Live data from Hacker News

The EU Open Source Strategy

digital-strategy.ec.europa.eu

141–150 of 167 posts

Re: The EU Open Source Strategy

#141
post #87

Earlier quoted context omitted.

Sovereignty yes it's obviously better. I am just talking about the pure tech fact that GNU/Linux desktops do not have any meaningful intra-host security boundaries. Is this a worthwhile tradeoff against being tied to US tech? Yeah maybe, like I said there are no good options here, and Linux might be the least bad.

Genuinely interested: does it bring something to say "everything is crap anyway, but given that we must choose between one of them, we may as well choose the least bad" instead of "the best solution we currently have is X"? Secondly, are you sure that it is impossible to secure a system for a whole department? I have seen relatively big companies having an IT team managing their own Linux flavour. That is, whitelisti…

> Genuinely interested: does it bring something to say "everything is crap anyway, but given that we must choose between one of them, we may as well choose the least bad" instead of "the best solution we currently have is X"

Well I dunno if that's true, that's why I didn't say it. Linux _may_ be the best solution overall I am not sure. It is definitely not the best solution from a security perspective.

> Secondly, are you sure that it is impossible to secure a system for a whole department? I have seen relatively big companies having an IT team managing their own Linux flavour. That is, whitelisting the packages that can be installed by the users.

Just whitelisting packages isn't enough. ChromeOS effectively does this and their whitelist is extremely small, yet they are still only ok with that because they backed it up with the rest of the pieces needed to make a secure Linux desktop, including a fully vertically integrated stack.

Re: The EU Open Source Strategy

#142

I wish there was somewhere I could earnestly and intelligently have discussions about EU related tech and tech policy, but HN isn't it. As you can see already in this thread, there's 14 comments besides mine and they are 100% negative, and about 95% low effort/reactionary. Of course there's a lot to criticize and also to appreciate about the EU. But this is supposed to be a forum for intelligent, thoughtful discussio…

I guess the hate is because the EU also invented the following monstrosities: - CRA (cyber resiliency act): Manufacturers must handle and release security patches for vulnerabilities, and developers are required to report actively on exploited vulnerabilities and breaches. - PLD (Product Liability Directive): A failure to provide critical security updates or the presence of exploitable vulnerabilities can now legally…

What is your point again? All of the above sounds perfectly fine to me.

Re: The EU Open Source Strategy

#143

Earlier quoted context omitted.

Sovereignty yes it's obviously better. I am just talking about the pure tech fact that GNU/Linux desktops do not have any meaningful intra-host security boundaries. Is this a worthwhile tradeoff against being tied to US tech? Yeah maybe, like I said there are no good options here, and Linux might be the least bad.

You know what happened at Google after Operation Aurora and they went full bore on security (BeyondCorp and all that)? They started phasing out Windows laptops for employees immediately. I'm honestly having trouble taking you seriously, Windows has always been at the butt of security jokes, I guess you maybe didn't grow up with winnuke etc? But maybe you could elaborate a bit more concretely about what kind of intra-…

I worked at Google on post-Aurora endpoints security. Windows laptops are alive and well at Google. Linux laptops have had one foot in the grave for a while now (it's a bummer). Google historically made gLinux work only with enormous investments in customised distros and D&R.

> But maybe you could elaborate a bit more concretely about what kind of intra-host security boundaries are missing

- no boundaries between applications, everything runs as $USER which can read your browser creds

- no boundary between user and root, everything can trivially escalate privs (maybe we will fix this post Glasswing, let's see)

- no boundary between boots, root can trivially persist a compromise (probably non-root too)

The tech exists to solve all these problems on Linux, but there isn't a distro that strings it all together. (Unless you count ChromeOS/Android which are not really OSS).

Re: The EU Open Source Strategy

#144
post #7

Earlier quoted context omitted.

Although I usually come up negative on my The Year of Linux Desktop comments, that would already be a starting point. Unless EU citzens are able to easily walk into FNAC, Vobis, Cool Blue, MediaMarket, Carrefour, Publico,.... and come out with a laptop or desktop with e.g. SuSE Linux already set up, this will always be a niche thing from nerds assembling their own PCs, or finding their ways into Tuxedo and co. And th…

I do not think I want my public sector running GNU/Linux desktops. There is no distro that meets the security requirements. I don't know if Windows is better, I have heard rumours that it's pretty bad. I know MacOS is MUCH better from a security PoV but I definitely don't want my public sector shelling out to Apple and I don't think it meets the boring IT management requirements anyway (I think big tech has a lot of…

So the NSA baseline of Linux + SELinux (that they helped develop) does not meet your needs but MacOS does? Please educate me.

