4 ms·
"We require all government agencies to report security vulnerabilities they are aware of to the Federal Office for Information Security (BSI) and to undergo reg
by AtNightWeCode 5y ago
"We require all government agencies to report security vulnerabilities they are aware of to the Federal Office for Information Security (BSI) and to undergo regular external audits of their IT systems."
If some well known agencies done this, loss of billions of dollars could have been avoided.
"In the future, development contracts will be regularly commissioned as open source, and the software will be made public as a matter of principle. There will be a right to encryption, and the state must also offer the option of genuine encrypted communication."
Personally I have a hard time to trust anything after heart bleed. A very basic attack that caused havoc. It proved that the quality of open source is nowhere close to the promises of OSS. It also tells that the automatic tests are too simple, if there are any. Fact is that a student in any class about the network stack probably already been targeted about far more complex attacks than heart bleed.
Encryption is mandatory for most things in EU. But the quality is difficult to evaluate.
- wizzwizz4 5y ago> Personally I have a hard time to trust anything after heart bleed. A very basic attack that caused havoc. It proved that the quality of open source is nowhere close to the promises of OSS. Heartbleed made international headlines, and got fixed very quickly. The equivalent bugs in Mike's Proprietary Encryption Layer are just another Tuesday. Which is better: being able to discover a bug like Heartbleed, or not being able to discover a bug like Heartbleed?
- wolverine876 5y agoOSS is certainly no guarantee of security, but there is quality, secure OSS, such as WireGuard.