Snowden: Privacy can't depend on corporations standing up to the government
networkworld.com
networkworld.com
When heartbleed broke that was evidence that the 'many eyes' theory of secure open source software hadn't worked. Alternatively, the bug was found because big corporations with security budgets were getting serious about holes, so maybe 'many eyes' is starting to be true. Certainly apple's 'goto fail' and RSA's key strength bribery are examples of 'not enough eyes' for closed software.
Heartbleed proved that just having software be open-source is not sufficient. Having the source available to audit isn't all the helpful if no one bothers to do the work to audit it, because they all assume someone else is going to do it.
However, if there are entities willing to put in the effort, it's much better for the code to be open-source because then it can be audited, and this auditing can be documented publicly (e.g., the fixes can be seen in git logs), whereas with proprietary software you have no idea if the software has bugs, you can't audit it if you want to, and you can only take the word of the vendor that they've made it secure, and of course we know that isn't worth squat.
Also, until reproducible builds become commonplace, most linux users can't verify that their binaries come from a specific version of the source. Binary verification is the way to go.
Sure is a ton of software you'd need to both find and maintain. This may be one of those things that sound good but are unworkable.
Please everybody, never stop promoting open-source solutions to your friends & family.
{ obligatory recommendation to watch PHK's "Operation Orchestra"[1], which discusses ways free and open software projects can be manipulated }
[1] https://archive.fosdem.org/2014/schedule/event/nsa_operation...
> but we absolutely need corporations to stand up to government
We need solidarity - the people and corporations - to stand up to problems in government. We also need the people and government to stand up to problems in corporations. Hoping that our social problems will be fixed by other people or some other group is a terrible defense strategy. There will always be people that try to control power or money; this requires constant vigilance and push-back from everybody; failure to do so creates more potentially exploitable attack surface.
The technical people that actually implement modern society hold an incredible amount of power. Unfortunately, the people involved are easily distracted with off-topic minutia and vague threats.
Does anyone here think all software should be open source?
I'm interested to debate someone about that. I can't see how that works unless the whole world stops using money.
These are also paid plugins. What this means is that once you download them, you can theoretically use them on as many sites as you like, release edited versions yourself or use them for as long as you need to.
What they charge for is basically the following:
1. Updates, since otherwise you have to find and install any updates outside the WordPress dashboard.
2. Support from their support team
That's how the WordPress scene in general works for paid products. The products themselves can be used however you like, but a paid license gives you access to support and much improved ease of use as far as updates and things are concerned.
So you can make money from open source software, and it would theoretically be possible to have all software as open source.
I think Richard Stallman addressed your concern in the GNU Manifesto back in 1985.
(I don't mean to suggest that his answers will necessarily convince you, just that the issue has been discussed explicitly for that long.)
https://en.wikipedia.org/wiki/Business_models_for_open-sourc...
I'm hoping Snowdrift.coop makes it viable.
Long-term, it should be financed via our taxes (best case: international agreement).
Perhaps the next level up is simply to allocate some money as simple grants. As long as you manage to produce the basic paperwork you get some additional money thrown at you.
I'm sure the lower end of such implementations are reasonably effective. After all their basic aim just to throw money around.
On top of that there's really not that many projects left, I'm sure we can continue to invent custom solutions for those.
I also think there are projects that a grant program could effectively support.
But I also think there is a really long tail of projects that some people would find worth having done, but that would not likely get done without someone paying, and would be difficult for grant issuers to distinguish from other projects that are simply not worth doing at all.
I think Snowdrift - or something similar - could have a huge role in such a world. In particular, a basic income would make it easier for more people to contribute to a project and also reduce the amount of money necessary to see a project move forward.
In an abstract sense, as i see it, we need to find a way to direct funding, in an accessible way, towards people just wanting to work on generally useful stuff, without being entirely reliant on capitalism and market economies.
I do fear that most schemes for selecting what to fund, grants, or capitalistic markets tend to promote the wrong things for the wrong reasons. Once serious money gets involved it gets ugly quickly and all sorts of gaming and failures take over.
I guess one failure mode of Snowdrift would be that high visibility projects, with a direct user facing component, will get loads of funds. But infrastructure kind of things, will be forgotten and be underfunded.
Perhaps not a real problem though, the funds going the user facing project might ripple down, so to speak, into the infrastructure.
In any case, the problem of selecting who should get money is hard, and you probably just have to accept that its a gamble with low odds of success. Maybe most of the things not worth doing, is worth doing precisely to find out how not worth doing they are!
The problem is thinking of software as a good (product). Software is not a scarce resource, so it is foolish to use tools such as capitalism (or other economic systems) as the model for the creation and distribution of software. Capitalism is very useful for optimizing the allocation of a scarce resource, but it doesn't apply for things that can be reproduced for free.
A better model is recognizing that software development is a service. We are moving quickly into a future filled with automation, data analysis, and everything we call "AI"; the demand for software development will be increasing dramatically. Just like today, most of this development will be for specific business needs, which are rarely useful directly to outside the specific use they were developed for.
