FSF responds to Microsoft's privacy and encryption announcement
fsf.org
fsf.org
I also can't agree that it isn't related. If I tell you I'm wearing a green shirt, how can you know for sure if you or someone you trust hasn't verified it? You can't. It's the same with MSFT. But in the case of MSFT, it has been proven that they wear a lot of Hypercolor[1] stuff.
Is it good that MSFT is doing stuff to make things more secure? Sure. Do we still have to take it on faith that they are doing everything they can to protect their users? Yup.
I work in a small programming company and we do internal and external audits while maintaining compliancy with federal and state regulators as well as groups like ISO.
Sure, our work is closed source, but that doesn't automatically mean it hasn't been externally verified for a number of different things by a number of different organizations...
Yes, but we have to take your word for it.
Sure, it looks like its not leaking air. It has not dropped down to earth yet, and all the videos posted on their website looks to show it being fine. However, if I ever went there and depended on its security, I would demand more.
Whereas if the source is open, and you are a subject matter expert (yes, that's a big if), you can review the source yourself. You can decide for yourself whether the software has an NSA backdoor, an innocent flaw or whatever.
Yes, a lot of people, myself included, don't have the technical background to do this. But with open source we could, if we had the knowledge (which can be learned), without relying on potentially compromised authorities.
With closed source we simply can't. We have to trust the auditors and the government, which have been shown to be unreliable.
How many open source projects have most people audited for their own sense of satisfaction about its security promises?
Debian SSL bug lasted 2 years. Open source means little for security.
The argument I'm making is not that Windows is secure (because it isn't), but that Open Source isn't necessarily secure just because it's open source.
Open source is however possible to independent verify if it is secure. Closed source is not possible to verify as secure and must be taken solely on the word of the company who made it.
How many examples can you come up with? Was this specific bug being actively exploited when it was discovered?
A bug caused by prettying the code, which was secure from upstream, which is in an important, widely used, supposedly secure bit of code isn't a good enough example?
> Was this specific bug being actively exploited when it was discovered?
Many Linuxes used to ship with lots of services running. That lead to many rooted boxes being used to deliver spam. Open Source fixed the problem, but only after many millions of emails had been delivered.
Someone somewhere probably has a nice chart of all the Red Hat boxes in SKorea in the late 1990s early 2000s.
Again, this isn't to suggest that MS or Apple are more secure. For years anyone putting an MS server onto the Internet ran the risk of very quick exploitation.
It's a good example. Can you come up with more? Because, you know, it's just one instance of a problem. It says nothing on how pervasive it is.
> For years anyone putting an MS server onto the Internet ran the risk of very quick exploitation.
IIRC, there was a time when the average time between install and first invasion was in the 40 seconds range.
I am not a fan of FSF's tone here, they could be more diplomatic -- but saying "we appreciate your effort, but you fail" would have been more insulting. I think there are many places for closed source software, but core privacy software is not one of those places.
The encryption core (the critical pieces that either input or output plain text -- the places where the attack is more likely to succeed as opposed to the core of the algorithms), as well and the general platform should have the source code available (even if at a fee). That's not quite the FSF vision, but perhaps the powerful vision is needed (one can think of FSF's goals as a captivating utopian story that leads to more incremental improvements).
Not everything has to be open source and not everyone has to choose open source. Microsoft/Apple/Google may never make their core products open but it doesn't mean they can't try to make it secure or privacy conscious. The beauty of freedom is that YOU get to choose and trust what you want, good or bad, open or closed.
As a developer, I find GPL to be against the "spirit of open source", but it would be extremely wrong for me to demand you license your code differently or to even suggest to your clients to choose a liberal license. Its yours and their choice not mine.
It's not about open source. It's about free software.
https://www.gnu.org/philosophy/open-source-misses-the-point....
Some of us care more about open source than free software.
More like Open Source is against the GPL, which is really the only reason the OSI came into existence.
>either you are with us or you are evil
Free software is about morality, not about getting or giving away free stuff. When you take a moral stand, you're necessarily making a moral judgement about people who don't.
Open source sells itself as a better way of doing business. Free software supports people's full ownership of their own devices even if it is worse for business.
"Transparency in the Windows world normally means self-reports commissioned by Microsoft, or access granted to outsiders covering very limited portions of source code under strict agreements that limit sharing that information."
