4 ms·
Over 100 comments, zero mentions that government funds should be spent on devices with auditable open-source firmware. Anyone here? No? Then I'm the first one t
by PinkSheep 1mo ago
Over 100 comments, zero mentions that government funds should be spent on devices with auditable open-source firmware. Anyone here? No? Then I'm the first one to say this.
SecureBoot is a funny one. It should be signed with the deployer's keys (Slovak), not the manufacturer's. Trusted boot probably wasn't a consideration here, really.
Ironically, a custom firmware can now be used thanks to the lack of a digital lock... if you still trust the hardware.
PS: Props to NBU for doing their job.
- srdjanr 1mo agoWould you be able to get those devices at all, especially at similar price as those with closed source firmware? R
- PinkSheep 1mo ago"at all" -> I would like to believe a government tender to wield more power than just being at the mercy of commercial market offerings. "similar price to closed source" -> Good argument. But what if the _lower price_ is only lower thanks to a vendor lock-in? Thus, over a long period of time, you don't get a better deal? Furthermore, here an expensive reverse-engineering project had to discover the backdoors? What was its cost? Why can't the government have this work done (new cameras) on a contract basis? First step: "we want this and that, you may choose the hardware freely, but the project source code will be perpetually licensed to the government to use and extend upon." Second step: "we have this source code from the last contract, we want another 1000 of these traffic cameras with improved specs/features." The belief, that the market will do anything right, perpetuates this system of outsourcing everything to the market. Though I don't think it can work any other way, because nobody among the government workers wants to bear responsibility and liability. It's much easier to give party B the money and then argue with them based on the paper trails. This is what they've been trained to do after all.
- like_any_other 1mo agoMaybe you trust the hardware and software and firmware to not be malicious or negligent (currently such assurances are extremely rare [1], so it's hard to overstate what a step up in security just this bare minimum would be), but what if it simply gets hacked by a nation-state level opponent? And there are so many ways to hack it - hardware and software supply chains, interdiction and replacement with compromised parts, attacking the software systems connected to it (maybe the camera is secure, but what about the computers it sends its signals to?), or the human systems, blackmailing an employee to insert a backdoored USB key somewhere... Are traffic cameras worth the risk of giving away the movement of your key personnel, military and political, in the age of drone warfare and targeted strikes? [1] https://news.ycombinator.com/item?id=49248678 https://news.ycombinator.com/item?id=49248678
- PinkSheep 1mo agoFair. I see, you are against traffic cams in general? One approach is to take away their networking capabilities. Dump the data from them manually, physical access :) like 26 years ago in the year 2000 AD. But the police and agencies will cry about losing real time access (and surveillance) capabilities. While you raise good arguments against wide deployment, politics will not backtrack. Despite the loopholes, despite the vulnerabilities, despite real life precedents, the juggernaut will keep moving. Much like blackouts or internet outages (Canada) that make payments, digital communication impossible, people will not rely any less on cashless payments etc. That's the blackpill. The Navy drones article is terrifying. The easier solution is to not have wars at all (lol) then the problem is reduced to only corporate espionage.
- dredmorbius 1mo agoThat was in fact the angle of the Fediverse post from which I first saw this story: "Please use open source systems whenever possible so you can review the source code." <https://floss.social/@mikebabcock/117134334377276076 https://floss.social/@mikebabcock/117134334377276076>