17 ms·
Snowden: Privacy can't depend on corporations standing up to the government
- jeena 11y agoIf we all used free software, would that even be a problem?
- deleted 11y ago[deleted]
- DanielBMarkham 11y agoMaybe. Sure is a ton of software you'd need to both find and maintain. This may be one of those things that sound good but are unworkable.
- benevol 11y agoThis, it's so important for society. If we want real democracy, software needs to be open-source. Please everybody, never stop promoting open-source solutions to your friends & family.
- anu7df 11y agoOpen source hardly guarantees anything. Governments armed with everything under the sun can make the lives of privacy advocates a living hell. When I was younger (no kids) I could think of standing up against it if need be. Things have changed, almost irrationally, with a family. Irrational because I would hate for my baby to grow up into an Orwellian dystopia but the fear of immediate consequences to the family keeps me from action. The point I am trying to make, is that government will not need to crack down on every one. Just a few brave snowdenlikes, the rest will either believe the government narrative or be afraid to rise up against it. So yes, open source is great, but we absolutely need corporations to stand up to government. Because let's face it.. In our society cash is king and a corporation like Apple has the cash,visibility and might to wield a sword for privacy even if they are possibly motivated by something other than concern for individual's privacy.
- pdkl95 11y ago> Open source hardly guarantees anything. { obligatory recommendation to watch PHK's "Operation Orchestra"[1], which discusses ways free and open software projects can be manipulated } [1] https://archive.fosdem.org/2014/schedule/event/nsa_operation_orchestra/ https://archive.fosdem.org/2014/schedule/event/nsa_operation... > but we absolutely need corporations to stand up to government We need solidarity - the people and corporations - to stand up to problems in government. We also need the people and government to stand up to problems in corporations. Hoping that our social problems will be fixed by other people or some other group is a terrible defense strategy. There will always be people that try to control power or money; this requires constant vigilance and push-back from everybody; failure to do so creates more potentially exploitable attack surface. The technical people that actually implement modern society hold an incredible amount of power. Unfortunately, the people involved are easily distracted with off-topic minutia and vague threats.
- dragonwriter 11y agoCorporations and governments aren't actual concrete things, they are labels put on certain actions of people (and corporations, specifically, are just names for certain actions of people through government.) So "people and corporations" and "people and government" are both just people.
- pdkl95 11y agoThat's correct. I'm making the distinction because of the comment that we "need corporations".
- Absentinsomniac 11y agoThe distinction is important because people in government and people in corporations usually have different motives than people in general. (Particularly people in leadership roles within these org's)
- studentrob 11y agoAgreed open source is very important. Does anyone here think all software should be open source? I'm interested to debate someone about that. I can't see how that works unless the whole world stops using money.
- CM30 11y agoWell, the WordPress scene tends to make most of their software open source, including the stuff they charge for. For example, every official WooCommerce plugin is under the GPL, as is Gravity Forms and Easy Digital Downloads. These are also paid plugins. What this means is that once you download them, you can theoretically use them on as many sites as you like, release edited versions yourself or use them for as long as you need to. What they charge for is basically the following: 1. Updates, since otherwise you have to find and install any updates outside the WordPress dashboard. 2. Support from their support team That's how the WordPress scene in general works for paid products. The products themselves can be used however you like, but a paid license gives you access to support and much improved ease of use as far as updates and things are concerned. So you can make money from open source software, and it would theoretically be possible to have all software as open source.
- schoen 11y ago> I can't see how that works unless the whole world stops using money. I think Richard Stallman addressed your concern in the GNU Manifesto back in 1985. (I don't mean to suggest that his answers will necessarily convince you, just that the issue has been discussed explicitly for that long.)
- schoen 11y agoFor subsequent thinking, there is a Wikipedia article: https://en.wikipedia.org/wiki/Business_models_for_open-source_software https://en.wikipedia.org/wiki/Business_models_for_open-sourc...
- dllthomas 11y ago> I can't see how that works unless the whole world stops using money. I'm hoping Snowdrift.coop makes it viable.
