Live data from Hacker News

Dutch government says no to backdoors, grants $540k to OpenSSL

theregister.co.uk

41–50 of 101 posts

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#41
post #33

This statement was made early December. And I think it does deserve some nuance: Minister Steur (Security and Justice) this monday said, representing the second chamber, that "laws that prohibit encryption are not desirable at this time ". That doesn't retract their early statement, but I think it's an important nuance. Arguably, it might also just be political play to get some douchebag rightwing parties over the li…

I think this needs a whole lot more nuance. Minister Steur said that the laws are not desirable at this time, after other cabinet members said it will hurt economic relations. This is not a statement saying we don't want this, this is a statement saying we can't do this right now. Also, the money going to OpenSSL and others is completely unrelated to the current encryption banning talks going on in the Netherlands. T…

The money going to OpenSSL might be related to the issue the Dutch government ran into in 2011 with the Diginotar (a certificate authority) hack; the TLS certificates for Dutch government websites were compromised at that time. While this hack was not related to weaknesses in OpenSSL (as far as I know), this did put the spotlight on the vulnerability and dependence on of the certificate chain. Supporting the software that provides this crucial layer of security makes a lot of sense for a government that has been bitten once.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#42

'Although the Dutch position is nuanced and firm, the government also has the luxury of not having real impact on the real world' noted.

Some people desire simplicity, and will think it into existence if necessary. I expect the author of those words didn't, for example, think about the Netherlands being a net contributor to the EU, he just knew it's a small country.

In the EU, net contributors seem to have something awfully close to an effective veto regarding minor issues, so this is good news.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#43

If I'm thinking of the same thing (and I believe I am), the vote actually happened a month or so ago. The original proposal was to give 500k euro to OpenSSL but what actually was approved was to spread that out amongst OpenSSL, PolarSSL (which, I think, comes from .nl), and LibreSSL, in a manner that was not yet determined. Personally, I'd prefer to see the majority of it go to the guys working on LibreSSL simply bec…

Yes, the proposal was changed to spend the 500k EUR on open source encryption projects in general, to quote: "OpenSSL, LibreSSL, PolarSSL, etc." - no particular distribution of the money has been decided on as far as I can see.

Source: http://www.tweedekamer.nl/kamerstukken/amendementen/detail?i...

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#44

Earlier quoted context omitted.

FWIW, LibreSSL replaced OpenSSL in OpenBSD 5.6 -- over a year ago.

OpenBSD started the LibreSSL project, so, naturally, they would adopt it. OSX has also adopted it for purely license politics reasons, El Capitan shipped with it: $ /usr/bin/ssh -V OpenSSH_6.9p1, LibreSSL 2.1.8

> "... license-related political reasons ..."

> "... license politics reasons ..."

I'm not sure exactly what you mean by this?

I mentioned OpenBSD replacing OpenSSL with it simply because the "official" OpenSSH is now developed against it.

I'm not sure if LibreSSL is being used for the portable version yet but if/when that happens, I expect people will begin to "trust" it more, leading to more projects potentially deciding to also replace OpenSSL with LibreSSL (i.e. for valid technical reasons, not for "political" ones).

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#45

Earlier quoted context omitted.

You're a bit mistaken. A lot of FOSS political warrghble happened, but OpenSSL still remains the most audited and used SSL library out there. Yes, it may have bugs. Yes, the NSA may have tampered with the standards themselves (that everyone else must also implement, else risk compatiblity issues in some areas). But there are no drop in alternatives that aren't based on the same codebase, and almost no one is using an…

FWIW, LibreSSL replaced OpenSSL in OpenBSD 5.6 -- over a year ago.

And I believe RHEL/Fedora use NSS?

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#46
post #5

This reminds me of the time when NSA offered an encryption algorithm to the public...

i haven't read the article but isn't this the dutch government just giving money to an existing open source project, to use as they see fit to improve/maintain the existing library? seems ultimately the opposite of what you're talking about.

Sure, but you never know what (non-public) conditions are attached to the money...

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#49

If I'm thinking of the same thing (and I believe I am), the vote actually happened a month or so ago. The original proposal was to give 500k euro to OpenSSL but what actually was approved was to spread that out amongst OpenSSL, PolarSSL (which, I think, comes from .nl), and LibreSSL, in a manner that was not yet determined. Personally, I'd prefer to see the majority of it go to the guys working on LibreSSL simply bec…

> the vote actually happened a month or so ago.

Yup, I posted the result on HN but nobody cared at that point. I guess it wasn't quite concrete enough because the money would go to "undetermined open source projects that have to do with encryption, such as polarssl and openssl".

Post reply on HN