Live data from Hacker News

FSF responds to Microsoft's privacy and encryption announcement

fsf.org

31–40 of 69 posts

Re: FSF responds to Microsoft's privacy and encryption announcement

#31

I just love how the FSF ignores, and has ignored for a considerable amount of time that governments, and organizations can and have gotten the Windows source code, and that their actions today restate that they do provide the windows source code for governments to audit. Given that such programs have been available for a considerable amount of time, one has to wonder when the FSF is going to change their tactic away…

Can those organizations also build the code from source, and then exclusively use the binaries they produced? And possibly even compare to the binaries that Microsoft ships?

Just being able to see the code is no advantage, you still have to trust Microsoft to actually ship the same code they've shown you.

Re: FSF responds to Microsoft's privacy and encryption announcement

#32
post #23

I just love how the FSF ignores, and has ignored for a considerable amount of time that governments, and organizations can and have gotten the Windows source code, and that their actions today restate that they do provide the windows source code for governments to audit. Given that such programs have been available for a considerable amount of time, one has to wonder when the FSF is going to change their tactic away…

So the NSA can see Windows source code, but Windows users can't? And users are supposed to feel secure about this? Why?

More than just the NSA. This shrill hyperbole that permeates the free software world is counterproductive to getting things fixed.

Re: FSF responds to Microsoft's privacy and encryption announcement

#33
As long as Microsoft tells NSA about the bugs they have in Windows before they start fixing them [1], that just constitutes the same thing as "backdoors", since with many of those bugs NSA can take full control of a machine.

So Microsoft doesn't need to "give NSA a backdoor". They just need to tell them about certain bugs before they fix them - and that's just as bad as giving them backdoors, since NSA can and will use them as such.

[1] - http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t...

Re: FSF responds to Microsoft's privacy and encryption announcement

#34
post #20

Earlier quoted context omitted.

> Sure it is not 100% fool proof, but it makes it far harder to sneak bad things through. Debian SSL bug lasted 2 years. Open source means little for security.

cherrypicked examples mean little for arguements either. The WMF exploit was in windows for more than 15 years. http://en.wikipedia.org/wiki/Windows_Metafile_vulnerability

SSL is a security sensitive bit of code. That's the kind of thing that needs to be kept safe, and it's the kind of thing that people claim is kept safe my open source's many eyes.

The argument I'm making is not that Windows is secure (because it isn't), but that Open Source isn't necessarily secure just because it's open source.

Re: FSF responds to Microsoft's privacy and encryption announcement

#35
post #23

Earlier quoted context omitted.

So the NSA can see Windows source code, but Windows users can't? And users are supposed to feel secure about this? Why?

More than just the NSA. This shrill hyperbole that permeates the free software world is counterproductive to getting things fixed.

Okay, who? And why should I trust them? How do I know they didn't sign an NDA promising to keep any security vulnerabilities secret?

Re: FSF responds to Microsoft's privacy and encryption announcement

#36
post #23

Earlier quoted context omitted.

So the NSA can see Windows source code, but Windows users can't? And users are supposed to feel secure about this? Why?

More than just the NSA. This shrill hyperbole that permeates the free software world is counterproductive to getting things fixed.

Drcube: How do I know that open source developers aren't contractors out to put backdoors in? At some point you have to trust someone, and I doubt with all the eyes on windows, both within and without, that any extant backdoor would have remained hidden until now. There are quite a few people who do reverse engineer windows without a license, and would be shouting it from the rooftops if they found a backdoor.

Re: FSF responds to Microsoft's privacy and encryption announcement

#37
I don't think people should be so dismissive of the FSF's argument here. It's central to the issues with security these days. P2P Affero GPL licensed software is about the only way to be secure anymore. Even then, we have issues with unknown code and hardware at the lowest levels of the stacks.

Re: FSF responds to Microsoft's privacy and encryption announcement

#38
post #21

Open/closed source software and secure/unsecure software are orthogonal concepts. Yes, it may be easier to assess open source software with regard to security and privacy issues, but it is absolutely not necessary. And even with open source software the overwhelming majority of users still has to trust some third party because it is absolutely unrealistic that every user or organization audits their complete software…

> Open/closed source software and secure/unsecure software are orthogonal concepts

No, they are not. It's fundamentally impossible to secure proprietary software because you have to trust its provider the software does what it says it does whereas with open-source you can always check for yourself. Any backdoor in open-source software is there to be exposed and corrected.

With proprietary software only one party can disclose vulnerabilities and in open-source anyone with the knowledge can do it. You can choose to trust a single party or choose to trust a myriad of different parties any one of which can blow the whistle if they find something fishy.

I find it highly unlikely a backdoor to a popular open-source application could remain there for long. I don't think it's unlikely at all with proprietary software where there is no incentive to fix a problem until someone outside the company learns about it.

Re: FSF responds to Microsoft's privacy and encryption announcement

#39
post #8

huh? I know this isn't going to be the popular opinion but I have to get this off. As much as I respect FSF, this mentality is one of the things I dislike about them. Statements that imply either you are with us or you are evil, trying to crash at opening events of MS/Apple "saving" people from closed source etc. Not everything has to be open source and not everyone has to choose open source. Microsoft/Apple/Google m…

>As a developer, I find GPL to be against the "spirit of open source". It's not about open source. It's about free software. https://www.gnu.org/philosophy/open-source-misses-the-point....

Which is, urm, rather the point.

Some of us care more about open source than free software.

Re: FSF responds to Microsoft's privacy and encryption announcement

#40
post #11

Earlier quoted context omitted.

No, I think in the FSF's eyes -- rightfully -- it can't be proven that security has improved. I also can't agree that it isn't related. If I tell you I'm wearing a green shirt, how can you know for sure if you or someone you trust hasn't verified it? You can't. It's the same with MSFT. But in the case of MSFT, it has been proven that they wear a lot of Hypercolor[1] stuff. Is it good that MSFT is doing stuff to make…

So, Microsoft and its Windows product adheres to no industry standards, has no external audit process, has never been verified by a private or Government contract agency through audit or other verification process? I work in a small programming company and we do internal and external audits while maintaining compliancy with federal and state regulators as well as groups like ISO. Sure, our work is closed source, but…

> Sure, our work is closed source, but that doesn't automatically mean it hasn't been externally verified for a number of different things by a number of different organizations...

Yes, but we have to take your word for it.

Post reply on HN