Live data from Hacker News

FSF responds to Microsoft's privacy and encryption announcement

fsf.org

61–69 of 69 posts

Re: FSF responds to Microsoft's privacy and encryption announcement

#61
post #11

Earlier quoted context omitted.

No, I think in the FSF's eyes -- rightfully -- it can't be proven that security has improved. I also can't agree that it isn't related. If I tell you I'm wearing a green shirt, how can you know for sure if you or someone you trust hasn't verified it? You can't. It's the same with MSFT. But in the case of MSFT, it has been proven that they wear a lot of Hypercolor[1] stuff. Is it good that MSFT is doing stuff to make…

So, Microsoft and its Windows product adheres to no industry standards, has no external audit process, has never been verified by a private or Government contract agency through audit or other verification process? I work in a small programming company and we do internal and external audits while maintaining compliancy with federal and state regulators as well as groups like ISO. Sure, our work is closed source, but…

Audit and verifying the security of software the size of Microsoft Windows without source code is like auditing and verifying the security of the international space station with only the help of a hand held telescope.

Sure, it looks like its not leaking air. It has not dropped down to earth yet, and all the videos posted on their website looks to show it being fine. However, if I ever went there and depended on its security, I would demand more.

Re: FSF responds to Microsoft's privacy and encryption announcement

#62
post #20
post #19

Earlier quoted context omitted.

Unfortunately, those skilled people at MS have let the NSA in on so many 0-day exploits. God knows how many have not been reported to the public yet. At least with open source, I know there is a community behind it for me or others to verify. Sure it is not 100% fool proof, but it makes it far harder to sneak bad things through.

> Sure it is not 100% fool proof, but it makes it far harder to sneak bad things through. Debian SSL bug lasted 2 years. Open source means little for security.

[deleted]

Re: FSF responds to Microsoft's privacy and encryption announcement

#63
post #34

Earlier quoted context omitted.

cherrypicked examples mean little for arguements either. The WMF exploit was in windows for more than 15 years. http://en.wikipedia.org/wiki/Windows_Metafile_vulnerability

SSL is a security sensitive bit of code. That's the kind of thing that needs to be kept safe, and it's the kind of thing that people claim is kept safe my open source's many eyes. The argument I'm making is not that Windows is secure (because it isn't), but that Open Source isn't necessarily secure just because it's open source.

No one has argued that open source is secure just because its open source.

Open source is however possible to independent verify if it is secure. Closed source is not possible to verify as secure and must be taken solely on the word of the company who made it.

Re: FSF responds to Microsoft's privacy and encryption announcement

#64
post #52
post #43

Earlier quoted context omitted.

It is not impossible. There is no reason why closed source software can not be secure. Yes, you can not convince yourself in the same way you can with open source software but again secure software and the ability to convince yourself that a software is secure are different things.

> There is no reason why closed source software can not be secure True, but there is no way to prove it's secure. It's not about convincing myself or anyone else - it's about proof.

You get no proof for open source software either unless you perform a formal verification. And even then your proof may be wrong.

But maybe we can agree on the following. Closed source software can be secure but there is a broad spectrum of needs for convincing someone that a software is secure and this need may be better served with open source software in some circumstances. For some it is sufficient to trust a vendor. Some want to audit the source code (and this does not exclude closed source software). Some even need formal verification maybe even of the underlying hardware.

Re: FSF responds to Microsoft's privacy and encryption announcement

#65
post #52
post #43

Earlier quoted context omitted.

It is not impossible. There is no reason why closed source software can not be secure. Yes, you can not convince yourself in the same way you can with open source software but again secure software and the ability to convince yourself that a software is secure are different things.

> There is no reason why closed source software can not be secure True, but there is no way to prove it's secure. It's not about convincing myself or anyone else - it's about proof.

So you mean the Linux kernel was proven secure? When?

http://www.theregister.co.uk/2009/08/14/critical_linux_bug/

http://www.networkworld.com/community/blog/linux-finally-fix...

http://it.slashdot.org/story/11/06/20/2257229/13-year-old-pa...