Re: The EU Open Source Strategy

#145

Earlier quoted context omitted.

[flagged]

I read it in full years ago and found it quite clear. Which parts did you find to be vague?

Look if everyone agrees the outcome of the law has been incredibly annoying, then that is ultimately down to the law and/or its enforcement. The point of the law is to provide incentives to self-interested actors for good behaviour. I see a lot of complacency in these threads, combined with a lot of frankly absurd posturing, like if anybody is against the GDPR, they must’ve been brainwashed by Elon Musk. No! People dislike it because they dislike its practical effects, and frankly the EU should take responsibility for that and try to fix it.

Re: The EU Open Source Strategy

#146

Earlier quoted context omitted.

I do not think I want my public sector running GNU/Linux desktops. There is no distro that meets the security requirements. I don't know if Windows is better, I have heard rumours that it's pretty bad. I know MacOS is MUCH better from a security PoV but I definitely don't want my public sector shelling out to Apple and I don't think it meets the boring IT management requirements anyway (I think big tech has a lot of…

So the NSA baseline of Linux + SELinux (that they helped develop) does not meet your needs but MacOS does? Please educate me.

SELinux is a framework not a solution. Main places that gap is closed are Android and ChromeOS, not normal distros.

MacOS has:

- Serious integrity story

- Actual kernel hardening

- No reams and reams of garbage in their kernel (wouldn't have equivalents to the recent AF_ALG vulns coz they don't have dumb stuff like AF_ALG).

- Filesystem security boundaries retrofitted onto the Unix model (interesting user data, browser creds etc are gated by special permissions that are tied to the application build, backed by the integrity story - a `curl | bash` command cannot dump your ~/Documents)

When people escalate privileges on MacOS it's news, when they do it on Linux it's Tuesday (you might think the recent spate of privesc vulns on Linux was unusual but that is totally normal).

I say this as someone who works on Linux security every day (I am a kernel developer) and uses Linux on every computer I have, both at work and at home, BTW. I am not a Linux hater or Apple fanboy by any means.

These are all solvable problems at EU scale too. Just, I think they should solve other problems first in the priority list of delivering sovereign IT.

Re: The EU Open Source Strategy

#147

Earlier quoted context omitted.

It’s even more interesting because a big supply chain problem during Covid were related to old chips used in tons of mechanical engineering products, like cars. Given that experience you could argue that the old fabs are much better value for money for resiliency.

Asianometry just released a video about this: The EU Chips Act is a Failure [0] Definitely the most cynical video he ever released. - [0] https://www.youtube.com/watch?v=eqoX9OIR-DI

Is cynical? I see lot of mocking in the comments but the video is basically saying to focus on the uncool older stable stuff and use that for stability. The very not recommended path there is to jump on hype of AI chips and fund some random Mistral AI chips.

Re: The EU Open Source Strategy

#148
post #145

Earlier quoted context omitted.

I read it in full years ago and found it quite clear. Which parts did you find to be vague?

Look if everyone agrees the outcome of the law has been incredibly annoying, then that is ultimately down to the law and/or its enforcement. The point of the law is to provide incentives to self-interested actors for good behaviour. I see a lot of complacency in these threads, combined with a lot of frankly absurd posturing, like if anybody is against the GDPR, they must’ve been brainwashed by Elon Musk. No! People d…

> People dislike it because they dislike its practical effects, and frankly the EU should take responsibility for that and try to fix it.

What’s to fix?

A business needs a legitimate reason to process personal data, people need to be sufficiently informed about how their data will be processed. These are not impossible obstacles. Anyone who claims otherwise is acting in bad faith because they know that people would not agree to what the business wants to do with their data.

Re: The EU Open Source Strategy

#149
post #83
post #71

Earlier quoted context omitted.

" True but it also reflects that the EU has indeed destroyed most goodwill towards it in the last decade regarding most things digital. " And these criticism destroys any goodwill from me. These are non topics my among political diverse friends. Most people criticise the EU internet regulations are American cry babys. Their arguments are shallow, their knowledge about EU is low.

If your friends have never said “man I hate these cookie popups”, they sound like a highly selected group.

My friends / co worker are computer and non computer people, hobbys, cultural background. Maybe your friend group is highly selected. Which country are you from?

Re: The EU Open Source Strategy

#150

I wish there was somewhere I could earnestly and intelligently have discussions about EU related tech and tech policy, but HN isn't it. As you can see already in this thread, there's 14 comments besides mine and they are 100% negative, and about 95% low effort/reactionary. Of course there's a lot to criticize and also to appreciate about the EU. But this is supposed to be a forum for intelligent, thoughtful discussio…

[flagged]

CRA is pretty damn cool
Post reply on HN