Live data from Hacker News

Dutch government says no to backdoors, grants $540k to OpenSSL

theregister.co.uk

81–90 of 101 posts

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#81

The danger of critical infrastructure being attacked digitally is already far greater than the risk of say, a bomb attack. Weakening our digital defenses to spy on terrorists is like throwing your laptop in the pool because you're afraid someone might light it on fire.

"The danger of critical infrastructure being attacked digitally is already far greater than the risk of say, a bomb attack."

This is not true. However, it is important to keep in mind that were it ever true it would be because of blatant negligence on the part of human actors.

It is neither obvious nor inevitable that a nuclear plant will ever be attacked digitally because a nuclear plant need not be networked - even internally.

It is neither obvious nor inevitable that a hydro dam will ever be attacked digitally because a hydro dam need not be networked - even internally.

With an open mind and some creativity this could be true even for things like air traffic control and the power grid. They don't need Internet access. They might not even need IP.

If any of these things are fragile to digital attacks it is because they were gratuitously made fragile.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#82
post #75

Earlier quoted context omitted.

Someone who disagrees with your policy does not make them a douche. This is the beginning of illiberal politics: If you are not with me, I will denigrate your person and declare you an enemy. The left wing of Europe was running at full speed towards Stalin / USSR for most of 2nd half of 20th century. It's easier to name-call than to govern.

You're doing exactly the thing that you're accusing of -- labeling. Just because you disagree with left parties' policies you're labeling them they were running towards Stalin and USSR, which is also not very logical since Stalin died in 1952.

Well, the USSR is dead and gone too. Maybe that statement would have been better as the idiom "going the way of the do-do bird?"

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#83
post #75
post #33

This statement was made early December. And I think it does deserve some nuance: Minister Steur (Security and Justice) this monday said, representing the second chamber, that "laws that prohibit encryption are not desirable at this time ". That doesn't retract their early statement, but I think it's an important nuance. Arguably, it might also just be political play to get some douchebag rightwing parties over the li…

Someone who disagrees with your policy does not make them a douche. This is the beginning of illiberal politics: If you are not with me, I will denigrate your person and declare you an enemy. The left wing of Europe was running at full speed towards Stalin / USSR for most of 2nd half of 20th century. It's easier to name-call than to govern.

There are some parties / persons in Dutch politics who refrain from healthy discussions and just money grab with popular and sometimes hate inducing statements. It so happens that they disregard any privacy, as well. I call them douches, and I'm very happy and confident to do so.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#84
post #75

Earlier quoted context omitted.

Someone who disagrees with your policy does not make them a douche. This is the beginning of illiberal politics: If you are not with me, I will denigrate your person and declare you an enemy. The left wing of Europe was running at full speed towards Stalin / USSR for most of 2nd half of 20th century. It's easier to name-call than to govern.

You're doing exactly the thing that you're accusing of -- labeling. Just because you disagree with left parties' policies you're labeling them they were running towards Stalin and USSR, which is also not very logical since Stalin died in 1952.

For those who have history exam tomorrow: 1953.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#85
post #52
post #32

Earlier quoted context omitted.

If there is a reasonable suspicion I don't see the problem with giving law enforcement the legal ability to hack their targets. This is something very different from drag-net surveillance and should not be tainted with the same stigma. It's not like the government actually _needs_ or wants to maintain giant botnets of all the targets they've hacked.

Withholding known security vulnerabilities from the public in order to be later used for hacking is immoral and dangerous. Imagine if the police had prior knowledge of a vulnerability in the computer system of a car, but did not act to protect the public. A few years later a criminal figure out the same vulnerability and causes a major car crash on a motorway and murder several people. I would view the police officer…

Withholding known security vulnerabilities from the public in order to be later used for hacking is immoral and dangerous.

I was thinking about this when Anonymous "hacked" thousands of ISIS twitter accounts. On the one hand that saves Twitter from having to make a stand themselves - but if they didn't immediately plug those holes, they're leaving legitimate users at risk.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#86
post #42

'Although the Dutch position is nuanced and firm, the government also has the luxury of not having real impact on the real world' noted.

Some people desire simplicity, and will think it into existence if necessary. I expect the author of those words didn't, for example, think about the Netherlands being a net contributor to the EU, he just knew it's a small country. In the EU, net contributors seem to have something awfully close to an effective veto regarding minor issues, so this is good news.

> In the EU, net contributors seem to have something awfully close to an effective veto regarding minor issues,

Do you have a source for this? I never got this impression. Some countries have proportionally large influence due to their size, namely France and Germany. Some others due to the high quality diplomats and politicians they send to Europe, such as Belgium and Italy.

Some countries actively sabotage their own influence in the EU, by showing nothing but hostility and obstruction (UK), or by using the EU as a kind of retirement plan for politicians and diplomats that failed domestically (Netherlands). Always echoing the German point of view should not be seen as "an effective veto", it is essentially an attempt to stay in favor with their formerly close, powerful friend to the east, who has been getting less and less interested over the years, as his attention shifts towards the East.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#87
post #75

Earlier quoted context omitted.

Someone who disagrees with your policy does not make them a douche. This is the beginning of illiberal politics: If you are not with me, I will denigrate your person and declare you an enemy. The left wing of Europe was running at full speed towards Stalin / USSR for most of 2nd half of 20th century. It's easier to name-call than to govern.

You're doing exactly the thing that you're accusing of -- labeling. Just because you disagree with left parties' policies you're labeling them they were running towards Stalin and USSR, which is also not very logical since Stalin died in 1952.

He used an example. He didn't call every left-wing party literally Communist. Classic HN pedantry.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#88
post #66
post #48

I hope we don't get someone in a few years "uncovering secret information that OpenSSL is funded by a foreign government".

They are funding it in public, no secret on that part. Hopefully they won't fund secret backdoors though :)

I mostly meant the parallels with Tor (which is also openly government funded)

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#89

Earlier quoted context omitted.

Debian stable is using LibreSSL for around a year already (Debian started switching just after the fork).

Debian is not using LibreSSL, I just checked. Sid currently ships OpenSSL 1.0.2e, and Jessie currently ships 1.01k.

Ouch, you are correct.

Something changed a while ago, my software stopped working with it, and I could only fix once I followed some LibreSSL guidelines. I thought it was this change, looks like I was wrong.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#90
post #81

The danger of critical infrastructure being attacked digitally is already far greater than the risk of say, a bomb attack. Weakening our digital defenses to spy on terrorists is like throwing your laptop in the pool because you're afraid someone might light it on fire.

"The danger of critical infrastructure being attacked digitally is already far greater than the risk of say, a bomb attack." This is not true. However, it is important to keep in mind that were it ever true it would be because of blatant negligence on the part of human actors. It is neither obvious nor inevitable that a nuclear plant will ever be attacked digitally because a nuclear plant need not be networked - even…

One only needs to look at the recent issue with hacking cars to see that it is quite possible. A single bomb, short of a nuke, would do far less damage than a virus attacking certain vehicles. The real issue is the effort needed to acquire the bomb/build the virus. Bombs seem to still have a far lower startup cost, so while you may get less bang for your dollar, they are more popular.

Is it popularity or damage/$ that determines what is more dangerous?

Post reply on HN