TikTok, Trump, and the Future of Open Source Surveillance
fossa.com
fossa.com
[1] https://www.phoronix.com/scan.php?page=news_item&px=Linux-Ke...
Compare this to something like, for example, TikTok, where the code is completely closed. The only kind of auditing one may do is looking at network traffic, and maybe some disassembly/hex-editing.
I'm not saying that everything needs to be OSS but it is nice to have options.
If you don't have code you can't audit code!
Tiktok is far smaller, and has a smaller attack surface. If there was money in it, people would audit Tiktok all day.
US government definitely trusts US companies more that Chinese companies.
I don't find it unreasonable to want to ban TikTok. Seems like the national security's risk is real.
The frustration is that for years, privacy advocates have been trying to find the right set of words to make people understand that it is bad for US companies have so much data on so many Americans. The argument is always dismissed as not being an important issue, or that it's good for rooting out terrorists or pedophiles. But privacy advocates have also been saying this whole time, "what if this data falls into the wrong hands" on deaf ears.
In an ideal world we would ban TikTok but also regulate how user data is obtained, stored, and used by US companies.
You can issue warrants warrants for your own jurisdiction, within your own country. Once data crosses country borders, it's much harder to get access to. The US (understandably) wants this data within their own country. Similarly, China also wants this data within their own country.
So having the data in the hands of US companies - problem,
having the data in hands of Chinese companies - maybe less of a problem,
having the data in hands of Chinese companies when Chinese government doesn't like me for any reason - really big problem,
having the data in hands of US companies when American government doesn't like me - approximately as big a problem as before (depending on what reason US doesn't like me)
on edit: formatting
I can't imagine why you don't think that when the CCP actively pursues Chinese activists and Uighur Muslims, including Chinese-Americans with ties (like family) to the mainland. Or maybe those people just aren't anyone you care about.
>vaguely implying that criticism of your hypothetical scenario comes from indignant moralists.
No, just your criticism so far. I'm sure there are other criticisms people might make but I read yours as an accusation of being morally bad for not hitting the notes you want hit, as if by not hitting those notes in this comment I cannot ever do so in another one should I feel the timing is right.
I guess you also feel you were making a comment on my immorality because otherwise you would have said something like "you've misread my comment, perhaps don't be so quick to aggravation"
My last sentence "Or maybe those people just aren't anyone you care about" isn't necessarily some kind of veiled insult, it's a real position that some people hold and one that I offered as an option. There was actually a reply to my comment (it's currently flagged so you may not be able to see it) that implied China's actions are justified because Falun Gong is a separatist group. This kind of reasoning is not uncommon in Chinese nationals, among others.
So that said, sorry for taking offense. I guess I am on edge recently.
- US companies have data. Law requires that government must ask or hack to get that data.
- Chinese companies freely share data and government has unfettered access.
There's a fine line and I have 3 points to make.
1) In one companies can say "no." In the second, companies can't. The ability to say no is important because as consumer opinion is changing we've seen more companies exercise that power.
2) More data is more power. In the first model data is distributed, in the second model it is aggregated (this is why I'd also never install a WeChat like app even if it came from Facebook).
3) There's a big difference, as an American, if my data is held by another country or not. American politicians and companies have to care about my voice (even if not much) because I elect them and can sue them. I cannot influence CCP politics, laws, or trade agreements. So at least if the data is in an enemy's hands locally I have some chance of doing something about it.
One of the key points here is that disliking one doesn't equate to liking another. Disliking Chinese companies does not mean I like that US companies have it. Disliking that US companies have that data doesn't mean that there's no difference in China (enough of the 五毛党 talk). Nuance exits. Good and bad are not discrete values but a continuous spectrum. I'll fight to stop both, but fight harder to prevent the one I have less autonomy over.
Growing up in the US, I’m 36, we used to celebrate how we didn’t do un-democratic things like the CCP. Now, we seem to use them as an excuse to justify un-democratic actions.
https://www.cnn.com/2020/07/10/politics/dnc-warning-tiktok/i...
The House voted a 336-71 to bar usage on government-issued devices
https://www.politico.com/news/2020/07/20/house-tiktok-federa...
Seems to me there's strong, bipartisan backing.
The government, in the meantime, sets a dangerous precedent, by blocking a foreign social app. It gives a great justification for other countries to block American social apps for similar reasons.
That's up to them; when it comes to PRC at least, banning American social media is the norm.
Now the US are forcing to sell or blocked every single non-american company whom already complied to all their law and rules, truly the first country in history doing this.
I don't much care who contributes to an open source project. Let them inject their malware if they want to. Because it is OPEN source such efforts will be discovered and the bad actors brought to task. And F/OSS principals extend beyond the code. Because it is open, any user is free to walk away from suspect code. Fork the project. Create your own code. Use the version created by someone you do trust. If I suspect that the particular flavor of linux on my desktop has been infiltrated by bad actors, absolutely nothing is stopping me from switching to any of a hundred other distros. That freedom is the real power, the real safeguard against wrongdoers, not vetting who or who isn't allowed to contribute.
as the article points out this isn't realistic because nobody actually has the resources or time to audit every piece of software this rigorously, let alone read or understand the entire codebase. A ton of open-source code is maintained by one or two or at best a handful of people and we'd be none the wiser if they'd put malicious code into the software until its to late, and as the article points out the permissiveness of open-source software makes it impossible to know for sure who contributed, after all the point of open-source is to let everyone contribute.
So as a system of trust open-source is no solution. The economics of it make it impossible to audit every bit of code, and the code could come from anywhere regardless even of what a Github profile says.
(1) This issue isn't going away, no matter who wins the next election.
(2) Data collection is not the only goal or threat. The article mentions other critical systems: energy, financial, healthcare, transportation, military. Even agriculture is heavily software dependent now[1]. Also, once you depend on a cloud service, the open source used by it is brought into the attack surface.
(3) Open source is theoretically reviewable, which is good. But even if resources were brought to bear to review it at scale, you'd need to do it continually and track what has passed. This brings pressure to fork. Worse, because review is imperfect even with the best people and tools, it will never be enough by itself to establish that a system doesn't contain malicious code. Current program verification technology is simply not up to the task of formally verifying the behavior of large scale software systems. Maybe it could be used for smaller libraries.
[1]: https://www.deere.com/en/technology-products/precision-ag-te...
The track record of popular free software projects like for example Linux in preventing malicious code is very good as far as I know.
Id say its something else entirely. Zucc needed a foil to get the president trained on something other than his own platform which, until the convenience of TikTok, was looking at serious legislative curtail. Knowing our president has the attention span of a jack russel terrier made it all the easier to torpedo what is arguably his biggest competition for Gen Z and younger, the lifeblood of his platform and what his advertisers arguably want the lions share of.