5 ms·
I'm a Windows/macOS developer, but I strongly feel that all national governments need to convert to Linux, for strategic sovereignty. I'm sure Microsoft, under
by GnarfGnarf 10mo ago
I'm a Windows/macOS developer, but I strongly feel that all national governments need to convert to Linux, for strategic sovereignty. I'm sure Microsoft, under orders from the U.S. government, could disable all computers in any country or organization, at the flick of a switch.
Imagine how Open Source Software could improve if a consortium of nations put their money and resources into commissioning bug fixes and enhancements, which would be of collective benefit.
Apart from a few niche cases, the needs of most government bureaucracies would be well served by currently available OSS word processing, spreadsheet, presentation and graphics software.
- jll29 10mo agoThe sabotage scenario is perhaps less likely than the alternative scenario of industrial and political espionage. There are also practical advantages: the ability to fix a bug in-house instead of waiting for a technology giant from another continent.
- lo_zamoyski 10mo ago> the ability to fix a bug in-house Yes, but bureaucracies make this impossible. If you have worked at a bank before, you'll know how difficult it is to make a change to some in-house piece of software. And that's a bank, not a gov't institution. Think how much more friction there will be in the latter.
- deleted 10mo ago[deleted]
- grim_io 10mo agoThe culture can only change when it actually becomes possible to make any changes to the systems. If all the software one institution uses comes in the form of proprietary binaries, there is simply no need to even think about making policies about fixing those systems in-house.
- nickff 10mo agoThese institutions don’t bother making fixes where they can, so it seems unlikely that giving them more options will change much. Ironically, things like windows auto-update being the default probably actually help their IT departments maintain some level of security
- grim_io 10mo agoAuto update is not rocket science. Linux distributions have it too.
- 1718627440 10mo agoYeah and it is better. Most things can be updated without a reboot and even for the kernel, you can either live-patch it (not always possible) or reboot only the kernel.
- petcat 10mo agoEU bureaucracy is where optimism goes to die
- jimnotgym 10mo agoI wonder if it is in fact easier in a German region than a bank though. A bank has massive compliance complications, where the state insists on rules being met, so their are teams of people trying to make sure no rules being broken, and therefore anti-change. Germany is a Federal system, and the region has law making powers, a bit like a US state. Therefore it can set the rules to make sure migration to a new system happens. If big fixes are not allowed, they have themselves to blame. At a bank it is the state causing the friction.
- Terr_ 10mo agoIt's funny, I was doing some budgeting stuff, and I ran into some corruption of payee-data in my bank's export files. Good: I already wrote a script to fix the exact same issue. Bad: It was in a pile of old stuff from 10+ years ago. Good: It worked anyway. Bad: The bank still has the same bug.
- __d 10mo agoAt a certain size (and government departments are absolutely large enough) it makes sense to manage software deployment centrally, from an internal package repository/cache. Once that’s in place, the process for populating that repository can easily adopt locally modified versions of upstream software: defaults changed, bugs removed, features added, etc. No one in a big business/government blinks at changing group policies for internal deployment. Changing the code is really very little different once the ability to do so is internalized.
- whstl 10mo agoLess likely? This is exactly what happened earlier this year. Here's an article from the same newspaper that showed up to me as "related" when browsing TFA: https://www.heise.de/en/news/Criminal-Court-Microsoft-s-email-block-a-wake-up-call-for-digital-sovereignty-10387383.html https://www.heise.de/en/news/Criminal-Court-Microsoft-s-emai...
- nroets 10mo agoSo you point to one instance of highly targeted sabotage aka sanctions. But Snowden and others exposed many instances of espionage dragnets.
- crazygringo 10mo ago[flagged]
- homarp 10mo agoindeed https://news.ycombinator.com/item?id=44336915 https://news.ycombinator.com/item?id=44336915 - Microsoft suspended the email account of an ICC prosecutor at The Hague then https://news.ycombinator.com/item?id=45837342 https://news.ycombinator.com/item?id=45837342 - ICC ditches Microsoft 365 for openDesk
- crazygringo 10mo agoYup. Microsoft pledged not to intervene like that again, reclassifying its legal interpretation of its own services, and added language to its contracts to guarantee that it would fight future US attempts to do so: https://www.politico.eu/article/microsoft-did-not-cut-services-international-criminal-court-president-american-sanctions-trump-tech-icc-amazon-google/ https://www.politico.eu/article/microsoft-did-not-cut-servic... When the US manages to force Microsoft to do something, it responds by trying to protect itself from the same scenario in the future. Because it wants profits. The ICC leaving Microsoft is the last thing Microsoft wanted.