You're trying to apply an impossible standard to closed source software that software that was that developed from the start to be open source and developed in the open cannot meet.

Re: FSF responds to Microsoft's privacy and encryption announcement

#66
You've got to read between the lines with a corporate statement. There are two major issues this one:

1) They're giving no indication that they can't decrypt their customers data. This won't protect customers from the thousands of information requests that they're not allowed to publicly acknowledge, and will only hamper vectors such as MITM fibre splitting. This is concerning given the fact the US intelligence agencies share their data with private companies, and that Microsoft didn't even attempt resist previous requests. They have no incentive to inform customers and fight expensive legal battles, so as soon as the whole privacy thing blows over it will be back to old habits.

2) Allowing companies to review their source code is only useful for their desktop products. Most data is going into the cloud now, plus it's possible to use cross library exploits and obfuscated code. I don't actually think that they'll do this now, hover they've done it in the past with their famous NSAKEY in the 4.0 kernel.

Office 2008 with a firewall will keep your data safe. Office365 is a company risk. I wouldn't put anything more confidential than a CV or short story on it.

Re: FSF responds to Microsoft's privacy and encryption announcement

#67
post #7
post #6

> A lock on your own house to which you do not have the master key is not a security system, it is a jail. This is completely bogus. The owner of the master key may have the access (understandably undesirable), but that does not keep you from getting out. If anything, it's like having no lock at all.

True, but their point that "these promises are meaningless" remains valid.

Replace "Microsoft" with manufacturers of food, cars, medicines, personal hygiene products, etc. They are regulated, inspected, but all under the same / similar conditions:

> or access granted to outsiders covering very limited portions of source code under strict agreements that limit sharing that information

You are trusting the manufacturer's promises. Are they essentially meaningless just because the general public doesn't have insight into manufacturing details?

Re: FSF responds to Microsoft's privacy and encryption announcement

#68

Earlier quoted context omitted.

cherrypicked examples mean little for arguements either. The WMF exploit was in windows for more than 15 years. http://en.wikipedia.org/wiki/Windows_Metafile_vulnerability

There are a lot or security holes regularly surfacing in all kinds of software. We don't even have the post mortem of the kernel.org compromise , as one example. Even some Debian servers got hacked. Open source helps but lets not pretend it's a panacea.

It's not all or nothing. Open source is better than close source for security auditing purposes, but of course open source alone is not enough, nor is it impervious to security flaws. It's just better than the alternative.

Re: FSF responds to Microsoft's privacy and encryption announcement

#69
post #11

Earlier quoted context omitted.

No, I think in the FSF's eyes -- rightfully -- it can't be proven that security has improved. I also can't agree that it isn't related. If I tell you I'm wearing a green shirt, how can you know for sure if you or someone you trust hasn't verified it? You can't. It's the same with MSFT. But in the case of MSFT, it has been proven that they wear a lot of Hypercolor[1] stuff. Is it good that MSFT is doing stuff to make…

So, Microsoft and its Windows product adheres to no industry standards, has no external audit process, has never been verified by a private or Government contract agency through audit or other verification process? I work in a small programming company and we do internal and external audits while maintaining compliancy with federal and state regulators as well as groups like ISO. Sure, our work is closed source, but…

If a piece of proprietary/close source software gets audited by an external agency, any of the private actors involved can be involved in deception (the authors of the software, the auditing company and the government or whatever). They can all be in collusion. This would have sounded like a conspiracy theory before recent discoveries, but now we've seen this can actually happen.

Whereas if the source is open, and you are a subject matter expert (yes, that's a big if), you can review the source yourself. You can decide for yourself whether the software has an NSA backdoor, an innocent flaw or whatever.

Yes, a lot of people, myself included, don't have the technical background to do this. But with open source we could, if we had the knowledge (which can be learned), without relying on potentially compromised authorities.

With closed source we simply can't. We have to trust the auditors and the government, which have been shown to be unreliable.

Post reply on HN