5 ms·
This is a terrible writeup. >>There is no way to ever prove or disprove whether any encryption was ever happening at all, and whether it was or not makes littl
by MagicWishMonkey 13y ago
This is a terrible writeup.
>>There is no way to ever prove or disprove whether any encryption was ever happening at all, and whether it was or not makes little difference.
That is the whole point in open sourcing the code!
- dsrguru 13y agoAre you saying that releasing a similar system under an open source license will prove claims about the way their code worked in the past or just that we'd know if encryption is happening in the open source system?
- tptacek 13y agoThat is a dumb comment. Open sourcing the code doesn't mean you know anything at all about what's actually running on a server purporting to use the open source code.
- stcredzero 13y agoNow, if such Open Source systems could be compiled with a mechanism that could ensure that only "blessed" executables could run, and if there was also a process where 3rd parties could compile their own executable and verify what is executing on the server, then there would be a solution to this dilemma. Unfortunately, that would be DRM, which evokes knee-jerk cries of "Evil!" The point here is that DRM is not fundamentally evil. The particular way that lots of companies want to use it and slip it into everyone's machine under the radar is most certainly bad. However, there are situations where it would actually be useful and help protect individual rights. (In particular, when it is used by individuals as a tool to protect their own interests.) (Yes, I know I'm preaching to the choir, but this is really for 3rd party readers.)
- dllthomas 13y agoI'm pretty confident there's no real DRM possible when the NSA (potentially) controls the hardware.
- igravious 13y agoThen you'd need a camera on the system and a remote kill trigger. Or. A system that commits suicide when tampered with. All this would need redundancy. But this is the very very outer edges of paranoia and extreme compromise surely? Wouldn't a trusted execution path DRM-style be more than enough?
- igravious 13y agoSo you think that the FSF have the wrong angle on this one? You're saying that DRM is fundamentally ethically neutral, it's just the use cases that have been put forward have been broadly user hostile. To continue, there's nothing to stop "good guys" from using DRM in a benevolent way to secure their rights. So if your reading of this is correct then the FSF should not be waging war on DRM per se but on the many and varied freedom and user -hostile implementations of DRM - this is a harder sell I guess but the distinction is an important one.
- igravious 13y agoSo you think that the FSF have the wrong angle on this one? You're saying that DRM is fundamentally ethically neutral, it's just the use cases that have been put forward have been broadly user hostile. To continue, there's nothing to stop "good guys" from using DRM in a benevolent way to secure their rights. So if your reading of this is correct then the FSF should not be waging war on DRM per se but on the many and varied freedom and user -hostile implementations of DRM - this is a harder sell I guess but the distinction is an important one.
- ds9 13y ago"Unfortunately, that would be DRM" No, it wouldn't. DRM means someone other than the hardware owner restricts what the hardware can do. If you're the owner and control all the relevant keys, the setup enhances rather than removes security - the opposite of DRM. Also I don't think the concept would work. Suppose you have something like a TPM chip and the so-called "trusted computing" scheme - except that the hardware owner has the ability to replace the "attestation key" at will. This would remove the "evil" quality of the TC scheme, which relies on a vendor or corporation acting similarly to a CA, keeping something mathematically related to the Attestation key, and concealing it from the hardware owner. Now as the server owner, you can remotely verify it's still running the software you specified. But without that third party role, you can't prove this to anyone else! And to the extent you could, you would have to point would-be users to the third party, which could "sell out" or use its power to foist treacherous software, or refuse to sign yours, etc. - IOW, right back to the evils of the TC plan.
- stcredzero 13y ago> No, it wouldn't. DRM means someone other than the hardware owner restricts what the hardware can do. Why doesn't it include someone voluntarily giving up what the hardware can do? > Now as the server owner, you can remotely verify it's still running the software you specified. But without that third party role, you can't prove this to anyone else! Why couldn't the license holder of the software take this role?
- jsmeaton 13y agoThe court order basically told lavabit to modify the code to provide the access they were seeking. Even if the code was open sourced, you can bet that the requested modifications wouldn't have been.
- insertnickname 13y agoIf someone else held the copyright to the code and it was licensed under the AGPL, then it would be illegal to not open source such contributions. Of course, the government could work around this by providing their own mail server software or by just disregarding it.