- dietr1ch 10mo agooh, pinky promise? sure, let's keep sovereignty at stake then, all good.
- crazygringo 10mo agoLengthy contracts between nation-states and corporations, developed and reviewed by teams of lawyers, and enforced by judges, are not exactly "pinky promises."
- zelphirkalt 10mo agoThey will become pinky promises, once Microsoft gets ordered to do something by orange man or some three letters. There isn't really anything Microsoft can do about that, unless they decide to move headquarters and lots of employees out of the US. It basically doesn't matter what they have in contracts, as US law or just political power with access to enforce that power trumps (ha) any contracts they can sign.
- myaccountonhn 10mo agoI agree, but it also feels like it would be so difficult. It requires a ton of training, the UIs are not flashy so people are going to feel repulsed (I unironically found looks to be a big blocker when adopting open source tech) and finally Microsoft is going to lobby incredibly hard against it. I wouldn't put it past Microsoft to actively sabotage any adoption.
- whstl 10mo agoThis excuse is as old as the hills and I've been hearing it since the late 90s, but historically there has been exactly zero training between versions of Office or Windows that changed a lot of the interface overnight. Office workers just kept using them like the rest of the planet. Not to mention companies who moved on to Google Docs or the web version of Office. Or companies who moved to MacOS 15-10 years ago. In my state back home the entire workforce moved to LibreOffice and, according to my sister (a government worker), everyone is doing fine. Recently I saw a German government worker using Office to produce a document and she mentioned that she "barely knows how to use it" and "just knows how to load templates, fill and print". This hypothetical problem of "needs training" only seems to exist when you mention the words "open source".
- dietr1ch 10mo ago> - It requires a ton of training, the UIs are not flashy so people are going to feel repulsed (I unironically found looks to be a big blocker when adopting open source tech), and finally Microsoft is going to lobby incredibly hard against it. I think everyone agrees the costs are high, especially beyond monetary ones, but this stance on avoiding these costs is slowly pushing everyone into finding out how expensive is not having sovereignty. Through its tech industry the US has over time acquired too much power over critical digital infrastructure that has already compromised governments. We know of Presidents/PMs/Legislators spied upon through their phones and computers, and also Microsoft itself involved in revoking email access to the ICC's chief prosecutor as retaliation/defense against investigations. Sovereignty is too important for government, and since everyone needs to do it and get security right going for open-source with funded development and constant auditing is in my mind the only way.
- 10mo ago
- al_borland 10mo agoToday when a government pushes for a backdoor we often see companies push back. The FBI publicly complained about iMessage encryption a lot, and currently Apple is also telling the government of India they aren’t going to install their “security” software… those are just a couple examples. What happens when major OSS projects are controlled by the governments themselves? Will David still beat Goliath?
- hamdouni 10mo agoFork the project.
- Spooky23 10mo agoMaybe. I highly doubt Apple or any other company isn’t complying in some way. It’s been widely speculated that there are gentleman’s agreements where strategic bugs do not get fixed. To apple’s credit, unlike say BlackBerry, they designed iMessage where many of the intercept methods are tamper evident.
- lucianbr 10mo agoHow does anyone "control" an OSS project in the sense that you are talking about, so the ability to insert backdoors or activate kill-switches? Maybe Linus controls Linux, but can he "flick a switch and kill" any running kernels? He might be able to insert backdoors, but will they go unnoticed? Would anyone be forced to install them? Just patch the code to remove the backdoor. I feel that you wrote some words that only seem to make sense if we don't think about them too much.
- rocqua 10mo agoLinux is not a smart target. But OpenOffice, nextcloud, postfix, those are much easier targets for developer coercion to compromise widely installed software that is important for "linux on the desktop". Ah and ofcourse also the desktop environments, and perhaps systemD are all in a privileged position with much less eyes on.
- al_borland 10mo agoThe thought was that the government would effectively become the largest employer of OSS developers who would then be compelled to follow directions or be out of a job. Would there be enough independent developers to review millions of lines of code, patch out any back doors, or fork and maintain an entirely separate projects, since none of the government protects can be trusted? Could the government also dictate the operating system and software people use to make sure it is the state sponsored one? If I’m not mistaken some similar actions have happened in N Korea and China. I’m not saying this is an inevitable outcome, but just trying to think of worst case scenarios. A lot of terrible things have started with good intentions.
