Live data from Hacker News

Dutch government says no to backdoors, grants $540k to OpenSSL

theregister.co.uk

51–60 of 101 posts

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#51
post #33

This statement was made early December. And I think it does deserve some nuance: Minister Steur (Security and Justice) this monday said, representing the second chamber, that "laws that prohibit encryption are not desirable at this time ". That doesn't retract their early statement, but I think it's an important nuance. Arguably, it might also just be political play to get some douchebag rightwing parties over the li…

>it might also just be political play to get some douchebag rightwing parties over the line

Who is the real "douchebag" in that case?

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#52
post #32
post #24

It's nice, meanwhile "we" now have a law being debated by government (not sure it will pass) that allows the government to hack individuals if they are suspect, this may even happen via people the suspect may know. It even includes being allowed to install spyware on a webcam. But I guess it is good to leave encryption strong, forget about mass surveillance and focus energy on individuals actually suspected of a crim…

If there is a reasonable suspicion I don't see the problem with giving law enforcement the legal ability to hack their targets. This is something very different from drag-net surveillance and should not be tainted with the same stigma. It's not like the government actually _needs_ or wants to maintain giant botnets of all the targets they've hacked.

Withholding known security vulnerabilities from the public in order to be later used for hacking is immoral and dangerous.

Imagine if the police had prior knowledge of a vulnerability in the computer system of a car, but did not act to protect the public. A few years later a criminal figure out the same vulnerability and causes a major car crash on a motorway and murder several people. I would view the police officer to be found liable under breach of duty, same as if they witnessed a crime and refused to act.

Under the same logic, if companies has a legal responsibility to protect their customers and provide safe products, and police officers has a professional responsibility to report crimes, then the police should be forced to act if they have confirmed information about a security vulnerability.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#53

Earlier quoted context omitted.

FWIW, LibreSSL replaced OpenSSL in OpenBSD 5.6 -- over a year ago.

OpenBSD started the LibreSSL project, so, naturally, they would adopt it. OSX has also adopted it for purely license politics reasons, El Capitan shipped with it: $ /usr/bin/ssh -V OpenSSH_6.9p1, LibreSSL 2.1.8

Debian stable is using LibreSSL for around a year already (Debian started switching just after the fork).

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#54

Earlier quoted context omitted.

OpenBSD started the LibreSSL project, so, naturally, they would adopt it. OSX has also adopted it for purely license politics reasons, El Capitan shipped with it: $ /usr/bin/ssh -V OpenSSH_6.9p1, LibreSSL 2.1.8

Debian stable is using LibreSSL for around a year already (Debian started switching just after the fork).

Debian is not using LibreSSL, I just checked. Sid currently ships OpenSSL 1.0.2e, and Jessie currently ships 1.01k.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#55
post #51
post #33

This statement was made early December. And I think it does deserve some nuance: Minister Steur (Security and Justice) this monday said, representing the second chamber, that "laws that prohibit encryption are not desirable at this time ". That doesn't retract their early statement, but I think it's an important nuance. Arguably, it might also just be political play to get some douchebag rightwing parties over the li…

>it might also just be political play to get some douchebag rightwing parties over the line Who is the real "douchebag" in that case?

Surveillance is not generally a right/left thing and seems to be more an establishment thing.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#56
post #8

I tried to open the (Dutch) DOCX that contains the official position paper of our government, but LibreOffice refuses to open it: File format error found at SAXParseException: '[word/document.xml line 2]: unknown error', Stream 'word/document.xml', Line 2, Column 30060(row,col). http://www.tweedekamer.nl/kamerstukken/brieven_regering/deta... Great. Usually OOXML Word files at least open in LibreOffice, but this one s…

Please complain to them [1]. They are required to publish that document as ODF, not DOCX. Alternatively PDF or HTML could be used. Using DOCX in Dutch government is against the standard [2], which is ODF 1.2.