Yup, John Sullivan really ignored that.
You can disagree with the FSF's mission, but they are certainly not spreading lies on purpose.
And I would listen to that argument, but you haven't made it.
Right, but A) I like to choose who I trust. Get a second opinion. Verify a few things myself, if I feel I'm up to the task. I get none of these options with Windows.
B) If you doubt, with all the eyes on Windows, that a backdoor would have persisted, why do you act as if more eyes is not better? Or, perhaps more importantly, a greater variety of eyes?
Microsoft gets to pick who studies their code, and may or may not prevent them from revealing vulnerabilities and bugs anyway. Popular open source projects may get actively hostile researchers studying their code specifically to shout any bugs they find from the rooftops. Or they may get the world's foremost expert in some aspect of their code to study it for fun. And nobody can stop them from revealing anything the find.
If MS giving a few hand-picked organizations their source code under strict terms, who may or may not be allowed to report what they find honestly, is good, why wouldn't fully open software be better?
Nobody is saying that giving governments and a few organizations a look at the Windows source isn't better than having it completely locked down. But it just doesn't go far enough.
You don't. That's why the source is open.
Just being able to see the code is no advantage, you still have to trust Microsoft to actually ship the same code they've shown you.
So Microsoft doesn't need to "give NSA a backdoor". They just need to tell them about certain bugs before they fix them - and that's just as bad as giving them backdoors, since NSA can and will use them as such.
[1] - http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t...
Surely real valuable attacks would be ones there's no planned security update for.
No, a security non-disclosure program. Disclosure is when you tell people. Telling a spy agency in no more "disclosure" than telling a Russian trojan dev.
No, they are not. It's fundamentally impossible to secure proprietary software because you have to trust its provider the software does what it says it does whereas with open-source you can always check for yourself. Any backdoor in open-source software is there to be exposed and corrected.
With proprietary software only one party can disclose vulnerabilities and in open-source anyone with the knowledge can do it. You can choose to trust a single party or choose to trust a myriad of different parties any one of which can blow the whistle if they find something fishy.
I find it highly unlikely a backdoor to a popular open-source application could remain there for long. I don't think it's unlikely at all with proprietary software where there is no incentive to fix a problem until someone outside the company learns about it.
True, but there is no way to prove it's secure. It's not about convincing myself or anyone else - it's about proof.
But maybe we can agree on the following. Closed source software can be secure but there is a broad spectrum of needs for convincing someone that a software is secure and this need may be better served with open source software in some circumstances. For some it is sufficient to trust a vendor. Some want to audit the source code (and this does not exclude closed source software). Some even need formal verification maybe even of the underlying hardware.
http://www.theregister.co.uk/2009/08/14/critical_linux_bug/
http://www.networkworld.com/community/blog/linux-finally-fix...
http://it.slashdot.org/story/11/06/20/2257229/13-year-old-pa...
You're trying to apply an impossible standard to closed source software that software that was that developed from the start to be open source and developed in the open cannot meet.
This is completely bogus. The owner of the master key may have the access (understandably undesirable), but that does not keep you from getting out. If anything, it's like having no lock at all.
> or access granted to outsiders covering very limited portions of source code under strict agreements that limit sharing that information
You are trusting the manufacturer's promises. Are they essentially meaningless just because the general public doesn't have insight into manufacturing details?
I hope the big tech companies are serious about protecting their users, even foreign users, since their business model depends on it.
1) They're giving no indication that they can't decrypt their customers data. This won't protect customers from the thousands of information requests that they're not allowed to publicly acknowledge, and will only hamper vectors such as MITM fibre splitting. This is concerning given the fact the US intelligence agencies share their data with private companies, and that Microsoft didn't even attempt resist previous requests. They have no incentive to inform customers and fight expensive legal battles, so as soon as the whole privacy thing blows over it will be back to old habits.
2) Allowing companies to review their source code is only useful for their desktop products. Most data is going into the cloud now, plus it's possible to use cross library exploits and obfuscated code. I don't actually think that they'll do this now, hover they've done it in the past with their famous NSAKEY in the 4.0 kernel.
Office 2008 with a firewall will keep your data safe. Office365 is a company risk. I wouldn't put anything more confidential than a CV or short story on it.