem, not part of the solution.
I didn't say it was wrong, I said it was useless. Screaming "use bcrypt" is no more helpful than screaming "don't use goto", and being an ass when someone tries to figure out what the actual problem is just turns them off to your "wisdom".
Your comparison is false. "goto" is a stylistic nit. Insecure password hashes are not.
Forest for the trees. This isn't about technical details, it's a question of psychology. Screaming platitudes at people and being a jerk when they ask "Why?" will not result in them following your advice, regardless of its correctness.
I understand your argument and I think I understand why you make it. We're trained to be skeptical (as scientists of one sort or another), but in reality, I really do wonder if most best practices actually have inherent flaws or if its a perception issue because we notice the times its wrong and not the overwhelming number of times it is right?
antirez was very civilized initially. That pull request has a wall of "use bcrypt" comments. It is just a despicable instance of mob mentality.
"Despicable"? Are you sure that's the word you want to use? I'm not fully on Coda's side on this (it's a silly news site, and I've told more than one HN'er to just stretch SHA1 with iterations), but a great way to guarantee that I end up there is to polarize the discussion with comments like this.
It's actually people like you who create stupid flame wars like this. Do you actually have an opinion about bcrypt versus PBKDF1? Or are you just sitting on the sidelines chanting "FIGHT FIGHT FIGHT"?
Incidentally: in the fully polarized discussion, Salvatore loses.
Despicable to just add "use bcrypt" comment without understanding why antirez was against it and not responding to his comments. There were several people on that thread who corrected antirez but did it in a civilized manner. I was specifically talking about people who just added "use bcrypt" and not coda
What is "people like me"?
I don't have an opinion about bcrypt v/s PBKDF1. I have an opinion about how people should provide feedback. I don't know where you get the idea that I'm chanting "fight fight fight". Exactly the opposite actually. Provide constructive feedback and don't just mindlessly litter a discussion with "use bcrypt"
Since you don't have an opinion about the actual subject we're discussing, you're really only here to talk about people. People I assume you don't actually know. You think you're contributing, but you're just like the kids on the playground taunting the two kids who look like they're about to fight.
You are just trolling. Calm down! I don't think you are even reading my comments fully.
Again I don't know where you are getting the idea that I'm taunting anyone. Also I'm not commenting on people but their collective behaviour. It is an important difference. You are just making baseless allegations.
"two kids" ? If you are referring to coda & antirez, I specifically said I was not referring to coda.
When five people show up on a pull request, out of nowhere, unsolicited, and tell me to use a library that I don't know well, and the first one of them is the author of that library, then I expect some sort of reasonable explanation beyond "use my library." Cargo-culting library usage is just as bad as cargo-culting functions or classes. Just pointing that out.
I've seen this a few times on Github^H^H^H^H^H^H the internet - someone makes a snide comment on an thread, tweets about it, and then a flood of dipshit pile-on comments follow.
It's cargo cult cryptography. Saying "use bcrypt" is fine, but understand why you say "use bcrypt."
Cody, Coda, and I are not a cargo cult.
No, but that coconut bra is you!
The whole conversation is really a lot of "willy waving" as one British guy wrote somewhere a number of years ago.
I totally agree.
If my first exposure to the world of cryptography and information security had involved someone like that, I'd have written them all off as arrogant quacks to be ignored.
...and then your customer's credit card info would have showed up on an FTP server in Romania six months later.
Which is exactly the point. He may or may not be "right", but he serves absolutely no one's interests by being a jerk about it.