- Veratyr 11y agoI can't start promoting open source solutions to my friends and family because for most of their tasks, open source solutions aren't adequate. Some examples (taken from my wife): - Art: Photoshop, Illustrator and Corel Painter are required by employers and educational institutions. GIMP/Inkscape etc. don't have feature parity so often can't be adopted. - Messaging: Friends and family use Skype and Whatsapp. Network is too large to convert to an OSS alternative. No OSS alternatives are sufficiently developed to be viable regardless (Signal lacks a desktop/web (not Chrome) client, XMPP, Tox have no decent mobile story, Matrix clients are hard to sell). - Browsing: Chrome's built in translation doesn't seem to have a viable alternative in other browsers like Firefox. Chromium lacks auto-update which is dangerous. - Documents: There isn't any open source alternative I'm aware of to Google Docs that is nearly as convenient or easy to use. - OS: Linux/BSD can't run the software needed for work/study so they're a no go. It's easy to think in our little tech bubble that OSS is wonderful and we should be screaming from the rooftops to get people to use it but I just don't think it's ready yet. I can't even get my wife onto one OSS application and the same goes for most of the people I know.
- jeena 11y agoIt sounds like the problem is that they value convenience more than freedom. That is their choice and the only thing you can do is to explain that to them and to choose differently yourself.
- CamperBob2 11y agoNo, that isn't the problem at all. When you understand why, you'll be better-equipped to work towards real solutions.
- jeena 11y agoBut you don't want to teach me what the real problem is quite yet?
- CamperBob2 11y ago
- rimantas 11y agoDon't tell me what to do and I won't tell you where to go. Democracy has nothing to do with open-source software and I will recommend the best tool for the job, open or closed source, thank you very much. OTOH maybe fewer peopel thinking that they have it all figured out and know the best what is good for society would be indeed good for democracy.
- tdkl 11y agoWell in a democracy, people can use whatever they like the most, but usually "open-source" goes hand in hand with "pain in the ass" and "doesn't have the user base".
- chishaku 11y agoYes. There's no silver bullet for protecting and preserving rights. Better technology (e.g. secure software, encryption) are part of the solution but this does not preclude the requirement of citizens and their associations (e.g. corporations) to maintain or restore accountability in government by whichever means are available.
- krapp 11y agoYes. Ironically, one the features that makes free software insecure is the religious belief that only proprietary software is insecure.
- ekianjo 11y agoWell for proprietary software there is no way to prove it's secure. It's security by obscurity, which is hardly a good thing. More transparency can ONLY be positive, even if it's not perfect.
- krapp 11y agoThat's not entirely true - there's no way for the general public to prove proprietary code is secure, but the people who wrote the software know. But the general public isn't competent enough to validate most open source code anyway, so in either case most users simply blindly trust that whatever they run is "safe." Transparency is only positive when it results in positive action. It can certainly be a negative when it doesn't.
- mindslight 11y agoIt's not really about "proving" something secure, but about leveling the playing field. With a piece of proprietary code, there is inherently a large difference between the public and private analysis of that software. And that private information can be leveraged by traditional power structures of money/government, eg source sharing programs with surveillance agencies. With Free software [0], one can be reasonably confident that the public analysis and private analysis are much closer. Nefarious groups can still spend resources to increase their private advantage, but the public baseline starts off much higher. And if the bad actors do start to exploit something, the public already has much more information with which to go about figuring it out. As another poster said, it's necessary but certainly not sufficient. [0] "open source" ersatz seems sufficient for such analysis, but generally implies a lack of ability to recompile. So who the hell knows what the binary is actually made from.
- 11y ago
- ta0967 11y agofree software is necessary but not sufficient.
- jeena 11y agoI guess I have to agree with that.
- deleted 11y ago[deleted]
- superuser2 11y agoYes. The FBI wants to run arbitrary code on a device it legally owns. Were the iPhone consistent with Free Software principles, that would be trivial. It is only because Apple built the walls of the walled garden so high (specifically implementing code signing enforcement in hardware) that this is so difficult for the FBI. Free Software on general purpose computing hardware can't stop you from reading its storage with other software (i.e. with security features commented out) - that's kind of the point.
