7 ms·
Brazilian government to ditch Microsoft in favour of bespoke email system
- ffrryuu 13y agoSpying/backdoor may be a consideration.
- arbuge 13y agoYou think?
- cleverjake 13y agoIt literally says that in the first paragraph.
- jwoah12 13y agoHopefully as this happens more often, the affected companies will start to lobby against the current policies.
- auctiontheory 13y agoAs we've already seen, US companies have very little leverage against the US government in such "national security" matters. (Same for Chinese companies, etc.)
- Ensorceled 13y agoI love the discussions on this topic: "It will probably cost more in the long run." "The NSA will just crack it and spy anyway." So many people with the attitude that countries that find out their tech partners are actually performing espionage on behalf of the US government (and US security partners) should just tolerate it rather than do something about it.
- outside1234 13y agoI agree, but what they should do about it is attack the policies, not swap out the stack for another stack. Motion is not necessarily progress.
- moocowduckquack 13y agoI don't think they are swapping the stack for a tech upgrade, they are swapping it because at the moment they are in the position of directing state funds towards an organisation that is seen to be under the control of a government that is acting aggressively towards them, which is not a tenable position politically for the people signing off on the budgets, especially since it is all so very public.
- CurtHagenlocher 13y agoTo the best of my knowledge, no one has alleged that the NSA had Microsoft's help in intercepting Petrobras-related email. This is more about the possibility of such a threat than anything else. Disclaimer: I work at Microsoft, so eh.
- devx 13y agoWhy take the chance? From the leaks, the companies have "cooperated enough", especially when we're talking about "foreigners". We don't need proof for absolutely everything and for every single case, to stop trusting American companies, until there's a dramatic change in laws, and surveillance policy in US.
- stfu 13y agoThis is going to be the main issue behind that argument. The burden of proof has shifted. The tech industries reaction to the Snowden seems to the outside very lukewarm. Sure, they are giving all sorts of "trust us" statements, but truth is we don't have the slightest clue if this is their honest opinion or just an opinion that a secret court forces them to uphold. Reality might be much more nuanced, but to the outside there is very little reason to give anyone any longer the benefit of the doubt.
- barista 13y agoThere is nothing that singles Microsoft out here as every other operator of email and other software complied as well. This is something the US government should come clean on and something that the tech companies should push the government to do.
- stfu 13y agoAbsolutely. There is nothing that singles out Microsoft as better or worse, but it is a looming issue for the whole US tech industry.
- neves 13y ago
- marcosdumay 13y agoIt's more of a practical concern. Migrating the government to Linux and using a free mail infrastructure would be cheaper (saving money in the long term, instead of costing), easier, and way more effective than using a non-standard internal email protocol and keep using Windows everywhere. Why bother when Microsoft still has access to all your data? About using that proprietary protocol AND migrating to a free software environment, that could be better than just migrating, or worse, depends of the actual quality* of the protocol. But while the government frames it as a XOR option, migrating to an open stack is the only sane option. * The fact that the protocol isn't public isn't good, the fact that it's Serpro creating it makes this worse - they've already done quite a few bad decisions about security.
- walshemj 13y agoIt sounds a lot like a Brazilian version of the secure intranet (GSI) that the UK has rolled out for lower level stuff. And from a security perspective (sorry linux fanbois and microsft haters) the choice of MTA/MUA isn't as important as the rest of the security. Would be interesting if due to this that OSI and X.400 makes a comeback for more secure email - though presumably with all the security enhancement proposed for the later standards - hmm I wonder if you could use quantum networking with x.400/500
- malandrew 13y agoIf they opted for an entirely open source system (possibly open-sourcing the one in question) that several governments with the same concern could collaborate on, then they would probably be much safer. Going with a bespoke system that will be deployed widely is a recipe for problems. It's likely to have limited documentation and lots of setup edge-cases that are easy to compromise.
- kenjackson 13y agoFor any interesting open source project, why would you think that the NSA wouldn't be deeply involved? If I were a spy agency and an open source project was being spun up that several countries would use, I'd get at least a dozen devs on it. And if I'm thinking that, then you know they all must be...
- kevin_rubyhouse 13y agoI would like to see how this turns out considering how miserably the US's Healthcare.gov site has been going. It sounds like the Brazilian govt. is using an internal group (the Federal Data Processing Service [SERPRO]) to do this, while the US sourced the work to a domestic company (CGI Federal.) I've got a gut feeling that Brazil's email system will fare better than our Healthcare.gov site. Article about SERPRO launching their cloud platform. http://www.zdnet.com/brazilian-government-launches-own-cloud-offering-7000020738/ http://www.zdnet.com/brazilian-government-launches-own-cloud... Some random info about the Healthcare.gov devs: http://www.washingtonpost.com/blogs/wonkblog/wp/2013/10/09/healthcare-gov-was-originally-built-in-a-garage/ http://www.washingtonpost.com/blogs/wonkblog/wp/2013/10/09/h...
- soneca 13y agoI don't know about your healthcare.gov, but it is very difficult to predict the success or failure of a government project around here (i am brazilian). At one side we have incredibly well done and well managed examples, as our elections voting system. I get embarassed for US everytime I see the news about your elections, with cards and weird stuff. On the other hand, we have lots of examples of how the government can mess things up, most notably these days are the stadiums and overall infrastructure for World Cup. It is even worse than any pessimist would have predicted. So... all we can do is wait. The initiative, I think is good, but the outcome.. who knows?
