Live data from Hacker News

Czech Republic: Petition for open source in public administration

portal.gov.cz

11–20 of 32 posts

Re: Czech Republic: Petition for open source in public administration

#11
post #2

See also: https://publiccode.eu

Why only code?

Anything funded with public money should have same proportion going back to the public (the organization running the area which funded it).

For example: a 100% EU money funded innovation should be free for everyone to use within EU and outsiders should license a patent.

50% public funding from state of Norway, then state of Norway has 50% ownership.

And so on.

Re: Czech Republic: Petition for open source in public administration

#12
post #2

See also: https://publiccode.eu

Why only code? Anything funded with public money should have same proportion going back to the public (the organization running the area which funded it). For example: a 100% EU money funded innovation should be free for everyone to use within EU and outsiders should license a patent. 50% public funding from state of Norway, then state of Norway has 50% ownership. And so on.

I guess software is a good enough start.

Re: Czech Republic: Petition for open source in public administration

#13

Earlier quoted context omitted.

> Realistically there's no reason government can't use open source software and open formats especially. > Last time I had to fill out a government form in Canada (...) Without any evidence, let me argue why maybe it shouldn't. In the past, a common opinion that I have heard is that open source is more secure because all the code is out in the open. The recent xzutils backdoor attempt [1] kind of led me to believe it…

Microsoft has literally been hacked multiple times by Russia in the last few years. Our government lost hundreds of thousands of CRA (tax agency) credentials to hackers and had to lock millions of accounts. Other agencies have also been breached. Meanwhile the XZ backdoor was found in Sid, Arch and pre-releases of Fedora and openSuse. It never actually made it into any numbered release of Fedora, openSuse, Ubuntu, De…

>Meanwhile the XZ backdoor was found in Sid, Arch and pre-releases of Fedora and openSuse. It never actually made it into any numbered release of Fedora, openSuse, Ubuntu, Debian, Red Hat or Suse distro. It's actually a pretty big win and the system worked as intended.

I would maybe not go quite that far. That it got caught was mostly a confluence of lucky breaks and accidents. The second version of the exploit would likely have not been detected if not for the fact that the first version of the exploit had a couple of programming mistakes that attracted some attention to itself.

Re: Czech Republic: Petition for open source in public administration

#14
post #13

Earlier quoted context omitted.

Microsoft has literally been hacked multiple times by Russia in the last few years. Our government lost hundreds of thousands of CRA (tax agency) credentials to hackers and had to lock millions of accounts. Other agencies have also been breached. Meanwhile the XZ backdoor was found in Sid, Arch and pre-releases of Fedora and openSuse. It never actually made it into any numbered release of Fedora, openSuse, Ubuntu, De…

>Meanwhile the XZ backdoor was found in Sid, Arch and pre-releases of Fedora and openSuse. It never actually made it into any numbered release of Fedora, openSuse, Ubuntu, Debian, Red Hat or Suse distro. It's actually a pretty big win and the system worked as intended. I would maybe not go quite that far. That it got caught was mostly a confluence of lucky breaks and accidents. The second version of the exploit would…

The entire thesis behind the open source security model is to have lots of eyes on the code/program, since more eyes = more likelihood of catching it. Even if you say it's accidental, let's say the odds of catching it are 0.00001. Repeat that enough times and you get 1.

It was caught before any distro released with it. The system worked.

Re: Czech Republic: Petition for open source in public administration

#16

Earlier quoted context omitted.

> Realistically there's no reason government can't use open source software and open formats especially. > Last time I had to fill out a government form in Canada (...) Without any evidence, let me argue why maybe it shouldn't. In the past, a common opinion that I have heard is that open source is more secure because all the code is out in the open. The recent xzutils backdoor attempt [1] kind of led me to believe it…

Every country already has a special government agency that deals with keeping stuff protected. In fact you tend to think the people who know most about this are in government, don't you? And it's not like there haven't been vulnerabilities found in proprietary software, despite them paying people to keep things safe.

Crowdstrike is a recent example that comes to mind. I don't see how paying for CrowdStrike made it more secure or reliable.

I would also argue that you could take all the $$ paying for proprietary software and contribute it to people who are making the open source software, making the reliance on "free" eyeballs less of an issue.

Re: Czech Republic: Petition for open source in public administration

#17
post #2

See also: https://publiccode.eu

I wonder there is not already such a petition in the EU or Germany. I searched, but didn't find any. Somebody who wants to create one? I'm not that good in writing such texts:

Europe: https://www.europarl.europa.eu/petitions/de/home

Germany: https://epetitionen.bundestag.de/epet/startseite.nc.html

Re: Czech Republic: Petition for open source in public administration

#18
post #13

Earlier quoted context omitted.

>Meanwhile the XZ backdoor was found in Sid, Arch and pre-releases of Fedora and openSuse. It never actually made it into any numbered release of Fedora, openSuse, Ubuntu, Debian, Red Hat or Suse distro. It's actually a pretty big win and the system worked as intended. I would maybe not go quite that far. That it got caught was mostly a confluence of lucky breaks and accidents. The second version of the exploit would…

The entire thesis behind the open source security model is to have lots of eyes on the code/program, since more eyes = more likelihood of catching it. Even if you say it's accidental, let's say the odds of catching it are 0.00001. Repeat that enough times and you get 1. It was caught before any distro released with it. The system worked.

If one of the Debian or Fedora developers had immediately caught on to what they were looking at when their attention was drawn to it by the failures, I would say the system worked. It's certainly true that open source saved the day here, but that's maybe different from saying "the system" worked. It easily could have gone unnoticed, or been noticed a few weeks later.

Re: Czech Republic: Petition for open source in public administration

#19
post #6

This really seems to be obvious. Brazil has such a legislation[0]. However, the code for the important payment service called Pix, developed by the Brazilian Central Bank, is nowhere to be seen. Laws alone are not enough. [0] https://www.gov.br/governodigital/pt-br/plataformas-e-servic...

Which is incredibly sad, there's nothing special about it, it is actually a bad sign this is not public.
Post reply on HN