- mindslight 11y agoSure, but the design constraints change along with. If the iPhone were Free, its security would have been designed to withstand any code changes, ala LUKS.
- superuser2 11y agoMost people don't boot their computers very frequently, and when they do they have a full-sized keyboard at their disposal.
- mindslight 11y agoThat's orthogonal to what I said. But to address your implicit point about UI - 64 bits of entropy is 6 diceware words, which seems eminently doable for your casual user wanting casual security. Phones are kept in possession more, and thus need a cold-unlock less frequently. And users are still free to compromise their security by using less entropy, just as they are currently regarding Apple (and likely by extension USG, as is currently being worked out). Also tamper-resistant hardware isn't strictly incompatible with Free software. Imagine a security model that allowed loading of whatever software image, but wiped nonvolatile storage before doing so.
- superuser2 11y agoPeople were annoyed enough by 4 digits that Touch ID was a major selling point. 6 words isn't gonna happen. But you already can use such a password with an iPhone, and if you do, the attack the FBI is attempting won't work. Software freedom doesn't enter into it. What should (and might) happen is Apple's model being amended to also require a code-signing key held by the user, encrypted with the rest of the phone. Apple could do this in its closed-source model, and Free Software wouldn't necessarily do that. Proper security design here really has nothing to do with whether the software is free.
- AdeptusAquinas 11y agoLike OpenSSL?
- jeena 11y agoFor example, there we were able to find the bug and to fix it. This is not possible with closed source software.
- rimantas 11y agoYou'd be amazed how many bugs are found and being fixed for closed source software. Especially when people are paid to do it.
- jeena 11y agoI guess the main difference is that we can only pray that a bug will be fixed in closed source software. In free software we have at least the possibility to do it ourselves.
- AdeptusAquinas 11y agoTwo years after the fact, in OpenSSLs case, after it became almost universally adopted.
- jasonjei 11y agoHardware could still make users vulnerable. Intel, I think, was involved in controversy relating to backdoors and encryption [0]. [0] http://arstechnica.com/security/2013/12/we-cannot-trust-intel-and-vias-chip-based-crypto-freebsd-developers-say/ http://arstechnica.com/security/2013/12/we-cannot-trust-inte...
- benevol 11y agoYes, open-source hardware would be the next step.
- rimantas 11y agoYes, because free software does not mean a shit. Unless you hand assemble your devices, compiler, verify every line of code before compiling it and only then install it.
- rimantas 11y agoYep, as Android being the paragon of security clearly shows us.
- awinter-py 11y agoNo surprise that security updates are the center of this conversation. Software patching is a source of vulnerabilities turned off (exploitation from fixed bugs) and turned on (update provider can be malicious). When heartbleed broke that was evidence that the 'many eyes' theory of secure open source software hadn't worked. Alternatively, the bug was found because big corporations with security budgets were getting serious about holes, so maybe 'many eyes' is starting to be true. Certainly apple's 'goto fail' and RSA's key strength bribery are examples of 'not enough eyes' for closed software.
- Grishnakh 11y ago>When heartbleed broke that was evidence that the 'many eyes' theory of secure open source software hadn't worked. Alternatively, the bug was found because big corporations with security budgets were getting serious about holes, so maybe 'many eyes' is starting to be true. Heartbleed proved that just having software be open-source is not sufficient. Having the source available to audit isn't all the helpful if no one bothers to do the work to audit it, because they all assume someone else is going to do it. However, if there are entities willing to put in the effort, it's much better for the code to be open-source because then it can be audited, and this auditing can be documented publicly (e.g., the fixes can be seen in git logs), whereas with proprietary software you have no idea if the software has bugs, you can't audit it if you want to, and you can only take the word of the vendor that they've made it secure, and of course we know that isn't worth squat.
