4 ms·
I believe releasing it to open source makes the code more trustworthy. Now, anyone can go in and verify how it works. Any backdoor would be visible in the co
by pwaivers 8y ago
I believe releasing it to open source makes the code more trustworthy. Now, anyone can go in and verify how it works.
Any backdoor would be visible in the code.
- craftyguy 8y ago> I believe releasing it to open source makes the code more trustworthy I don't, and I think it's dangerous to assume that. Many open source projects have systems in place for publicly reviewing and approving code, but microsoft does not have a history of conducting public code reviews for their projects. I would never assume that publicly viewable code is being reviewed by others who know what they are doing if it's not obvious that they are. > Now, anyone can go in and verify how it works. Any backdoor would be visible in the code I would only trust those with a high degree of mathematical knowledge, specifically around the subject of cryptography to be able review the code in any meaningful way. The rest of us can verify that it builds successfully and, well, that's about it.
- jf- 8y agoBe that as it may, if you’re trying to hide something releasing it as open source is a pretty terrible way to do it.
- craftyguy 8y agoNot if it's highly unlikely anyone with enough knowledge to know otherwise is going to review it. The upside is that you get folks like the one above who automatically assume open source software is safe, and use it.
- jf- 8y agoOr just don’t bother open sourcing it and running the risk of being caught. In principle I agree with you, but in practical terms it would be a very wacky double bluff to pull.
- zcf 8y agoI am working on the SEAL team and agree that these are reasonable concerns and questions. With open-sourcing we are hoping to build more trust in our implementation of this admittedly complicated technology. In addition to our internal code reviews at Microsoft, we are hoping to engage with the broader OSS and crypto researcher community in identifying and address any issues and concerns that are brought to our attention. Note also that the theory of homomorphic encryption has been developed in the open scientific community; all schemes and security estimates are backed up by published papers, and multiple other publicly available implementations. SEAL itself has been publicly available since 2015, although under a non-commercial license. In 2017 Microsoft helped launch the HomomorphicEncryption.org consortium for standardizing homomorphic encryption (see http://HomomorphicEncryption.org http://HomomorphicEncryption.org). Today, this group consists of more than 300 scientists from around the world, including partners and participants from industry (Microsoft, IBM, Duality Technologies, Intel, Google, multiple start-ups), top researchers from universities (MIT, Seoul National University, EPFL, ...), and government (e.g. NIST).
- ancarda 8y ago>Any backdoor would be visible in the code. AFAIK, looking at the code for a Dual_EC_DRBG implementation wouldn't look backdoor'd as the backdoor was in the mathematics of the crypto itself. Even if the code itself had a backdoor, a carefully hidden one may go undetected. Like a missing "goto" or a single equals sign; `if x = y`. An example here: https://freedom-to-tinker.com/2013/10/09/the-linux-backdoor-attempt-of-2003/ https://freedom-to-tinker.com/2013/10/09/the-linux-backdoor-...