2 ms·
> And then you say, loudly and publicly, "all the source code of our software is public, and our binaries use binary transparency so it's not possible for us to
by danaris 1mo ago
> And then you say, loudly and publicly, "all the source code of our software is public, and our binaries use binary transparency so it's not possible for us to build a binary that doesn't match the source, and people will rapidly find this in our source code at which point we go out of business and you stop having a product to backdoor in the first place".
> (And you move out of the US.)
And then everybody claps.
Name me a software or hardware company—one big enough that the US government would actually care to force them to add a backdoor—that would be willing to give up the US market? The only one that's shown the least bit of backbone is Apple, and while I like them and appreciate what they've done in that vein so far, they're never going to move to open source software running their stuff, and they're pretty well embedded in the US, and very, very unlikely to try to move regardless of the headwinds there.
I'm fully with you that this would be a wise and moral thing to do, but frankly, our tech companies are neither wise nor moral. They are self-serving, greedy, and many of them have wanted to become the neofeudal overlords of a new order since before Trump started smashing the old one.
- JoshTriplett 1mo agoI'm not suggesting giving up the US market. I'm suggesting moving out of the US and continuing to serve the US market from elsewhere, because the US does not have a nation-wide firewall. And working with organizations mounting legal challenges to "please destroy your company in order to put in a backdoor for us". Certificate Transparency has essentially eliminated the problem of backdoored CAs, because attempting to do so would destroy an entire CA. Binary Transparency can do the same for software.
- danaris 1mo agoI'm not sure exactly what you think that will accomplish...? Companies have to follow the laws of the countries they operate in, not just the countries their physical headquarters are in. That's why, for instance, Apple has to follow the DMA in Europe. Furthermore, especially for many of the tech companies, where they are located is an integral part of their culture. They are Silicon Valley. You're going to have a very, very hard time convincing any of them to up stakes and move. And further-furthermore, move where? Europe has, unfortunately, made similar authoritarian noises (eg, Chat Control). China is already more of an authoritarian state than even Trump's USA. Ditto for Russia, and, AIUI, India, though both in somewhat different ways.
- JoshTriplett 1mo agoThe degree to which you have to follow the laws of a place you have no legal nexus in (e.g. no employees) is limited. Non-US companies can and do refuse overreaching requests from the US sometimes. Apple is subject to the DMA in europe because 1) they have employees in Europe and 2) they want to import and sell physical phones into Europe. It's easy to block imports or fine employees. It is not especially easy to prevent people from spending money on a service provided entirely via the Internet from another country. It is not at all impossible to impose sanctions on an entire company. But if the US tried to do so over a refusal to put in a backdoor, and the company very loudly made that clear, that would to some extent be exceptional free marketing.