Like plumbing, there will always be people who need software that is customized for their current situation. When you hire a plumber to install the waterworks for a new building, you don't expect them to develop their own type of pipe fittings; they use standard parts. Similarly, a business that has software needs should expect that the software developer they hire or contract will save time, money, and bugs by utilizing existing software that is available in the commons. The remaining bits of software that are necessary to customize the standard components for their specific needs are - by definition - not a "product" that is useful to others.
One scenario could therefor be that open-source development is financed via taxes, meaning we should pressure the government to initiate that.
Also requiring all software to use an open source development model is probably not necessary for security purposes.
- Art: Photoshop, Illustrator and Corel Painter are required by employers and educational institutions. GIMP/Inkscape etc. don't have feature parity so often can't be adopted.
- Messaging: Friends and family use Skype and Whatsapp. Network is too large to convert to an OSS alternative. No OSS alternatives are sufficiently developed to be viable regardless (Signal lacks a desktop/web (not Chrome) client, XMPP, Tox have no decent mobile story, Matrix clients are hard to sell).
- Browsing: Chrome's built in translation doesn't seem to have a viable alternative in other browsers like Firefox. Chromium lacks auto-update which is dangerous.
- Documents: There isn't any open source alternative I'm aware of to Google Docs that is nearly as convenient or easy to use.
- OS: Linux/BSD can't run the software needed for work/study so they're a no go.
It's easy to think in our little tech bubble that OSS is wonderful and we should be screaming from the rooftops to get people to use it but I just don't think it's ready yet. I can't even get my wife onto one OSS application and the same goes for most of the people I know.
When you understand why, you'll be better-equipped to work towards real solutions.
1. Consolidation & definition of protocols as well as inroads to making use of communications tools are controlled by gatekeepers:
1. Google
2. Microsoft
3. Apple
4. Other providers in non-english speaking countries.
I wouldn't call this easy to fix, but I don't think it is super difficult to fix this.
======
Let's assume you disaggregate some of the above and fragment it out enough where information is semi-balkaninized. I actually skipped over the initial problem referenced above:
It isn't people favor convenience over privacy (although they do) most people just DGAF. I think, and I have been considering this a fair bit lately, gov is actually pretty reasonably modeled (at least in the US) after society. No one actually values organization, deferred gratiofication, privacy or many other things I had previously assumed. So you actually just have to provide something really really great, get all the users, and provide them privacy for free and they won't care but will be semi-protected.
But, to resume here. If you build something people use, priovide them privacy, and dethrone incumbant internet companies, you still have huge obstacles:
Infrastructure. Broadspectrum is ~10 Billion for a band that can reach 200M people. Verizon is a 200B company (market cap). Comcast, Timewarner etc.
This is super hard to sort out. I actually think it is doable as well though. Let's wave our hands at this.
=======
Let's assume you have done the impossible: users all prefer amazing privacy by design top shelf UX open source software running on distributed systems in a decentralized network. You own bandwith and hard lines and insure you can protect and distribute signals with minimal interference. What do you do?
=====
No idea, pretty stuck here. I was thinking you return control to the people, but that doesn't seem to work. Obviosuly, I am sure there are some other constraints around just this general simplified model I presented, but how do you do decentralized governance. It isn't working well for Bitcoin. Interested to figure this out.
Telegram owns Whatsapp across the ceiling and down the walls in every aspect (only one I'm not sure about is security and for that one I don't know.) We already converted the inlaws (yep, big family) few months ago and it works like a charm.
An 50 year old electrician was the first to show me Ubuntu back in 2006 and he was enthusiastic about it.
So no, I don't buy it.
Of course many of them will never care, but that is because they don't care, not because there aren't alternatives.
Edit: saw employers mentioned. In that moment we are suddenly talking about professionals who just happens to be friends and family as well. In that case Photoshop might be a good solution.
Uh, you're not really in a position to say that.
> We already converted the inlaws (yep, big family) few months ago and it works like a charm.
You're totally ignoring the network effect. Nobody I know who uses WhatsApp uses it only to contact me. So now you've just introduced yet another messaging app they need to have installed and use to message me.
> An 50 year old electrician was the first to show me Ubuntu back in 2006 and he was enthusiastic about it.
So? I can't run Linux on my desktop because of some of the applications I need to run.
While I'm a huge proponent of open source, if you force it on people when it's not suitable you're going to encounter a massive backlash and turn them off it, undoing all the hard work that people are putting in.
Statements like this make the OSS community seem toxic.
With hypothetical closed source software in the abstract this might be a reasonable claim, but the software mentioned above includes a bunch of software which is known not to protect your privacy.
You can't seriously claim, for example, that Google employees don't have more access to your Google docs than you do.
Better technology (e.g. secure software, encryption) are part of the solution but this does not preclude the requirement of citizens and their associations (e.g. corporations) to maintain or restore accountability in government by whichever means are available.
