Live data from Hacker News

Dutch government says no to backdoors, grants $540k to OpenSSL

theregister.co.uk

21–30 of 101 posts

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#22
post #7

Wasn't OpenSSL quite vulnerable and not recommended to use few years back and people were phasing it out? Or am I mistaking this with something else?

There was a pretty serious security issue in it, but it was fixed. A lot of people were predicting the end of OpenSSL, but at the end of the day, most viable alternatives came around too late for people to phase it out.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#23
post #7

Wasn't OpenSSL quite vulnerable and not recommended to use few years back and people were phasing it out? Or am I mistaking this with something else?

You're a bit mistaken. A lot of FOSS political warrghble happened, but OpenSSL still remains the most audited and used SSL library out there.

Yes, it may have bugs. Yes, the NSA may have tampered with the standards themselves (that everyone else must also implement, else risk compatiblity issues in some areas).

But there are no drop in alternatives that aren't based on the same codebase, and almost no one is using any alternatives: NSS (Mozilla's framework) is rarely used outside of Firefox, GnuTLS is rarely used, I've never heard of anyone using PolarSSL outside of very specific embedded projects, and LibreSSL (a OpenSSL fork) is being adopted only as a license-related political response, and BoringSSL is Google's response to the entire thing (their own OpenSSL fork that they control, to just ignore the entire political bullshit).

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#24
It's nice, meanwhile "we" now have a law being debated by government (not sure it will pass) that allows the government to hack individuals if they are suspect, this may even happen via people the suspect may know. It even includes being allowed to install spyware on a webcam.

But I guess it is good to leave encryption strong, forget about mass surveillance and focus energy on individuals actually suspected of a crime.

The cynic in me thinks the reasoning was: "We need a European Google", "We see that Europeans distrust American companies because of NSA economic spying in the past", "Let's make the Netherlands more attractive for large European companies"... no Idealism involved.

Edit: Updated original post: This new law ("Wet Computercriminaliteit 3") has not been passed yet!

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#25
If I'm thinking of the same thing (and I believe I am), the vote actually happened a month or so ago.

The original proposal was to give 500k euro to OpenSSL but what actually was approved was to spread that out amongst OpenSSL, PolarSSL (which, I think, comes from .nl), and LibreSSL, in a manner that was not yet determined.

Personally, I'd prefer to see the majority of it go to the guys working on LibreSSL simply because I think it would have the most impact there. I somewhat expect most of it go to OpenSSL, however, if for no other reason than it being the most widely used of the three.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#26
post #24

It's nice, meanwhile "we" now have a law being debated by government (not sure it will pass) that allows the government to hack individuals if they are suspect, this may even happen via people the suspect may know. It even includes being allowed to install spyware on a webcam. But I guess it is good to leave encryption strong, forget about mass surveillance and focus energy on individuals actually suspected of a crim…

Without knowing the details, I think this sounds fine as long as there is reasonable suspicion, it is approved by a court or judge, and a warrant is issued to conduct the surveillance.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#27
post #26
post #24

It's nice, meanwhile "we" now have a law being debated by government (not sure it will pass) that allows the government to hack individuals if they are suspect, this may even happen via people the suspect may know. It even includes being allowed to install spyware on a webcam. But I guess it is good to leave encryption strong, forget about mass surveillance and focus energy on individuals actually suspected of a crim…

Without knowing the details, I think this sounds fine as long as there is reasonable suspicion, it is approved by a court or judge, and a warrant is issued to conduct the surveillance.

Indeed, it is the way to go imo, it is akin to a steak-out, hacking friends and family though... a bit fishy.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#28
post #24

It's nice, meanwhile "we" now have a law being debated by government (not sure it will pass) that allows the government to hack individuals if they are suspect, this may even happen via people the suspect may know. It even includes being allowed to install spyware on a webcam. But I guess it is good to leave encryption strong, forget about mass surveillance and focus energy on individuals actually suspected of a crim…

As an American unhappy with the way our government is heading (backdoors in encryption), I would love to see a "European Google". I am certainly no expert in laws in the EU but, as I understand it, the data protection laws there are actually pretty good. I would much rather handle/host my data in countries where the companies are held to these standards.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#29
Dutch here. The argumentation is remarkably good. The privacy like you have with letters and phone calls is part of our constitution, and also part of European guidelines. The rules to violate this privacy, only in certain cases, is already part of the law (eg. wiretaps under suspicion). ISPs have to cooperate where possible.

That the dutch intelligence services are now hampered by end-to-end encryption making the ISPs have no way to cooperate any more, is basically the problem of the intelligence services to solve, and not a legal problem. Hence, encryption stays in place.

Post reply on HN