[1] http://www.tweedekamer.nl/contact/contact#webform-client-for... [2] https://lijsten.forumstandaardisatie.nl/open-standaard/odf12

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#57
post #33

This statement was made early December. And I think it does deserve some nuance: Minister Steur (Security and Justice) this monday said, representing the second chamber, that "laws that prohibit encryption are not desirable at this time ". That doesn't retract their early statement, but I think it's an important nuance. Arguably, it might also just be political play to get some douchebag rightwing parties over the li…

I think this needs a whole lot more nuance. Minister Steur said that the laws are not desirable at this time, after other cabinet members said it will hurt economic relations. This is not a statement saying we don't want this, this is a statement saying we can't do this right now. Also, the money going to OpenSSL and others is completely unrelated to the current encryption banning talks going on in the Netherlands. T…

It is indeed a statement that "we can't do this right now". You don't need the implication you're making; it can literally be found in the 'cabinet's standpoint' (see below for a translation). I have the suspicion that it has something to do with the 'utopic' outlooks that other nations and their presidential candidates have come to suggest: "technologists will find a way to have both security and access".

"At this time, there is no outlook on the general possibility to, for example via standards, weaken encryption products without compromising the security of digital systems relying on encryption. By for example introducing a technical point of access into a encryption product which would enable intelligences agencies to view encrypted files, digital systems could be rendered vulnerable to for example criminals, terrorists and foreign intelligence agencies. This would have negative consequences for the security of communicated or saved information, and the integrity of ICT-systems, which are increasingly of importance in the functioning of society." (second paragraph of 'Afweging en conclusie')

(in these debates, there is always an important question: what would Ivo have said? Luckily, somebody has already provided an answer: http://tinyurl.com/whatwouldivohavesaid)

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#58

Earlier quoted context omitted.

OpenBSD started the LibreSSL project, so, naturally, they would adopt it. OSX has also adopted it for purely license politics reasons, El Capitan shipped with it: $ /usr/bin/ssh -V OpenSSH_6.9p1, LibreSSL 2.1.8

> "... license-related political reasons ..." > " ... license politics reasons ..." I'm not sure exactly what you mean by this? I mentioned OpenBSD replacing OpenSSL with it simply because the "official" OpenSSH is now developed against it. I'm not sure if LibreSSL is being used for the portable version yet but if/when that happens, I expect people will begin to "trust" it more, leading to more projects potentially d…

Until the announcement in August 2015, OpenSSL was dual licensed ASL1 + SSLeay License (and by dual licensed, OpenSSL means both apply, instead of choose one), the terms of which make it GPL incompatible, and also has questionable patent issues (a problem for commercial software).

The announcement was that they are moving to Apache License 2.0, thus solving both issues. However, this move has not happened yet.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#59
post #45

Earlier quoted context omitted.

FWIW, LibreSSL replaced OpenSSL in OpenBSD 5.6 -- over a year ago.

And I believe RHEL/Fedora use NSS?

NSS is not an OpenSSL drop in.

Firefox, Chrome on platforms other than Android, OSX, and iOS (although I think they have completed removal of the NSS interface and gone with OpenSSL on all platforms, now served by Google's own BoringSSL fork), the mod_nss module for Apache, some Java projects (including some from Redhat and Sun/Oracle) that don't want to use Java's own SSL API, all use NSS.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#60

Earlier quoted context omitted.

I think this needs a whole lot more nuance. Minister Steur said that the laws are not desirable at this time, after other cabinet members said it will hurt economic relations. This is not a statement saying we don't want this, this is a statement saying we can't do this right now. Also, the money going to OpenSSL and others is completely unrelated to the current encryption banning talks going on in the Netherlands. T…

The money going to OpenSSL might be related to the issue the Dutch government ran into in 2011 with the Diginotar (a certificate authority) hack; the TLS certificates for Dutch government websites were compromised at that time. While this hack was not related to weaknesses in OpenSSL (as far as I know), this did put the spotlight on the vulnerability and dependence on of the certificate chain. Supporting the software…

The amendment to provide €500 million to open sources encryption project (initially only OpenSSL), was done by D66's Kees Verhoeven. He has a history of asking question about the Snowden revelations and other issues around computer security. He is also partly responsible for the amendment on net neutrality, and the infamous 'cookie law' (which is actually more of a 'do not 3rd party track before asking consent' law).

For example in June has asked questions [1] about "the news that American intelligence agencies used vulnerabilities in encryption software" (specifically weak DH / Logjam).

If anything, this proposal has more to do with Logjam than with Diginotar. Not all too incidently, improving OpenSSL would do nothing to prevent another Diginotar from happening.

[1] http://www.tweedekamer.nl/downloads/document?id=97a9bc20-eca...

Post reply on HN