- filipemonte 13y agoI use the expresso daily, it's not a good platform, lot of limitations! But at least, is a response for the spying. Better than doing nothing! Hope this investment change expresso in a better way!
- marcosdumay 13y agoA question from someone that'll probably have to start using it soon: Can you back-up your emails in a way where the central IT of your place can't delete them?
- felipe 13y agoApparently this is the software currently being used to replace Outlook: http://www.expressolivre.org/modules/conteudo/conteudo.php?conteudo=3 http://www.expressolivre.org/modules/conteudo/conteudo.php?c...
- yeukhon 13y agoWho created Expresso?
- filipemonte 13y agoIt is based in a german project (http://www.egroupware.org/ http://www.egroupware.org/)
- yeukhon 13y agoCool. Since they think that project is more secured than MS Outlook, I wonder if the government has requested to audit or not.
- marcosdumay 13y agoThe (brazilian) government is the maintainer of the software. Why would it require an audit?
- darkarmani 13y agoThey are making the claim that they are doing it for security reasons, why wouldn't they want the code audited? A gov't employee could write a backdoor just like a private sector employee.
- marcosdumay 13y agoOk, maybe I should rephrase that. Who would do an audit? Because the obvious candidate is Serpro, but they are already developing it. Anyway, it's open source, so if any part of the government (military maybe, ABIN, or some university) thinks that it deserves an audit, it can simply do it, no need for formalization.
- evli 13y agoI find it great that my country (Brazil) is not so mindless about technology. I hope that this anti NSA moves sparks an actual development in the industry here.
- Theodores 13y agoIf a country is big enough to have an air force then it is big enough to do something on its own about securing government communications. How hard is it to write an email client? With some calendar? Is it complete rocket surgery or something in the realms of feasibly possible? Wasn't gmail some 20%-er time by a couple of guys at Google? I don't think it took years or billions to get up and running. I think you could have a tidy and secure webmail built by half a dozen people randomly chosen from Hacker News in six months. Sure it might not be as all singing and dancing as the oh-so-wonderful Microsoft Outlook but then again it might actually be better for the task in hand - facilitating communication for a government. Sometimes people have got to try rather than be all helpless. I am all for software re-use, open source and everything else deemed good software engineering, but, for a government wanting to keep their communications private some consideration has to be given to 'how hard can it be to write an email client?'
- InclinedPlane 13y agoYou'd think so. But we're still in an age of software wizardry. It's easy to write great software if you exist within an organization where software dev. is already a core competency. But if that's not the case and you need to procure high quality software without already having the expertise in house then things get hairy really fast. Not that it's the best example, but look at healthcare.gov, it's a buggy mess at a cost of tens of millions of dollars. I suspect that Brazil's home grown mail system is also going to be a buggy, low-quality mess at a cost of tens of millions of dollars.
- alipang 13y agoWell, one problem is when the client is a government. Healthcare.gov can not exactly be described as rocket science either (even less so I'd imagine), but ended up costing a nice little sum of money, while also not even working.
- vkou 13y agoNo, interfacing with half of the stone-age machinery that Healthcare.gov has to is not rocket science. The closer analogy would be pulling teeth. I'd also daresay that GMail is only possible thanks to Google infrastructure - which was not built over 20% time.
- doorty 13y agoThis is great. If service providers lose business because of cooperation with the NSA, then it's just a matter of time until those service providers have a compelling reason (Capitalism) that Congress, etc. can get behind.
- mpyne 13y agoIt would be nice if the Brazilian government adopted and helped to improve an existing open source solution (may I recommend Kolab?) instead of falling prey to NIH. As others have mentioned, PIM is very difficult and if it's done wrong, you end up with metadata leaking across the Internet, security flaws, etc. If the real issue is with the inability to see the source then open source is better than "Brazilian government"-proprietary, as the NSA could simply hack the source code repository, CIA could plant an insider, the list goes on. You could have someone whose job is to audit the integrity of the archive, but who watches the watchers? With open source the problem is simpler: everyone can watch the source code archive.
- outworlder 13y agoAt least, that's an excuse to ditch proprietary solutions. I could back that up. But the source will probably be closed (as the voting machines, for instance), so I don't see any gains there, other than jurisdiction. It probably won't do much for security though. If anything, vulnerabilities will be more likely. The only thing they've got for it is securing the physical comms. But even if the US (or any other superpower) doesn't compromise them, there are other ways of extracting the data. And this being SERPRO, they'll likely use cutting edge technologies such as MD5 and DES.
- darkarmani 13y ago> And this being SERPRO, they'll likely use cutting edge technologies such as MD5 and DES. Hey, PBKDF1 uses md5. That only puts them a handful of years behind.
- jhhn 13y agoLOL.... BIG LOL! Only who lives here in Brazil should know that software engineering skills is not the requirement to be accepted in SERPRO team. And, considering the corrupt chain of outsourcing related to most of IT projects here, maybe would be safer for us to stay being spied by NSA and other agencies.
- rhapsodyv 13y agoSome day, just for fun, I have broken some gov site using expresso. I got full remote code execution (for test, I just uploaded a php file with a phpinfo()). And I'm not a security expert. I think my govern has a lot of work to do to make their email more secure...