Slashdot Mirror


Hifn Restricts Crypto Docs, OpenBSD Opens Fire

Mhrmnhrm writes "After totally closing off public access to documentation for their chips roughly five years ago, Hifn is again offering them, but with an invasive registration requirement. Needless to say, Theo de Raadt and the rest of the OpenBSD team were not amused, and following a Hifn manager's missive, the gauntlet has been thrown. Either open the docs fully, or be removed from the system. This wouldn't be the first time... the same thing happened to both Adaptec and Intel following similar spats."

2 of 304 comments (clear)

  1. Personal Info == Legal Tender by TripMaster+Monkey · · Score: 5, Interesting


    From Theo's response:
    "50 personal questions" is not open access. Please don't lie about it.


    Theo is essentially taking the position that personal information is tantamount to currency, and therefore, requesting personal info is tantamount to charging...hence, HIFN can no longer be considered Open Source. This position may currently be confined to OSS in general and the HIFN question in particular, but it's not difficult to imagine this argument generalized to apply to any situation in which an entity requests personal information. Personal info needs to be treated as the valuable commodity that it is...kudos to Theo for taking a stand on this issue.

    Theo also addreses something many of us here are worried about:
    >Registration at our extranet is required along with an email address
    >that can be confirmed. We cannot support anonymous FTP or http
    >downloads. The reason for this is that we are required by the
    >conditions of our US export licenses to know who and where our customers
    >are. If anyone objects to registration then we could not sell them
    >chips anyway so it does not seem an unreasonable restriction to us.

    So the personal information you ask for in the registration process
    will be given to the US government if they ask? Without court
    documents demanding the information?


    Even disregarding the 'personal info == currency' argument outlined above, this objection stands on its own. HIFN is basically stating that yes, the info gathered will be handed over to the U.S. government on request, to satisfy their licensing requirements. This alone is a deal-breaker.

    Theo sums his entire argument up beautifully here:
    We are not your customers. YOU ARE OUR CUSTOMER. Our driver sells
    your chips.

    I know that our hifn driver has some problems. But because I cannot
    get data sheets without giving you private information, I will not
    spend even one moment more of my time to improve support for your
    products. Jason and I spent a lot of time writing that code in the
    past, but because your policies are privacy invasive towards us, and
    thus completely thankless for the sales that we have given you in the
    past -- we will not spend any more time on your crummy products.


    Well said, Theo. I for one don't care to support a company who engages in such practices, and I would rather see no support for a product than half-assed support, because the driver writers were not allowed full, unfettered access to the data sheets.

    And finally from Theo's response:
    And if you continue baiting me, I will delete the driver from our
    source tree.

    I stand by my statement that HIFN is not open.


    Don't just say it, Theo, do it. If you stand by your statement, then HIFN has no place in the source tree, and should be deleted immediately.
    --
    ____

    ~ |rip/\/\aster /\/\onkey

  2. Re:Theo by the_B0fh · · Score: 5, Interesting

    Has any one who badmouths Theo actually tried to talk to him? I've communicated with him without any issues. Just because a person has principles, and stands up for those principles, loudly, doesn't mean he is an asshole.

    Looking at the NetBSD issue, Theo was bitching about developers who kept introducing security holes - I dunno about you, but I'd bitch slap people who keep introducing security holes too, else you end up with something like Windows.