Brazilian government to ditch Microsoft in favour of bespoke email system
zdnet.com
zdnet.com
"It will probably cost more in the long run." "The NSA will just crack it and spy anyway."
So many people with the attitude that countries that find out their tech partners are actually performing espionage on behalf of the US government (and US security partners) should just tolerate it rather than do something about it.
Disclaimer: I work at Microsoft, so eh.
The tech industries reaction to the Snowden seems to the outside very lukewarm. Sure, they are giving all sorts of "trust us" statements, but truth is we don't have the slightest clue if this is their honest opinion or just an opinion that a secret court forces them to uphold. Reality might be much more nuanced, but to the outside there is very little reason to give anyone any longer the benefit of the doubt.
I was a bit amused to read that "The Expresso platform will also be used as the base of the Hotmail-like system that the government is also planning to offer to citizens." Are Brazil's citizens that trusting of its government? I certainly can't imagine Americans trusting their email to the government even before Snowden-gate.
I mean to say this appears to be primarily a political reaction with nice governmental side-benefits.
Migrating the government to Linux and using a free mail infrastructure would be cheaper (saving money in the long term, instead of costing), easier, and way more effective than using a non-standard internal email protocol and keep using Windows everywhere. Why bother when Microsoft still has access to all your data?
About using that proprietary protocol AND migrating to a free software environment, that could be better than just migrating, or worse, depends of the actual quality* of the protocol. But while the government frames it as a XOR option, migrating to an open stack is the only sane option.
* The fact that the protocol isn't public isn't good, the fact that it's Serpro creating it makes this worse - they've already done quite a few bad decisions about security.
And from a security perspective (sorry linux fanbois and microsft haters) the choice of MTA/MUA isn't as important as the rest of the security.
Would be interesting if due to this that OSI and X.400 makes a comeback for more secure email - though presumably with all the security enhancement proposed for the later standards - hmm I wonder if you could use quantum networking with x.400/500
If I were a spy agency and an open source project was being spun up that several countries would use, I'd get at least a dozen devs on it. And if I'm thinking that, then you know they all must be...
How hard is it to write an email client?
With some calendar?
Is it complete rocket surgery or something in the realms of feasibly possible?
Wasn't gmail some 20%-er time by a couple of guys at Google? I don't think it took years or billions to get up and running.
I think you could have a tidy and secure webmail built by half a dozen people randomly chosen from Hacker News in six months. Sure it might not be as all singing and dancing as the oh-so-wonderful Microsoft Outlook but then again it might actually be better for the task in hand - facilitating communication for a government. Sometimes people have got to try rather than be all helpless. I am all for software re-use, open source and everything else deemed good software engineering, but, for a government wanting to keep their communications private some consideration has to be given to 'how hard can it be to write an email client?'
I'd also daresay that GMail is only possible thanks to Google infrastructure - which was not built over 20% time.
I suspect that Brazil's home grown mail system is also going to be a buggy, low-quality mess at a cost of tens of millions of dollars.
> With some calendar?
> Is it complete rocket surgery or something in the realms of feasibly possible?
Oh dearie. Thus began every single failed multi-million-dollar software project in the history of software.
> Wasn't gmail some 20%-er time by a couple of guys at Google? I don't think it took years or billions to get up and running.
A: The feature-set of GMail as is released in 2004 is unlikely to impress someone used to Outlook/Exchange
B: What a correctly motivated Google-quality engineer can cook up in a few years (which is apparently how long GMail was in development before release) has little to no correlation to what a government can procure from a systems integrator. Also, I don't recall the calendar being worth much back them. Maybe, maybe, maybe if they hired Google-grade engineers, paid them Google salaries and gave them Google-freedom to work on this, they might be able to pull it off. But that's a lot harder than it sounds.
EDIT:
> do something on its own about securing government communications
It's not hard to secure an email installation - its interface to the internet at large is super small and well understood (SMTP). Most likely NSA grabs the mail they want from outside the installation by sniffing unencrypted network traffic.
A worthwhile effort, and one quite suitable for a government even, is to get people to encrypt their emails.
There's really nothing complex or fancy in developing a bare bones secure email system. And keep in mind these poor souls are using Lotus Notes (!), so it can't get much worse than that.
Also, it's not that it has to be built entirely from scratch. They will likely re-use existing ideas from other systems, and even (licenses permitting) other open source solutions as a starting point.
All in all, I wish we had more governments stepping up against this whole US spying mess. The real long term solution is not to have each government developing their own proprietary email systems, but for the US to be more transparent and stop the illegal spying.
Sadly, this will have to get worse before it gets better. We'll probably watch a few years of increasing distrust and strained relationships, before governments start to come to terms with the US again.
If that was really the case then the U.S. government (which has effectively 2 separate air forces which are each 10x bigger than any other nation's) should be kicking ass at delivering IT projects of all sorts.
If they are writing a brand new clean room new mail standard (plus all the ancillary bits directory non repudiation key handling the whole nine yards) - it will be amusing to watch the CF that results.
Not much, but unnecessary. There are open-source solutions that can be security audited, fortified and improved.
> With some calendar?
Devilishly hard.
It probably won't do much for security though. If anything, vulnerabilities will be more likely. The only thing they've got for it is securing the physical comms. But even if the US (or any other superpower) doesn't compromise them, there are other ways of extracting the data.
And this being SERPRO, they'll likely use cutting edge technologies such as MD5 and DES.
Hey, PBKDF1 uses md5. That only puts them a handful of years behind.
As others have mentioned, PIM is very difficult and if it's done wrong, you end up with metadata leaking across the Internet, security flaws, etc.
If the real issue is with the inability to see the source then open source is better than "Brazilian government"-proprietary, as the NSA could simply hack the source code repository, CIA could plant an insider, the list goes on. You could have someone whose job is to audit the integrity of the archive, but who watches the watchers? With open source the problem is simpler: everyone can watch the source code archive.
Article about SERPRO launching their cloud platform. http://www.zdnet.com/brazilian-government-launches-own-cloud...
Some random info about the Healthcare.gov devs: http://www.washingtonpost.com/blogs/wonkblog/wp/2013/10/09/h...
At one side we have incredibly well done and well managed examples, as our elections voting system. I get embarassed for US everytime I see the news about your elections, with cards and weird stuff.
On the other hand, we have lots of examples of how the government can mess things up, most notably these days are the stadiums and overall infrastructure for World Cup. It is even worse than any pessimist would have predicted.
So... all we can do is wait. The initiative, I think is good, but the outcome.. who knows?
Who would do an audit?
Because the obvious candidate is Serpro, but they are already developing it. Anyway, it's open source, so if any part of the government (military maybe, ABIN, or some university) thinks that it deserves an audit, it can simply do it, no need for formalization.