6 ms·
This is a bid to place Microsoft above reproach. They get to play the "we did everything in our power to protect privacy" card, while still remaining fully comp
by AC__ 11y ago
This is a bid to place Microsoft above reproach. They get to play the "we did everything in our power to protect privacy" card, while still remaining fully compliant with government back-door policies. Now the media runs with this, and eventually the mindless masses are lulled back to sleep while their rights and freedoms continue to be eroded.
- lazaroclapp 11y agoThere are a lot of tech companies that can argue that they are doing everything within their power to protect privacy from government actors (e.g. Apple, Yahoo, but not, say, Verizon[1]). It just so happens that "everything within their power" might be extremely little, if they are required to maintain their existing structure and comply with the letter of the law. At some point our options really become: relying on tech providers without presence in "unsafe" jurisdictions (if there are any), relying on tech providers willing to disobey the law (and ideally capable of convincing us they disobey them in our favor. Via: open-source, audits, etc) or pursuing reform of those laws. [1] https://www.eff.org/who-has-your-back-government-data-requests-2015 https://www.eff.org/who-has-your-back-government-data-reques...
- x5n1 11y agoHi everybody. Just your friendly neighborhood Linux nerd. Use Linux, it's open source.
- nickpsecurity 11y agoWhich gets you what against the NSA, BND, and mass collection? Nothing by itself. Solving these problems is a tad more difficult than merely using Linux. ;)
- x5n1 11y ago> Which gets you what against the NSA, BND, and mass collection? A step away. > Nothing by itself. Not so. > Solving these problems is a tad more difficult than merely using Linux. True. But it's swallowing the red pill, just something you have to swallow to know how deep the rabbit hole goes.
- nickpsecurity 11y ago"A step away" = still there. You're just being contrarian. "Not so." Prove it. Linux still shows your communications on plaintext online by default. They have zero days in popular apps and kernel for Linux. They have attacks below firmware if you get clever with OS security. So, no, using Linux by itself doesn't change anything for bulk collection as proven by the Snowden leaks. It can be an improvement over Windows for targeted collection but will still be hit in default state. And most people hearing "Use Linux" aren't qualified to get it anywhere near bulletproof. So, they'll be easy targets. Using any standard, mainstream system when nation-states are after you equals much higher chance of getting your box owned. It's just economics: they focus on attacks w/ highest ROI. Windows, Mac, and Linux kernels are highest ROI for desktop. People on an Amiga are probably less likely to get hacked by automated system despite inferior security just because of its obscurity and attackers' focus. It's why my old trick of BSD or UNIX on non-popular ISA's (eg Alpha) stopped so many attacks despite their apparent sophistication.
- AC__ 11y agoI love Ubuntu and haven't touched Windows in 2+ years, but I don't delude myself into believing that Ubuntu being Debian-based affords me protection against mass surveillance.
- Spivak 11y agoI guess it depends on the method of surveillance. If your data is being collected by any 3rd party then you might as well assume that any vague yet menacing government agency can access it since it's just a subpoena away. So all the tracking and analytics that MS/Apple/Google/Damn near every tech company put on their services is really the problem. The only method of securing your data is to make sure it never leaves your computer without your consent and using Linux is one of many possible things you can do to ensure that. Sure, if you're running Skype, Chrome, Steam, etc. on your Linux laptop then the benefit is pretty marginal but still technically better than if it was on Windows.
- mappu 11y ago- http://www.gnu.org/philosophy/open-source-misses-the-point.html http://www.gnu.org/philosophy/open-source-misses-the-point.h... - http://www.gnu.org/gnu/linux-and-gnu.html http://www.gnu.org/gnu/linux-and-gnu.html
- nickpsecurity 11y agoGNU and links like those consistently miss the point when the discussion is about security. OSS or FOSS don't matter as much as review by qualified, trusted party with trustworthy distribution. As explained here: https://www.schneier.com/blog/archives/2014/05/friday_squid_bl_424.html#c6051639 https://www.schneier.com/blog/archives/2014/05/friday_squid_... Might explained why a few closed source products achieved high assurance security (B3/A1/EAL6/EAL7) that survived years of NSA pentesting while FOSS... see Snowden leaks. You can get those freedoms with proprietary models via contracts, esp with non-profits. Most just are about money though. Likewise, FOSS communities rarely deliver high-quality, maintained software and never deliver highly assured software. So all this philosophical crap serves nobody if we're talking about making software trustworthy. For that, we need capable people building it while utilizing every security-enhancing method we know, trustworthy people reviewing it whether closed or open, ability to know you possess what was reviewed in that configuration, and continual maintenance esp of bugfixes. That's the baseline we need to push whether FOSS or a proprietary version of open-source.