Live data from Hacker News

FSF responds to Microsoft's privacy and encryption announcement

fsf.org

51–60 of 69 posts

Re: FSF responds to Microsoft's privacy and encryption announcement

#51
post #48
post #41

Earlier quoted context omitted.

> Debian SSL bug lasted 2 years. Open source means little for security. How many examples can you come up with? Was this specific bug being actively exploited when it was discovered?

> How many examples can you come up with? A bug caused by prettying the code, which was secure from upstream, which is in an important, widely used, supposedly secure bit of code isn't a good enough example? > Was this specific bug being actively exploited when it was discovered? Many Linuxes used to ship with lots of services running. That lead to many rooted boxes being used to deliver spam. Open Source fixed the p…

> A bug caused by prettying the code, which was secure from upstream, which is in an important, widely used, supposedly secure bit of code isn't a good enough example?

It's a good example. Can you come up with more? Because, you know, it's just one instance of a problem. It says nothing on how pervasive it is.

> For years anyone putting an MS server onto the Internet ran the risk of very quick exploitation.

IIRC, there was a time when the average time between install and first invasion was in the 40 seconds range.

Re: FSF responds to Microsoft's privacy and encryption announcement

#52
post #43
post #38

Earlier quoted context omitted.

> Open/closed source software and secure/unsecure software are orthogonal concepts No, they are not. It's fundamentally impossible to secure proprietary software because you have to trust its provider the software does what it says it does whereas with open-source you can always check for yourself. Any backdoor in open-source software is there to be exposed and corrected. With proprietary software only one party can…

It is not impossible. There is no reason why closed source software can not be secure. Yes, you can not convince yourself in the same way you can with open source software but again secure software and the ability to convince yourself that a software is secure are different things.

> There is no reason why closed source software can not be secure

True, but there is no way to prove it's secure. It's not about convincing myself or anyone else - it's about proof.

Re: FSF responds to Microsoft's privacy and encryption announcement

#54

It seems like the response glosses over what Microsoft is actually doing and instead just attacks them for something unrelated (Widows is closed source). In the FSF eyes, Microsoft can do nothing to improve security until Windows is open sourced.

Yes, much of the announcement(which they seem to have purposefully not linked, I wonder how many commenters here have actually read it), has nothing to do with Windows but its about Cloud services like Outlook.com, Office 365, Skydrive and Windows Azure all of which can be used from Linux! Just like Google, they're now encrypting all data links.

Re: FSF responds to Microsoft's privacy and encryption announcement

#55
post #8

huh? I know this isn't going to be the popular opinion but I have to get this off. As much as I respect FSF, this mentality is one of the things I dislike about them. Statements that imply either you are with us or you are evil, trying to crash at opening events of MS/Apple "saving" people from closed source etc. Not everything has to be open source and not everyone has to choose open source. Microsoft/Apple/Google m…

>I find GPL to be against the "spirit of open source"

More like Open Source is against the GPL, which is really the only reason the OSI came into existence.

>either you are with us or you are evil

Free software is about morality, not about getting or giving away free stuff. When you take a moral stand, you're necessarily making a moral judgement about people who don't.

Open source sells itself as a better way of doing business. Free software supports people's full ownership of their own devices even if it is worse for business.

Re: FSF responds to Microsoft's privacy and encryption announcement

#56
post #20

Earlier quoted context omitted.

> Sure it is not 100% fool proof, but it makes it far harder to sneak bad things through. Debian SSL bug lasted 2 years. Open source means little for security.

cherrypicked examples mean little for arguements either. The WMF exploit was in windows for more than 15 years. http://en.wikipedia.org/wiki/Windows_Metafile_vulnerability

There are a lot or security holes regularly surfacing in all kinds of software. We don't even have the post mortem of the kernel.org compromise , as one example. Even some Debian servers got hacked. Open source helps but lets not pretend it's a panacea.

Re: FSF responds to Microsoft's privacy and encryption announcement

#57
post #33

As long as Microsoft tells NSA about the bugs they have in Windows before they start fixing them [1], that just constitutes the same thing as "backdoors", since with many of those bugs NSA can take full control of a machine. So Microsoft doesn't need to "give NSA a backdoor". They just need to tell them about certain bugs before they fix them - and that's just as bad as giving them backdoors, since NSA can and will u…

You're describing a security disclosure program. Since anyone else could have (and often has) already found the attack, the point of this is to put the defenses up as early as possible.

Surely real valuable attacks would be ones there's no planned security update for.

Re: FSF responds to Microsoft's privacy and encryption announcement

#58

Earlier quoted context omitted.

"Freedom and security necessitate not just being allowed a peek at the code." "Transparency in the Windows world normally means self-reports commissioned by Microsoft, or access granted to outsiders covering very limited portions of source code under strict agreements that limit sharing that information." Yup, John Sullivan really ignored that. You can disagree with the FSF's mission, but they are certainly not sprea…

The source agreements are far more than just a "peek" at the code. I would still argue that Mr Sullivan is at the very least distorting the truth, if not outright lying. The FSF has its agenda, and has proven it will try to distort the motives of any entity that doesn't completely agree with it.

>I would still argue that Mr Sullivan is at the very least distorting the truth, if not outright lying.

And I would listen to that argument, but you haven't made it.

Re: FSF responds to Microsoft's privacy and encryption announcement

#59

Earlier quoted context omitted.

More than just the NSA. This shrill hyperbole that permeates the free software world is counterproductive to getting things fixed.

Drcube: How do I know that open source developers aren't contractors out to put backdoors in? At some point you have to trust someone, and I doubt with all the eyes on windows, both within and without, that any extant backdoor would have remained hidden until now. There are quite a few people who do reverse engineer windows without a license, and would be shouting it from the rooftops if they found a backdoor.

>How do I know that open source developers aren't contractors out to put backdoors in?

You don't. That's why the source is open.

Re: FSF responds to Microsoft's privacy and encryption announcement

#60
post #33

As long as Microsoft tells NSA about the bugs they have in Windows before they start fixing them [1], that just constitutes the same thing as "backdoors", since with many of those bugs NSA can take full control of a machine. So Microsoft doesn't need to "give NSA a backdoor". They just need to tell them about certain bugs before they fix them - and that's just as bad as giving them backdoors, since NSA can and will u…

You're describing a security disclosure program. Since anyone else could have (and often has) already found the attack, the point of this is to put the defenses up as early as possible. Surely real valuable attacks would be ones there's no planned security update for.

>You're describing a security disclosure program.

No, a security non-disclosure program. Disclosure is when you tell people. Telling a spy agency in no more "disclosure" than telling a Russian trojan dev.

Post reply on HN