Live data from Hacker News

Czech Republic: Petition for open source in public administration

portal.gov.cz

1–10 of 32 posts

Re: Czech Republic: Petition for open source in public administration

#3
post #2

See also: https://publiccode.eu

Really wish this was a EU-wide directive. Code produced with the public's money really should at the very least be public, but even better with a permissive license.

FOSS is already in the blood of Europeans, now we just need the legislators to realize this is a good thing, and foster the ecosystem even more!

Re: Czech Republic: Petition for open source in public administration

#4
Realistically there's no reason government can't use open source software and open formats especially.

Last time I had to fill out a government form in Canada, it was a PDF that only opened in the Windows desktop version of Adobe Acrobat... Even the Android version couldn't open it. Super annoying and completely unnecessary.

Edit - I don't even care if they keep their server code proprietary. But just use free formats, save our taxpayer money on stuff like Windows and Office licenses, and make it easy for citizens to interact with them. I'd even rather they hire some more local devs than send money out of the country.

Re: Czech Republic: Petition for open source in public administration

#5
post #4

Realistically there's no reason government can't use open source software and open formats especially. Last time I had to fill out a government form in Canada, it was a PDF that only opened in the Windows desktop version of Adobe Acrobat... Even the Android version couldn't open it. Super annoying and completely unnecessary. Edit - I don't even care if they keep their server code proprietary. But just use free format…

> Realistically there's no reason government can't use open source software and open formats especially.

> Last time I had to fill out a government form in Canada (...)

Without any evidence, let me argue why maybe it shouldn't. In the past, a common opinion that I have heard is that open source is more secure because all the code is out in the open.

The recent xzutils backdoor attempt [1] kind of led me to believe it's not really true, it's only true if many good-actor eyeballs, which are willing to donate their time for public benefit, are on the code.

Almost all of the government's code that I interact with are web apps that are potential targets of foreign adversaries -- tax filing web apps, prescription + vaccination scheduling web apps, family benefit applications, and more. (This is not in Czechia, but close.)

Now, would I want to read that web app code? Not at all, I couldn't care less about it. However, foreign adversaries would love to immediately start analyzing it. Extracting the entire country's health data or tax data would be a goldmine.

And even though there probably are several people actively paid to maintain security of these systems, I feel that the foreign adversarial agents would be much more motivated (and better paid) than government employees/software developers.

You could make a opt-out for national-security purposes for the code, but I feel almost all the code a government works on would have such an impact when compromised.

[1]: https://en.wikipedia.org/wiki/XZ_Utils_backdoor

(Disclaimer: I am a huge supporter of open source in general, contributed to the Linux ecosystem in the past and in my current job as an academic, almost everything I do is available out in the open in some way or another.)

Re: Czech Republic: Petition for open source in public administration

#6
This really seems to be obvious. Brazil has such a legislation[0]. However, the code for the important payment service called Pix, developed by the Brazilian Central Bank, is nowhere to be seen. Laws alone are not enough.

[0]https://www.gov.br/governodigital/pt-br/plataformas-e-servic...

Re: Czech Republic: Petition for open source in public administration

#7
I dig the initiative. Unfortunately, I'm afraid the petition either will not fullfill its target number of signatures or gets denied to be acted upon. Our public sector is too corrupt to make public software contracts transparent like this. Overly expensive and prolonged projects would look even more suspicious with the code (and possibly progress) being publicly available.

Re: Czech Republic: Petition for open source in public administration

#9
post #4

Realistically there's no reason government can't use open source software and open formats especially. Last time I had to fill out a government form in Canada, it was a PDF that only opened in the Windows desktop version of Adobe Acrobat... Even the Android version couldn't open it. Super annoying and completely unnecessary. Edit - I don't even care if they keep their server code proprietary. But just use free format…

> Realistically there's no reason government can't use open source software and open formats especially. > Last time I had to fill out a government form in Canada (...) Without any evidence, let me argue why maybe it shouldn't. In the past, a common opinion that I have heard is that open source is more secure because all the code is out in the open. The recent xzutils backdoor attempt [1] kind of led me to believe it…

Every country already has a special government agency that deals with keeping stuff protected. In fact you tend to think the people who know most about this are in government, don't you?

And it's not like there haven't been vulnerabilities found in proprietary software, despite them paying people to keep things safe.

Re: Czech Republic: Petition for open source in public administration

#10
post #4

Realistically there's no reason government can't use open source software and open formats especially. Last time I had to fill out a government form in Canada, it was a PDF that only opened in the Windows desktop version of Adobe Acrobat... Even the Android version couldn't open it. Super annoying and completely unnecessary. Edit - I don't even care if they keep their server code proprietary. But just use free format…

> Realistically there's no reason government can't use open source software and open formats especially. > Last time I had to fill out a government form in Canada (...) Without any evidence, let me argue why maybe it shouldn't. In the past, a common opinion that I have heard is that open source is more secure because all the code is out in the open. The recent xzutils backdoor attempt [1] kind of led me to believe it…

Microsoft has literally been hacked multiple times by Russia in the last few years. Our government lost hundreds of thousands of CRA (tax agency) credentials to hackers and had to lock millions of accounts. Other agencies have also been breached.

Meanwhile the XZ backdoor was found in Sid, Arch and pre-releases of Fedora and openSuse. It never actually made it into any numbered release of Fedora, openSuse, Ubuntu, Debian, Red Hat or Suse distro. It's actually a pretty big win and the system worked as intended.

Open source and Linux are doing just fine security-wise.

Also, none of this has anything to do with using offline tools like a word processor to make documents.

Post reply on HN