Live data from Hacker News

FSF responds to Microsoft's privacy and encryption announcement

fsf.org

21–30 of 69 posts

Re: FSF responds to Microsoft's privacy and encryption announcement

#21
Open/closed source software and secure/unsecure software are orthogonal concepts. Yes, it may be easier to assess open source software with regard to security and privacy issues, but it is absolutely not necessary. And even with open source software the overwhelming majority of users still has to trust some third party because it is absolutely unrealistic that every user or organization audits their complete software (and hardware) stack. The only thing you really gain is that you are free to choose which third party or parties you have to trust.

Re: FSF responds to Microsoft's privacy and encryption announcement

#22

I just love how the FSF ignores, and has ignored for a considerable amount of time that governments, and organizations can and have gotten the Windows source code, and that their actions today restate that they do provide the windows source code for governments to audit. Given that such programs have been available for a considerable amount of time, one has to wonder when the FSF is going to change their tactic away…

"Freedom and security necessitate not just being allowed a peek at the code." "Transparency in the Windows world normally means self-reports commissioned by Microsoft, or access granted to outsiders covering very limited portions of source code under strict agreements that limit sharing that information." Yup, John Sullivan really ignored that. You can disagree with the FSF's mission, but they are certainly not sprea…

The source agreements are far more than just a "peek" at the code. I would still argue that Mr Sullivan is at the very least distorting the truth, if not outright lying. The FSF has its agenda, and has proven it will try to distort the motives of any entity that doesn't completely agree with it.

Re: FSF responds to Microsoft's privacy and encryption announcement

#23

I just love how the FSF ignores, and has ignored for a considerable amount of time that governments, and organizations can and have gotten the Windows source code, and that their actions today restate that they do provide the windows source code for governments to audit. Given that such programs have been available for a considerable amount of time, one has to wonder when the FSF is going to change their tactic away…

So the NSA can see Windows source code, but Windows users can't? And users are supposed to feel secure about this? Why?

Re: FSF responds to Microsoft's privacy and encryption announcement

#24
post #11

Earlier quoted context omitted.

So, Microsoft and its Windows product adheres to no industry standards, has no external audit process, has never been verified by a private or Government contract agency through audit or other verification process? I work in a small programming company and we do internal and external audits while maintaining compliancy with federal and state regulators as well as groups like ISO. Sure, our work is closed source, but…

No, I did not say those things. That aside, if you wanted to, after an audit/review concluded, could you put a backdoor in your software? Since it's closed source, would anyone know about it?

There are these things called signed binaries...

Re: FSF responds to Microsoft's privacy and encryption announcement

#25

I just love how the FSF ignores, and has ignored for a considerable amount of time that governments, and organizations can and have gotten the Windows source code, and that their actions today restate that they do provide the windows source code for governments to audit. Given that such programs have been available for a considerable amount of time, one has to wonder when the FSF is going to change their tactic away…

I just love how you like to equate governments and organizations (not individuals) getting to peek at source code (that they're not allowed to modify, share or comment publicly upon) under an NDA as "open source". Who's outright lying?

I never said it was open source. However, the source is available, and researched, by third parties. The announcement today also states that they are making the source available to more eyes than before. Not everything needs to be completely open source.

Re: FSF responds to Microsoft's privacy and encryption announcement

#26

Earlier quoted context omitted.

No, I did not say those things. That aside, if you wanted to, after an audit/review concluded, could you put a backdoor in your software? Since it's closed source, would anyone know about it?

In deterministic build? It will be very hard. I doubt that any audit signs on anything other than specific versions.

does microsoft use deterministic builds?

Re: FSF responds to Microsoft's privacy and encryption announcement

#27
post #21

Open/closed source software and secure/unsecure software are orthogonal concepts. Yes, it may be easier to assess open source software with regard to security and privacy issues, but it is absolutely not necessary. And even with open source software the overwhelming majority of users still has to trust some third party because it is absolutely unrealistic that every user or organization audits their complete software…

At least with FOSS, I get to choose the third party I trust to verify my software's security. And I don't have to take it on faith, I can get a second opinion, or audit the parts I care most about myself.

Re: FSF responds to Microsoft's privacy and encryption announcement

#28
I think FSF has an open-source axe to grind here and this happens to be an issue they can use to bash MS. I do think MS should be praised for improving security. However, don't forget Snowden's warning -- encryption does not help you if you don't have secure endpoints. Moreover, encryption does not help you if you have rogue agencies with secret courts, secret rulings, no due process and no legal rights in a police or dragnet surveillance state.

I hope the big tech companies are serious about protecting their users, even foreign users, since their business model depends on it.

Re: FSF responds to Microsoft's privacy and encryption announcement

#29
post #27
post #21

Open/closed source software and secure/unsecure software are orthogonal concepts. Yes, it may be easier to assess open source software with regard to security and privacy issues, but it is absolutely not necessary. And even with open source software the overwhelming majority of users still has to trust some third party because it is absolutely unrealistic that every user or organization audits their complete software…

At least with FOSS, I get to choose the third party I trust to verify my software's security. And I don't have to take it on faith, I can get a second opinion, or audit the parts I care most about myself.

Added exactly this while you wrote you comment. I don't deny that open source software has advantages in this regard.

Re: FSF responds to Microsoft's privacy and encryption announcement

#30
post #20
post #19

Earlier quoted context omitted.

Unfortunately, those skilled people at MS have let the NSA in on so many 0-day exploits. God knows how many have not been reported to the public yet. At least with open source, I know there is a community behind it for me or others to verify. Sure it is not 100% fool proof, but it makes it far harder to sneak bad things through.

> Sure it is not 100% fool proof, but it makes it far harder to sneak bad things through. Debian SSL bug lasted 2 years. Open source means little for security.

cherrypicked examples mean little for arguements either. The WMF exploit was in windows for more than 15 years.

http://en.wikipedia.org/wiki/Windows_Metafile_vulnerability

Post reply on HN