More transparency can ONLY be positive, even if it's not perfect.
Transparency is only positive when it results in positive action. It can certainly be a negative when it doesn't.
With a piece of proprietary code, there is inherently a large difference between the public and private analysis of that software. And that private information can be leveraged by traditional power structures of money/government, eg source sharing programs with surveillance agencies.
With Free software [0], one can be reasonably confident that the public analysis and private analysis are much closer. Nefarious groups can still spend resources to increase their private advantage, but the public baseline starts off much higher. And if the bad actors do start to exploit something, the public already has much more information with which to go about figuring it out.
As another poster said, it's necessary but certainly not sufficient.
[0] "open source" ersatz seems sufficient for such analysis, but generally implies a lack of ability to recompile. So who the hell knows what the binary is actually made from.
Does it really? How many people are actually watching any particular piece of free/open source software, versus the number of programmers who might be paid to do so for the same as a proprietary project? The "public baseline" for free software includes all users, but only the subset of those who are competent enough programmers to be able to recognize issues, and who actually audit code and bring those issues to light, or have a PR accepted, or have the time to fork a project, even matter in this case.
I suspect politics and popularity affect the security of open source projects far more than the openness of the source code itself. While the potential is there once an issue is discovered for the community to come together around a solution in ways a dedicated staff might not be able to achieve, unpopular but mission critical projects may languish for years with only one or two people watching them because everyone is watching code that looks good on their resume.
The money from a closed project can buy professional auditors, but their utility is permanently capped by users not knowing if the company retains privileged backdoors. A user can only trust the software as much as they can trust that company. And as interest in the software rises, interest in subverting the company does as well.
Like always, centralization makes the small scale much easier but is fundamentally flawed when scaled up.
Free Software on general purpose computing hardware can't stop you from reading its storage with other software (i.e. with security features commented out) - that's kind of the point.
But to address your implicit point about UI - 64 bits of entropy is 6 diceware words, which seems eminently doable for your casual user wanting casual security. Phones are kept in possession more, and thus need a cold-unlock less frequently. And users are still free to compromise their security by using less entropy, just as they are currently regarding Apple (and likely by extension USG, as is currently being worked out).
Also tamper-resistant hardware isn't strictly incompatible with Free software. Imagine a security model that allowed loading of whatever software image, but wiped nonvolatile storage before doing so.
What should (and might) happen is Apple's model being amended to also require a code-signing key held by the user, encrypted with the rest of the phone. Apple could do this in its closed-source model, and Free Software wouldn't necessarily do that. Proper security design here really has nothing to do with whether the software is free.
Free software generally relies wholly on complexity theoretic security - so that it can be completely software based, as well as the author lacking any special privilege when the source is released. Computationally security necessitates a certain minimum amount of entropy.
For UI reasons, Apple would like to skimp on the required entropy, and thus employs additional non-complexity-based means of security. While this provides security for a casual user against a casual attacker, it unfortunately creates a juicy target for USG to fixate on, as in the current proceedings. It would have been more responsible for Apple to have designed their system so that low entropy passcodes were directly crackable by USG, rather than leaving themselves in a privileged position they can be compelled to use.
If you use a strong password on an iPhone than the attack the FBI is trying to pull wouldn't work either.
> If it's short enough that you're willing to type it every time you touch your phone, then it can probably be cracked very easily by cloning your flash storage and brute-forcing in parallel.
That doesn't work with a unique hardware key. Being clearer since you missed it the first time: the attack you describe does not work on the iPhone.
Nobody is proposing that FOSS is a security panacea: FOSS would still have to run on hardware with a hardware key to achieve similar password security. But if such FOSS existed, it could be more secure than the iPhone can be, because it would be immune to the attack that the FBI is attempting.
[0] http://arstechnica.com/security/2013/12/we-cannot-trust-inte...
With your logic, you might as well say that freedom of information laws are useless because nobody can review all of the government's documents by themselves. The point is not that anyone can review it all by themselves--it's just that it's more reasonable to trust things that the public can verify rather than unsubstantiated claims by someone who has an interest in keeping things secret.
I however think we should instead focus on creating good enough encrypted communication for email, chat... for two reasons.
1. It'll make things a little bit more expensive for the "watchers."
2. It will create noise. I.e. right now, if one person is using encrypted communication, he automatically becomes a target. With everyone using some level of encryption...
3. It'll serve as an intro to security. The same app that provides base level encryption can give TIPS on how to become even more secure. Think Windows "Tip of the day."
There's no perfect security. An insecure world-wide, easy-to-setup encrypted communication is better than nothing. Because, it'll at least make people more security/privacy conscious.
What exactly do you propose? We already have large swaths of insecure encryption, for example opportunistic TLS [1], and the "export" crypto leftover from the 1990s.
Designing some sort of mediocre encryption system that's both "good enough" to defend against typical criminals and simultaneously only "a little bit more expensive" for the well funded nation states seems like a poor use of expertise. Also it will have a shelf life: attacks only get better.