5 ms·
From the article: "Proprietary security software is an oxymoron -- if the user is not fundamentally in control of the software, the user has no security." I co
by cgranade 14y ago
From the article: "Proprietary security software is an oxymoron -- if the user is not fundamentally in control of the software, the user has no security."
I could not agree more.
- sseveran 14y agoFor most users I could not agree less.
- cgranade 14y agoMake software secure-by-default, make it difficult to override defaults by accident, easy to override on purpose. This is the thought process that seems to be behind, for example, CyanogenMod's recent decision to disable root access by default. To me, the essence of that quote is that any sane security model must include the vendor as a threat, but when I do not have control over my own hardware and software, I have little to no ability to respond to that threat. Moreover, without access to source code, I have little to no ability to audit my own security. Fundamentally, I do not believe in the idea that security can reasonably exist without auditability.
- billswift 14y ago>must include the vendor as a threat Or anyone who gets access to the vendor's database.
- rbanffy 14y agoThe problem is that, in most cases, the user is unable to judge quality. The difference here is software anyone with knowledge can audit and software only the vendor can. If the vendor is in control, you aren't secure.
- mhurron 14y agoAnd the user has to trust that these 'knowledgeable people' are indeed knowledgeable. The exact same thing they have to do with a vendor. Open-source and closed-source software really isn't all that much different for users. All the differences require you to become a professional in the field, or a subset of the field before they mean anything.
- gioele 14y agoThe difference is that, once you have chosen who to trust, you are not forced to trust them forever; you can change who you trust whenever you want and for whatever reason you may have. Can you say "I would like to keep using Exchange, but I do not trust Microsoft, so I will switch to another vendor"? PS: this has to do both with open source and open formats as well.
- Spearchucker 14y agoI don't trust anybody. That applies to both open- and closed-source apps. Security is one concern of many. The overriding one being business value. Using Exchange as an example, it would be difficult for me to come up with something that matches its value. I don't, however, trust it. As an aside, I trust Gmail even less, because at least Exchange runs in an environment I control. And therein lies the solution. Defence in depth. It's a process, and should not rely on any single product. Open- or closed-source. I might choose to protect myself against external, internal and vendor attacks (unintentional as well as malicious) by installing a network firewall, a proxy service, and an application firewall. I might then deploy access controls that authenticate users and authorise their access based on certain criteria. I'd devise a patch strategy. I'd implement an audit policy. I'd do a whole heap of stuff. Frankly, the argument for either open- or closed source is getting tired. Any threat can be mitigated. It's success depends entirely on the value of the asset being protected, and the amount of money you're prepared to spend protecting that asset.
- rbanffy 14y agoIf we are talking about open-source versus proprietary software you shouldn't offer Gmail as an option to Exchange, since both are proprietary. In fact, I believe your perception of security is wrong - if someone wanted to steal your e-mails from your Exchange server, all they have to do is to compromise a sysadmin inside your organization (or your co-lo provider). When you need to get someone's email from Gmail, you'll have to compromise a sysadmin within Google with access to the information you want. Even pinpointing one is, most likely, hard.
- arihant 14y agoI cannot agree with you. A user, on a given day, interacts with countless interfaces, not all of those interfaces have to do with technology. If you give everyone 100% control over every interface - this will drive the world crazy. How much control do you have on your house lock - do you take it apart everyday? How much control do you have on temperature regulation in your fridge, except for temperature dial? People in computing must realize that a computer is just another interface for a user. For a programmer, I agree with you. But if I made cupcakes for a living, I'd want control over my oven, not my computer. As a programmer though, I trust that my oven company did their job and eat food out of it everyday.
- ori_b 14y ago> How much control do you have on your house lock - do you take it apart everyday I actually have taken apart the locking mechanism once to repair it. It got stuck, the door wouldn't open, so I fixed it. I didn't take out the barrel or dig too deep in, but I didn't need to. If I hadn't been technically competent to do that, I would have been able to hire someone else to do it for me.
- kalleboo 14y agoIf my house lock automatically rejected anyone it arbitrarily deemed "morally suspect", I'd sure as heck want control over it.
- arihant 14y agoThe software mentioned in the article already gives you that level of control, with use of exceptions. But this is just as much control as my fridge gives me with the temperature control dial. What FSF is debating is "fundamental" and full control of inner workings of the software, which is what I find a bit narrow.
- rlpb 14y ago> How much control do you have on your house lock - do you take it apart everyday? No, but I can hire any locksmith of my choosing to look at it. The point isn't that end-users are in control of it, but that end-users can hire experts to adjust it if needed. Giving a manufacturer complete aftermarket control of their product is entirely different.
- cooldeal 14y agoThe users are in control of the software, they can disable the gateway or add exceptions to it. http://technet.microsoft.com/en-us/library/dd441041.aspx http://technet.microsoft.com/en-us/library/dd441041.aspx Unless you consider the 'user' to be the employee sitting at the desk which is a topic for another discussion, unless the FSF is claiming that website blocking by an employer is user abuse. Edit: There's speculation that the gambling classification was triggered by a pattern matching algorithm because of accepting bitcoin which mostly gambling sites tend to do. Maybe that's why only the donation page got blocked.
- rbanffy 14y ago> The users are in control of the software, they can disable the gateway or add exceptions to it. Still, you have to trust Microsoft the software will run as expected. With proprietary software, you have no option but to trust the provider. It doesn't matter how much they claim the software is secure, you will never know.