Seriously though - the software itself would be separated from secrets architecturally. And because it's open and anyone in the world can contribute it could be superior code than what some private government tech contractor could come up with.
For the equipment use case like jets and missiles, a separate directive component (driver) would likely be necessary anyway, not just for security/privacy but because different nations have different equipment. We use F-16s, M-16s, Autel drones, etc.
This driver/directive component would be the manufacturer's IP - like an nvidia GPU driver. Think of it like we'd all be running/contributing the same OS but because we have different hardware and security needs there are still some private components.
The idea/goal here is that our defense companies would overall benefit from it. Not just because the software is improved, but you can justify funding, build curricula around it - might benefit the defense industry to modernize their tech practices.
If you put all the design up for nuclear weapons but just kept the nuclear codes secret it's great that no one can fire ours, but people could implement the design on their own with different codes.
To use a more realistic example, consider air defence missile systems use to shoot down incoming missiles and drones. The secrets here aren't keys, it's software-driven behaviours including the approach to identify radar tracks as hostile or noise, identify when to commit a missile and how to target it, the code implicitly contains the vulnerabilities where the radar tracking is less effective and more evadable and how the system tries to mitigate this, etc.
When you take away all the secret behaviours, you quickly end up with not much more than just the drivers connecting the hardware to the logic, which isn't a lot of code that's driving the funding. How you set a missile tubes tilt and direction is trivial stuff and is mostly reused from old platforms that were funded decades ago.
Additionally, there is some talk about how this is kind of like security through obscurity. When it comes to things like weapons and other high-tech capabilities, security isn't only security against being owned, it's security against your opponent closing the technological gap. Unfair wars, where you have a significant tech lead on your opponent, means your population bleeds less.
Decreasingly the case, and we might be at the point I can say "poorly architected" if that's the case. A random 19 year old developer in the military with access to the secrets would be a big security hole too.
That's what we should be comparing with regards to open-source vs not open-source - in either case access to weaponry would of course be heavily gated.
Some of the other arguments you make here are no different than conventional arguments against open-source:
> the real code would still be private
Precisely the point, get the crowd to optimize the low-risk parts, build communities around those libraries and frameworks and recruit from it
> opponents might catch up
To remain an industry leader it's actually better to get everyone playing your game rather than trying to compete and stay ahead in a wild west scenario. You want to capture it really, so you can control it and be the leader in it. Open-source is one great way to do that (browser vendors come to mind).
>19 year old developer with access would be a big security hole
It's true, they are. That's why militaries and defence companies go to great lengths to vet their staff and why even within vetted staff, sensitive material is compartmentalised to minimise the risk from any given individual. Even despite that, military secrets are still leaked on an all too regular basis.
What a joke, no they don't. They establish security internally by gating access, not trusting everyone because they've been "pre-vetted".
I'm not saying that just because you have some kind of clearance you will get access to everything, but it's part of the preconditions to your own relevant access.
A very secure codebase is designed in a way that all the sensitive parts are separated from the parts general users (and developers) have access to - it shouldn't be all imbued together such that sensitive parts about missiles are exposed to login APIs etc. as it seems like you were saying.
It may even be lower risk than not to open-source as the public is more likely to find and fix actual security quirks that a private contractor might miss (or could even be paid as a spy to purposely leave vulnerable).
There's also the community/recruitment aspect. AI/LLM companies are cleverly open-sourcing major parts of their work while keeping the only important part that makes them valuable private - it's a win:win as they keep their secrets yet provide for and stimulate a developer community.
From where I sit, I find it absurd that everything we use isn't open source. Again, not free, but the code given to purchasers.
You don't need closed source to protect IP, and the proof is in all of these API lawsuits, and copyright law.
I don't want my missiles to not have code I cannot edit, and stepping back from the top secret sphere, tangential I am appalled at how crappy car firmwares are closed source.
In the old days, a country's national transport agencies could look at evey linkage, every rod, every part of a car design.
Now 90% of the design is hidden. And with electric cars, it's even more firmware.
And the idea that OTA updates are a thing for cars. The madness. The absolute madness.
How much do you want to bet that charging firmwares are remotely updatable?
Now imagine that 9am on Monday, every electric car explodes?
Even today, that would mean an immense number of houses on fire. How could the fire department handle it?
And how could it be handled as the fires spread? And what if lots of other infra goes up?
And that's today. What about when 90% of transportationn is electric? Even if not a single house or building burned, or person was hurt, how would you replace all those buses, trucks, delivery vehicles, and cars? As COVID showed us, you cannot ramp up and down overnight.
And what if it happened to all our allies? Would they still sell part to us?
What of all the tractors are electric, and we miss corn and wheat planting season?
My point in this tangent is... no one is even looking at the important bits. And to reiterate, how much do you want to bet charging firmwares are remotely updated? Really, they should be air gapped from the entire rest of the car.
Letting potential hackers have access in this way, is just plain lazy and reckless.
> I don't want my missiles to not have code I cannot edit, and stepping back from the top secret sphere, tangential I am appalled at how crappy car firmwares are closed source.
I read that as that whoever's missiles they are should have full visibility and control of their code; I am assuming that "my missiles" means the government, not that the poster personally owns missiles.
Access does not mean open source. Open source = OSI and what I think GP meant. And I hold the sentiment that government funded development should be open source.
