Live data from Hacker News

FSF responds to Microsoft's privacy and encryption announcement

fsf.org

11–20 of 69 posts

Re: FSF responds to Microsoft's privacy and encryption announcement

#11

It seems like the response glosses over what Microsoft is actually doing and instead just attacks them for something unrelated (Widows is closed source). In the FSF eyes, Microsoft can do nothing to improve security until Windows is open sourced.

No, I think in the FSF's eyes -- rightfully -- it can't be proven that security has improved. I also can't agree that it isn't related. If I tell you I'm wearing a green shirt, how can you know for sure if you or someone you trust hasn't verified it? You can't. It's the same with MSFT. But in the case of MSFT, it has been proven that they wear a lot of Hypercolor[1] stuff. Is it good that MSFT is doing stuff to make…

So, Microsoft and its Windows product adheres to no industry standards, has no external audit process, has never been verified by a private or Government contract agency through audit or other verification process?

I work in a small programming company and we do internal and external audits while maintaining compliancy with federal and state regulators as well as groups like ISO.

Sure, our work is closed source, but that doesn't automatically mean it hasn't been externally verified for a number of different things by a number of different organizations...

Re: FSF responds to Microsoft's privacy and encryption announcement

#12

It seems like the response glosses over what Microsoft is actually doing and instead just attacks them for something unrelated (Widows is closed source). In the FSF eyes, Microsoft can do nothing to improve security until Windows is open sourced.

No, I think in the FSF's eyes -- rightfully -- it can't be proven that security has improved. I also can't agree that it isn't related. If I tell you I'm wearing a green shirt, how can you know for sure if you or someone you trust hasn't verified it? You can't. It's the same with MSFT. But in the case of MSFT, it has been proven that they wear a lot of Hypercolor[1] stuff. Is it good that MSFT is doing stuff to make…

[deleted]

Re: FSF responds to Microsoft's privacy and encryption announcement

#13

I just love how the FSF ignores, and has ignored for a considerable amount of time that governments, and organizations can and have gotten the Windows source code, and that their actions today restate that they do provide the windows source code for governments to audit. Given that such programs have been available for a considerable amount of time, one has to wonder when the FSF is going to change their tactic away…

"Freedom and security necessitate not just being allowed a peek at the code."

"Transparency in the Windows world normally means self-reports commissioned by Microsoft, or access granted to outsiders covering very limited portions of source code under strict agreements that limit sharing that information."

Yup, John Sullivan really ignored that.

You can disagree with the FSF's mission, but they are certainly not spreading lies on purpose.

Re: FSF responds to Microsoft's privacy and encryption announcement

#14
post #11

Earlier quoted context omitted.

No, I think in the FSF's eyes -- rightfully -- it can't be proven that security has improved. I also can't agree that it isn't related. If I tell you I'm wearing a green shirt, how can you know for sure if you or someone you trust hasn't verified it? You can't. It's the same with MSFT. But in the case of MSFT, it has been proven that they wear a lot of Hypercolor[1] stuff. Is it good that MSFT is doing stuff to make…

So, Microsoft and its Windows product adheres to no industry standards, has no external audit process, has never been verified by a private or Government contract agency through audit or other verification process? I work in a small programming company and we do internal and external audits while maintaining compliancy with federal and state regulators as well as groups like ISO. Sure, our work is closed source, but…

No, I did not say those things. That aside, if you wanted to, after an audit/review concluded, could you put a backdoor in your software? Since it's closed source, would anyone know about it?

Re: FSF responds to Microsoft's privacy and encryption announcement

#15
post #8

huh? I know this isn't going to be the popular opinion but I have to get this off. As much as I respect FSF, this mentality is one of the things I dislike about them. Statements that imply either you are with us or you are evil, trying to crash at opening events of MS/Apple "saving" people from closed source etc. Not everything has to be open source and not everyone has to choose open source. Microsoft/Apple/Google m…

>As a developer, I find GPL to be against the "spirit of open source".

It's not about open source. It's about free software.

https://www.gnu.org/philosophy/open-source-misses-the-point....

Re: FSF responds to Microsoft's privacy and encryption announcement

#16

I just love how the FSF ignores, and has ignored for a considerable amount of time that governments, and organizations can and have gotten the Windows source code, and that their actions today restate that they do provide the windows source code for governments to audit. Given that such programs have been available for a considerable amount of time, one has to wonder when the FSF is going to change their tactic away…

I just love how you like to equate governments and organizations (not individuals) getting to peek at source code (that they're not allowed to modify, share or comment publicly upon) under an NDA as "open source". Who's outright lying?

Re: FSF responds to Microsoft's privacy and encryption announcement

#17
post #11

Earlier quoted context omitted.

So, Microsoft and its Windows product adheres to no industry standards, has no external audit process, has never been verified by a private or Government contract agency through audit or other verification process? I work in a small programming company and we do internal and external audits while maintaining compliancy with federal and state regulators as well as groups like ISO. Sure, our work is closed source, but…

No, I did not say those things. That aside, if you wanted to, after an audit/review concluded, could you put a backdoor in your software? Since it's closed source, would anyone know about it?

In deterministic build? It will be very hard. I doubt that any audit signs on anything other than specific versions.

Re: FSF responds to Microsoft's privacy and encryption announcement

#18
post #11

Earlier quoted context omitted.

So, Microsoft and its Windows product adheres to no industry standards, has no external audit process, has never been verified by a private or Government contract agency through audit or other verification process? I work in a small programming company and we do internal and external audits while maintaining compliancy with federal and state regulators as well as groups like ISO. Sure, our work is closed source, but…

No, I did not say those things. That aside, if you wanted to, after an audit/review concluded, could you put a backdoor in your software? Since it's closed source, would anyone know about it?

If there's a deterministic build process, in theory, the auditor would know something was up if the binary differed.

Re: FSF responds to Microsoft's privacy and encryption announcement

#19
post #4

Earlier quoted context omitted.

Why would you place any amount of trust in a closed source privacy solution from a company with a history such as Microsoft's?

Because they employ intelligent, skilled people who care and know more about privacy than I do. How many open source projects have most people audited for their own sense of satisfaction about its security promises?

Unfortunately, those skilled people at MS have let the NSA in on so many 0-day exploits. God knows how many have not been reported to the public yet. At least with open source, I know there is a community behind it for me or others to verify. Sure it is not 100% fool proof, but it makes it far harder to sneak bad things through.

Re: FSF responds to Microsoft's privacy and encryption announcement

#20
post #19

Earlier quoted context omitted.

Because they employ intelligent, skilled people who care and know more about privacy than I do. How many open source projects have most people audited for their own sense of satisfaction about its security promises?

Unfortunately, those skilled people at MS have let the NSA in on so many 0-day exploits. God knows how many have not been reported to the public yet. At least with open source, I know there is a community behind it for me or others to verify. Sure it is not 100% fool proof, but it makes it far harder to sneak bad things through.

> Sure it is not 100% fool proof, but it makes it far harder to sneak bad things through.

Debian SSL bug lasted 2 years. Open source means little for security.

Post reply on HN