Live data from Hacker News

Open Source Could Be a Casualty of the Trade War

bunniestudios.com

41–50 of 79 posts

Re: Open Source Could Be a Casualty of the Trade War

#41
post #36

Earlier quoted context omitted.

> really basic things like updating OpenSSL libraries seem near impossible for Huawei. > Huawei (...) took their designs and code, without fully understanding them. Do you want to say that there aren't people in China smart enough to "update OpenSSL" in their codebase? Whichever way the codebase started to be used by the company? A lot of companies and developers inherit the products created in some other times in so…

Many companies have the same problems, not rewarding people who fix these type of security issues and look at security holistically, and instead the only path to success is to create new features

See Cisco's handling of their low-end routers as a great example: https://news.ycombinator.com/item?id=19507225

It is rotten corporate culture that is starving critical maintenance work at these companies, creating the internet of vulnerable shit.

Re: Open Source Could Be a Casualty of the Trade War

#42
post #17
post #5

Earlier quoted context omitted.

Fortunately, there is a bulwark: Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the Government for a redress of grievances. The bulwark defending the bulwark is the population.

Good luck explaining your commits to that munitions grade crypto used by terror cells in the mideast region as "Free Speech". Hope that works out for you. :-( (I'd wager there'll be a few more Snowden types asking for asylum outside the US before this is all over.)

If good crypto really boils down to math, and therefore either everyone can be secure or noone, then I'd rather everyone be secure. There are more ways to stop terrorists than wanton collection of communication.

Re: Open Source Could Be a Casualty of the Trade War

#43

Earlier quoted context omitted.

Bunnie seems to fear this type of IP restriction but with regard to closed source chipset designs and proprietary hardware, which he views as key to continued innovation in China. I have met Bunnie, and he has a bit of a warped view of the world. I think it caused him to gloss over things like https://www.theregister.co.uk/2019/03/28/hcsec_huawei_oversi... where Huawei did not give a single shit about security in the…

And so is so much other US-produced or maintained hardware. Do we now ban outdated corporate websites which can be hacked and used to launch attacks on other servers? The Huawei ban is very clearly a political anti-China move, not one based on technical reasons.

We need a cultural shift, security should not be a whimsical dream. A company running vulnerable websites should be culpable for their neglect, and likely shouldn't be administering their own IT affairs if they are repeatedly negligent.

This is an anti-China move, but we do know Huawei builds vulnerable LTE basestations and products, and refuses to do the bare minimum to secure them, despite promising $20 billion in investment in software security (see the article I linked to earlier).

Re: Open Source Could Be a Casualty of the Trade War

#44

“through powers granted via the “EAR” (Export Administration Regulation 15 CFR, subchapter C, parts 730-774), along with a sometimes surprisingly broad definition of what qualifies as export-controlled US technology.” Boom! I told people they might do that back in the crypto discussions. Custom crypto and high-assurance security are still munitions with only a few things re-classified such as mass-market, one-size-fi…

> The best route to that is to intentionally leave in memory safety bugs or a configuration that enables privilege escalation. Hackers find those all the time in all kinds of devices. They say, “Hey, they just made a common mistake.” Maybe it was there on purpose. We won’t know.

By that logic everyone from Apple to Xerox could possibly be enabling computer espionage. You’d never be able to prove a bug wasn’t a deliberate back door.

Re: Open Source Could Be a Casualty of the Trade War

#45
post #27

Considering that two U.S. appeals courts have ruled that source code which was classed as a munition was protected by the First Amendment, I'm not too worried just yet. Of course we have a lot of new judges so who knows.

Bunnie seems to fear this type of IP restriction but with regard to closed source chipset designs and proprietary hardware, which he views as key to continued innovation in China. I have met Bunnie, and he has a bit of a warped view of the world. I think it caused him to gloss over things like https://www.theregister.co.uk/2019/03/28/hcsec_huawei_oversi... where Huawei did not give a single shit about security in the…

This seems like a specific and direct attack at Bunnie. Do you have any evidence to back up your claim? Was your opinion of what you call his 'warped view of other world' shaped from your conversation? What specifically about that conversation led you to that conclusion?

I don't know Bunnie and I only follow his blog posts sometimes but he's a strong proponent of open source software and open source hardware [1]. Bunnie is helping to develop a fully open source hardware laptop, Novena [2], that requires companies providing components to not require non disclosure agreements [3]. Bunnie is also specifically interested in FPGAs and making them and their toolschains available [4].

Your post seems like it has a veiled nationalistic and anti-open source undercurrent. Is Bunnies silence on the matter of the Huawei security issue reason for you to have this view? If so, do others not mentioning Intel's vulnerabilities [5] the past years also mean they have the same "warped view of the world".

To be clear, I'm not trying to absolve Huawei or Intel of anything. I'm trying to address the claim that Bunnie turns a blind eye to proprietary chipset and hardware technology more than others.

[1] https://www.eff.org/press/releases/hardware-hacker-anti-acta...

[2] https://www.bunniestudios.com/blog/?cat=28

[3] https://en.wikipedia.org/wiki/Andrew_Huang_(hacker)#Novena

[4] https://www.bunniestudios.com/blog/?p=5166

[5] https://meltdownattack.com/

Re: Open Source Could Be a Casualty of the Trade War

#46

Earlier quoted context omitted.

Already holds up: "The claimed principle was simple: export of munitions—guns, bombs, planes, and software—was (and remains) restricted; but the export of books is protected by the First Amendment. The question was never tested in court with respect to PGP. In cases addressing other encryption software, however, two federal appeals courts have established the rule that cryptographic software source code is speech pro…

How it worked out last time is no guarantee of how it will work out this time.

I like the odds in the US better than anywhere else. No other country has a better track record of protecting freedom of speech.

Re: Open Source Could Be a Casualty of the Trade War

#48
post #2

The article takes a while to get to the point made in the title but the way to counteract this seems to be, get the infrastructure for open source out of America before it's too late. In contrast to the ARM example, the US doesn't really have any leverage against a volunteer open source project not within its borders.

This means get the open source off github as well...

Or keep it there where you have one of the most powerful companies in the world to defend it.

Re: Open Source Could Be a Casualty of the Trade War

#49
post #9

Earlier quoted context omitted.

Open Source effectively is out of America or any other single jurisdiction: think of all of the people who have up to date copies of virtually every package all around the world. If the U.S. were to say tomorrow, as we used to do with cryptography, that (certain types of) software can't be shared outside of the U.S., the development of said (Open Source) software would likely just be taken over by groups outside the…

I believe the majority of FOSS developers reside in the US. You can't really pipe them out through a fiber channel.

Citation needed. Honestly this seems like a pretty offensive american-centric belief

Re: Open Source Could Be a Casualty of the Trade War

#50

[flagged]

> I have zero problems with "economic pain" caused by us not doing business with a country that has 1M people in "re-education camps", disappears protesters, and wants to extradite people from Hong Kong.

If these were the reasons for the U.S's actions I would agree with you more. I think only international pressure can help with these issues. The Chinese people themselves can do very little given the realities of their country's surveillance capabilities.

But let's not nobly kid ourselves that these issues have anything to do with the cause or the possible resolution to the trade war.

Post reply on HN