- tonyhart7 10mo ago"the needs of most government bureaucracies would be well served by currently available OSS word processing, spreadsheet, presentation and graphics software." wait until they found out that there is no "customer service" in OSS, sometimes the project is fine but people need "someone" to be held accountable in some ways that's why a lot of OSS project never take flight
- TRiG_Ireland 10mo agoThere absolutely can be "customer service" in OSS. You can usually find someone to pay for it.
- 1718627440 10mo agoCustomer service is how OSS companies make money.
- newsclues 10mo agoI feel like there should be an open project to manage and support this. I think governance (both public and private) would benefit from open tools to manage communities at scale via technology.
- rocqua 10mo agoI doubt that Microsoft has a kill switch. Though through automatic updates they still have pretty strong sabotage capabilities. But the OS is not where Microsofts power lies. Its in exchange (almost everywhere cloud managed, including for many governments) and SharePoint, with a small amount of teams, where Microsoft is truly a scary prospect for sovereignty.
- smodo 10mo agoThe kill switch is M365 account management. You take that offline, many SME’s and local governments just stop working. At least for a while.
- codedokode 10mo agoThey have the kill switch, it is called a "cloud account". Nowadays you need a valid cloud (MS-controlled) account to log into your computer.
- Aperocky 10mo agoHaven't used Windows in almost a decade, has it gotten that bad? I can't log on to a windows computer if the cloud account don't exist? What if there's no internet?
- 1718627440 10mo ago> What if there's no internet? Surely that is something only criminal would say.
- d3Xt3r 10mo agoIt caches your credentials so you can still login offline. But you do need to be online when you're logging into your PC for the first time, post-install. There are some unofficial hacks to bypass the online account requirement, but MS have been actively stamping these out. Now the current situation isn't like it's impossible to bypass this, mind you (as far as I'm aware there's at least a couple of workarounds), but normal users won't know/care and will end up just creating an online account.
- consumer451 10mo agoI have a possibly strange take. Isn't the code of law the original open source, for very good reason? As law becomes more and more enforced by software, should it not all be required to be open source?
- graemep 10mo agoGovernments have more to gain from being able to work with a few big companies on things like surveillance than they do from sovereignty - which many of them regard as an out of date idea anyway. Despite all the talk about sovereign cloud the actual governments are actually going the other way. 1. The Online Safety Act in the UK pushes people to use big tech more rather than run stuff independently - the forums that moved to social media. 2. EU regulatory requirements that help the incumbents:https://www.theregister.com/2025/10/27/cispe_eu_sovereignty_framework/ https://www.theregister.com/2025/10/27/cispe_eu_sovereignty_... 3. ID apps in multiple countries that require installs from Google or Apple stores, and only run on their platforms. 4. The push to cashless which means increased reliance on Visa, Mastercard, Apple and Google. To be clear I do not not think that any of these things are in the public interest. However the government is not the public, and the public (and probably a lot of the government) has deeply ingrained learned helplessness about technology.
- SoftTalker 10mo agoPrudent to assume that the same is possible with Linux.
- pjmlp 10mo agoSimilar opinion and source of income. Linux for starters, however even that has too many US contributions. In general, we need to go back to the cold war days, multiple OSes and programming languages governed by international standards, with local vendors. If sovereignty is desired, it can't stop at Office packages.
- mattip 10mo ago> Imagine how Open Source Software could improve if a consortium of nations put their money and resources into commissioning bug fixes and enhancements, which would be of collective benefit. This is the business model of Quansight Labs, whose employees help maintain much of the scientific python stack. Mostly tech companies, not governments, sponsoring the work
- switknee 10mo agoFlicking that switch would be pretty much a one time deal. Not likely. What would happen instead, and has happened in the past, is Microsoft (or juniper, etc) leaving a remote vulnerability unpatched while certain groups use that exploit. It's much more deniable. So deniable, that it's impossible to say for certain that it was intentional. It's more practical to audit FOSS systems for bugs than a Microsoft solution, and the tools for doing so are open source and getting even better every day. Like you said, sharing the burden helps with cost: It also helps with the trust issue. Going one step further, formally verified software solutions are possible (and exist!). Good luck getting that from Microsoft, they ship a calculator that needs updates and internet access to run.