Live data from Hacker News

Why We Can No Longer Trust Microsoft

pcmag.com

221–230 of 310 posts

Re: Why We Can No Longer Trust Microsoft

#221
post #215

Earlier quoted context omitted.

"Ever heard of reverse engineering? It turns out you'd need even that approach even with open source as soon as you use binaries you haven't compiled yourself." This is true: reverse engineering can be used for verification, but it's a whole lot more work than inspecting source. "And you'd have to verify the compiler and your disassembler that way too." This is false. You can verify the compiler with diverse double c…

Am I missing something: does it mean that to verify the compiler with DDC you need a trusted compiler that always produces the same binary output as an untrusted one, so to verify GCC you need a compiler that duplicates the whole GCC functionality but is trusted? What is practicality of that approach? Proving that "hello world" produces the same output doesn't prove that the crypto functions wouldn't be patched? Plea…

Yes, you're missing something unfortunately. The author apparently states it several times, but many people must miss it in reading.

"I say it in the ACSAC paper, and again in the dissertation, but somehow it does not sink in, so let me try again.

Both the ACSAC paper and dissertation do not assume that different compilers produce equal results. In fact, both specifically state that different compilers normally produce different results. In fact, as noted in the paper, it’s an improvement if the trusted compiler generates code for a different CPU architecture than the compiler under test (say, M68000 and 80x86). Clearly, if they’re generating code for different CPUs, the binary output of the two compilers cannot always be identical in the general case!

This approach does require that the trusted compiler be able to compile the source code of the parent of the compiler under test. You can’t use a Java compiler to directly compile C code."

Re: Why We Can No Longer Trust Microsoft

#222

Earlier quoted context omitted.

not worth the legal hassle That's not the Steve Jobs I read about. Like him or not, he was a man of principle.

Principles must have come to him later in life because I'm sure his first daughter would have something to say about that.

Being principled does not necessarily mean they are principles you agree with!

Re: Why We Can No Longer Trust Microsoft

#224
post #213

Earlier quoted context omitted.

Unfortunately, those are real courts, their functions and jurisdictions have been established by the Congress.

If congress can redefine courts into what is basically an administrative panel, then the entire separation of powers can be short-circuited. It's not a court just because congress says so.

That's the crux of the matter. The root cause is that half of Americans are okay with such courts.

Re: Why We Can No Longer Trust Microsoft

#225
post #107

Earlier quoted context omitted.

I thought you were joking about the number plates thing, but it's true (and apparently legal) ... http://thenextweb.com/apple/2011/10/27/mystery-solved-why-st... This reminds me of a friend of mine who proxies all his web traffic through something which strips user agents and referrers. It's very easy for me to tell when he visits my website, because the logs show "-" for each of these fields.

How does your friend do that? I'd be really interested in reading on how to setup a proxy like that.

http://www.privoxy.org/

It is really simple.

Re: Why We Can No Longer Trust Microsoft

#226
post #132

Earlier quoted context omitted.

With a public record as a LSD user, I wonder how they could have justified giving him clearance.

I remember an Australian talking about the various levels of clearance - confidential, secret negative (anything stand out in your history), secret positive (in-depth active examination of your history). He said that the process wasn't about finding dirt on you, it was about finding out if you had any dirt that could be leveraged against you. For example, if you were gay and being outed would be a problem, then that'…

That harmonizes with my experience. I was interviewing for a "top secret" job with the US and spent some time studying the system and looking over the appeals rulings of the clearance process.

Generally, the key things were, "are you a crook? are you liable to be bribed/coerced?".

E.g. one chap was a transvestite, but the appeals court ruled that since his wife and minister knew, it wasn't something that could be leveraged against him.

Re: Why We Can No Longer Trust Microsoft

#227
post #169

GNU/Linux, and Free software and hardware in general, look to be the BIG winners out of the NSA brouhaha, because all non-US governments, businesses, organizations, and individuals around the planet who need to safeguard their private or confidential information now have reason to mistrust proprietary (unauditable) software and hardware. Free, open software and hardware are less likely to have secret 'back doors' ins…

It would be grossly unprofessional of the three-letter agencies if they should have failed to run counter-intelligence operations upon the open source communities. Futhermore, given their resources to hire hackers and long history of infiltrating loosely affiliated organizations, it is hard to image that they have struggled to place moles deep within many critical projects. Open source communities have no membership…

Let's just go back to type writers and sending encrypted letters.

Re: Why We Can No Longer Trust Microsoft

#228
Wait a second... they trusted Microsoft?

;-)

Seriously though, if you don't play ball with the NSA, they come after you, your business, and your family with the full weight of the US government. Your wealth or status means nothing against it.

Which means, as a parent, I can relate.

Yes, you and I can sit here on my keyboard and say we would have stood our ground, but when you have a children and a mortgage, suddenly things are very different. Suddenly, you think that maybe fighting this one particular fight isn't worth the damage to you and your family.

That, my HN friends, is why the whole NSA PRISM thing is so evil and why it outrages us: Even those normally beyond the law (the rich and famous) are suddenly victims like the rest of us.

Re: Why We Can No Longer Trust Microsoft

#230

Earlier quoted context omitted.

It would be grossly unprofessional of the three-letter agencies if they should have failed to run counter-intelligence operations upon the open source communities. Futhermore, given their resources to hire hackers and long history of infiltrating loosely affiliated organizations, it is hard to image that they have struggled to place moles deep within many critical projects. Open source communities have no membership…

Is there any evidence of this? Certainly there is a single hacker out there that has been approached by the gov't or contracted for them for these purposes at some point, that is also willing to talk, even anonymously.

It's not the Lone Ranger. It's a business.

Think of Federal employees at Fort Meade, who were hired to do the sort of work I am describing.

Think of defense contractors with nondescript offices in Fairfax who hire those same employees after they leave the government and whose employees spend their days writing and pulling and pushing and merging open-source software.

Think of $200,000 a year.

Think of Edward Snowden.

A 1000 hackers is a line item in the NSA's budget.

Or the KGB's.

Or China's.

It's asymmetric warfare. But the side without the money is disorganized and open and trusting.

Post reply on HN