- awinter-py 11y agoBytecode / binaries can be verified (for certain properties) using static analysis. Open source doesn't make verficiation that much easier (at scale), but it makes fixing a lot easier. Also, until reproducible builds become commonplace, most linux users can't verify that their binaries come from a specific version of the source. Binary verification is the way to go.
- Grishnakh 11y agoYou only really need reproducible builds if you don't trust the source. So far, there hasn't been any evidence that any open-source projects are untrustworthy.
- matheweis 11y ago"I didn't use Microsoft machines when I was in my operational phase, because I couldn't trust them" ... I'm not really sure that open source should get a free pass in terms of trust - it's not possible for you as an individual to single handedly verify that the open source software is trustable either; you need to assume that the group maintaining it has your best interests at heart.
- ta0967 11y ago1. i don't think that a "free pass" was necessarily implied 2. how would you put it? "i can't review windows source code because it's a trade secret. but since i can't review GNU/Linux or *BSD source code (because it's too much) either, meh."?
- zAy0LfpBZLC8mAC 11y agoBut proprietary software vendors have an interest in keeping things secret, while open source code can be reviewed by people who have an interest in making problems known. With your logic, you might as well say that freedom of information laws are useless because nobody can review all of the government's documents by themselves. The point is not that anyone can review it all by themselves--it's just that it's more reasonable to trust things that the public can verify rather than unsubstantiated claims by someone who has an interest in keeping things secret.
- vezycash 11y agoI was thinking about encryption the other day. It struck me that whenever the topic came on HN we tended to see encryption as 100% or nothing. I however think we should instead focus on creating good enough encrypted communication for email, chat... for two reasons. 1. It'll make things a little bit more expensive for the "watchers." 2. It will create noise. I.e. right now, if one person is using encrypted communication, he automatically becomes a target. With everyone using some level of encryption... 3. It'll serve as an intro to security. The same app that provides base level encryption can give TIPS on how to become even more secure. Think Windows "Tip of the day." There's no perfect security. An insecure world-wide, easy-to-setup encrypted communication is better than nothing. Because, it'll at least make people more security/privacy conscious.
- wyager 11y agoWhy stop at making dragnet surveillance "a little bit more expensive"? It's not much more effort to make dragnet surveillance impossible and directed surveillance extremely expensive.
- kardos 11y ago> I however think we should instead focus on creating good enough encrypted communication for email, chat... for two reasons. What exactly do you propose? We already have large swaths of insecure encryption, for example opportunistic TLS [1], and the "export" crypto leftover from the 1990s. Designing some sort of mediocre encryption system that's both "good enough" to defend against typical criminals and simultaneously only "a little bit more expensive" for the well funded nation states seems like a poor use of expertise. Also it will have a shelf life: attacks only get better. [1] https://en.wikipedia.org/wiki/Opportunistic_encryption https://en.wikipedia.org/wiki/Opportunistic_encryption
- marssaxman 11y agoSnowden generally seems not to open his mouth unless he has something worthwhile to say, so I imagine he might have addressed this in the actual talk of which this article is such a brief summary, but: what choice do we have? No, it's not great, but we typically use government power to check corporations, so I don't see anything inherently wrong with using corporations to check an unaccountable, runaway government.
- rdancer 11y agoThe choice is to either (1) hold all three branches of the government accountable for enforcing the Constitution (or the Universal Declaration of Human Rights outside U.S.), or (2) let slide even further towards tyranny, or (3) there is no #3.
- marssaxman 11y agoWell, yes, but how in practical terms are we supposed to accomplish #1? I see no options. The US government is doing what it wants because it can, and has grown increasingly obvious about it since they face no consequences beyond the embarrassment consequent from perverting the democracy, which is easier to solve by adopting a status-hierarchy mindset and not worrying about it than by actually letting go of power once seized. They are not going to stop unless someone forces them to, and major tech corporations are the only entities I see capable of wielding force on the scale that might accomplish it. They don't care what citizens think anymore - the total failure of the largest protests in the history of the world to accomplish anything against the blatant idiocy of the Iraq war proved that.
- rdancer 11y agoVote in people who would change that. Or get out while you still can get exit visa.