For government work, I care about OSI, not if people can just see and not legally change, contribute, and redistribute.
I think government should fund global goods and want to be precise in my language. So when I say “open source” I specifically mean OSI-licensed stuff.
No matter. One entity doesn't get to unilaterally redefine a century old term. You claim you want precision, well then specify OSI, a subset of open source.
(And yes, the licenses it approves are indeed a subset.)
Using precise language is useful for building software (and in general life).
I like that OSI exists and helps people understand a specific and desired definition for open source.
There’s a lot of thought on this topic by really smart and skilled people. The aspects of open source that I think are most important are captured in OSI.
For me, I don’t care if I can see the source, if it’s not free and usable. I can decompile code and patch for myself without a license. And I can pay for code in escrow.
But what’s important is that I can modify and redistribute. And that I can be part of a virtuous community creating things together.
I think Linux is as or more secure than windows and it’s open source. There’s tons of sensitive systems that are open source.
It’s a design fallacy that security through obscurity is good.
I like free software a lot, and do not know much about weapon development, but would not the software reveal a lot about capabilities of the weapon platform? The argument to keep the software private might not be motivated just by attempt to hide security holes, but also by desire to hide what the weapon can do, what are the operational limits, etc.
Yet, still obscurity increases security.
Reverse engineering is not trivial and raises the bar.
I disagree and think obscurity decreases security. It just gives the false belief of security.
The point is simple - obscurity as an addition increases security.
Reverse engineering is not trivial and raises the bar.
Edit. Oh, your link supports that
>The obvious disadvantage of this approach is that it doesn't prevent the bugs from being exploited - it only make the meaningful exploitation very hard or even impossible. But if one is concerned also about e.g. DoS attacks, then Security by Obscurity will not prevent them in most cases. The other problem with obfuscating the code is the performance (compiler cannot optimize the code for speed) and maintenance (if we got a crash dump on an "obfuscated" Windows box, we couldn't count on help from the technical support). Finally there is a problem of proving that the whole scheme is correct and that our obfuscator (or e.g. ASLR engine) doesn't introduce bugs to the generated code and that we will not get random crashes later (that we would be most likely unable to debug, as the code will be obfuscated).
They likely already do. Between exploiting remote vulnerabilites (a nation-state intrusion will never even be noticed -- they aren't going to encrypt all the files and ask for ransom) and old-fashioned spycraft, it would be really amazing if all the contractors involved on those projects had perfect security.
As we saw with 702, we really have very little leverage left in what our gov does anymore, the threat of being voted out even carries little power, exactly because they're systematically removing humans from every loop they can for the purpose of working unilaterally even when--perhaps especially when--it's against the will of the people. The spooks themselves have literally said exactly as much in their fight against privacy.
To me, the latest 702 is more terrifying than any adversary. When we, who the government should be beholden to, cannot even know the text of the laws which apply to us, it really puts a fine point on how the those who run our government view themselves in relation to its citizenry.
"The liberties of people never were, nor ever will be, secure, when the transactions of their rulers may be concealed from them." -Patrick Henry
Not that it matters, the state still doesn't care. It can't, it's not that kind of being.
I think it's a pretty obvious ipso facto that the more, and more advanced weapons, that are placed into the global battlefield, the less actual security (in life and liberty) we can expect.
The problem isn't that there are adversaries that are willing to sacrifice their people, almost every war is one of attrition after all, it's that leaders that would be adversaries like this are inevitable in a governmental structure that is delegated a monopoly on violence.
- Stuxnet (developed to attack PLCs which control nuclear centrifuges)
- Petya (targeted Microsoft developed systems and software and brought governments and states to their knees. Notably Ukraine)
and an aside note do you really want the national defense to be one thumb drive away from total collapse?
the reality is that this military industrial complex is just a way to print money and funnel it into the hands of a few criminals. all of the major news publications openly told you that the USA has been attacked over 100 times in the middle east AND WE LEFT. The public is going to find out very soon that this massive, expensive military can't actually defend against or defeat other militaries. That when you spend $1000 on a hammer everything looks really flashy and impressive AT FIRST with your fancy jets and missile systems, but after enough time, and after enough of the money has been funneled out, you realize it's a paper army. the USA is so weak that Iran is pushing them out of the middle east and there's nothing the theives that run the military can do about it. but don't worry. they already manufactured a Palestine sympathy story ahead of time to explain why they have to pull out and run away like the cowards they are. and your son's and neighbors sons will pay the price with their lives
Quality verification depends on auditing and auditing depends on competent, trusted review and testing. Global transparency is not a substitute for auditing except when discussing absolute rock-bottom standards. Reviewable is significantly better than unreviewed and unreviewable, but that is the lowest possible bar. Unfortunately, software does, as a general rule, have rock-bottom auditing standards, so FOSS does provide meaningful assurance increases in many use cases. But, that is a artifact of the abysmal quality standards rather than any sort of inherent auditing advantage that FOSS provides. That is not to say that global transparency is not valuable for other reasons, but it provides no meaningful quality verification or auditing advantage in serious applications versus local transparency (to the trusted reviewer).
If you want to see how this works in practice, look at literally every other industry.
Thankfully governments are now also funding FOSS work but this really doesn't align with what you're envisioning, I think.