Bonum Certa Men Certa

Bristol Council Claims it Chose Microsoft for 'Security'

Bristol coat of arms



Summary: The laughing stock of the security world is said to have been favoured because it bought some expensive certifications

A FEW months ago we wrote about a bizarre dodge from Free software [1, 2], which happened after everything seemed finalised. No proper explanation was given and those involved were questioned about the sudden change of heart (with the suspicion that something nefarious had happened). Only months later, under persistent pressure from the public and from investigative journalists, we finally see this apparent excuse, which goes like this: "It has been considering a number of open source email solutions, but Bristol City Council confirmed to eWEEK Europe UK that none of them have the necessary government security accreditation to enable the council to use them."



Is this the same reasoning which they gave to those companies? Is this an afterthought? An excuse? Being blessed by some expensive process (that carries no liability either) does not actually make the software more secure. It is not as though when Microsoft software gets cracked the certificate plays any role and somehow gives another target to point the finger at. This smells like dishonesty and since the White Houses uses Drupal and GNU/Linux, this claim holds no water, either.

There are many new examples of insecure proprietary software, one of which came last week from Novell on Windows. To quote:

"Unfortunately, a problem has been discovered with this file, which can potentially result in a system crash in certain circumstances.

The problem has been fixed, and the Client software has been re-released as Novell Client 2 SP1 for Windows (IR9a), available at: http://download.novell.com/Download?buildid=rSUN_TTVSf0~

Please remove the (IR9) build, and use the (IR9a) version instead. We regret the inconvenience.

Thank you."


How would certification have resolved such an issue? It wouldn't have. In practice, Microsoft software and proprietary software are not secure, they are just more secretive and expensive.

The tale of Bristol has been followed quite closely by Mark Ballard, who writes about excuses such as the above (excluding all Free software in one fell swoop, pretending that Microsoft is the only secure option) in the following text:

Bristol City Council's open source push has suffered another series of set-backs that point a finger of blame at CESG, the cyber security arm of government intelligence unit GCHQ.

Leaders at the local authority claim that the need for CESG security certification of e-mail systems effectively means the council has no choice but to buy Microsoft.

Senior Cabinet Office IT leaders have been asked to help as Bristol's faltering open source strategy, still showing little progress after a year, highlighted problems besetting the coalition government's own open source policy.


What a sham. As many other governments use Free software quite happily, this concern has little or no validity. It is a good excuse though -- like one an employer uses to reject a candidate for reasons that are not technical/skills-related but qualifications-related.

In other news of interest, "U.K. Liberal Democrats urge open source," but given the story of Bristol it seems like lip service. From the article:

The British government should ensure it owns all software code it pays for and should share that code for free within the public sector, says a policy paper adopted Sept. 20 by the Liberal Democrats party, the minority partner of the two-party ruling coalition forming the United Kingdom's government.

In addition, the paper urges the British government to embrace collaborative software development along the lines of models on display at GitHub, an open source software project hosting website.


Someone should tell the Lib Dems that Bristol rejects British firms that offer Free software in favour of proprietary software from a foreign company with criminal history -- software that the British public overpays for and has no control over.

Comments

Recent Techrights' Posts

In defence of JD Vance, death of Pope Francis
Reprinted with permission from Daniel Pocock
Three Years in Prison for Disney Employee’s ‘Menu Hacking’: The Economic Fallout of Digital Menus
Reprinted with permission from Ryan Farmer
Approaching 10,000 Articles/Pages Since Going Static
Trying to silence or derail the site was always a dumb strategy
Microsoft is Shedding Off Loads of Staff and That Can be Dangerous Too
Working for Microsoft is a choice; nobody forces you to do it
Richard Stallman and the Unix Philosophy
When asked about systemd people must remember that RMS speaks as an active Board member of the FSF and also the founder of the FSF
Get Rid of Back Doors, Don't Obsess Over Bounties and Other Corporate PR Stunts (or Needless Reboot Rituals)
Security as a term has mostly lost its meaning due to repeated misuse for many years
Serial Sloppers Are Killing the Web (They Probably Don't Care, Either)
Slop is a disease on the Web
 
Links 26/04/2025: Facebook Layoffs Again, Remembering What's Real, and Say No to Mass Surveillance
Links for the day
Links 26/04/2025: NOAA Budget Cuts and "Dog Days Ahead"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, April 25, 2025
IRC logs for Friday, April 25, 2025
Links 25/04/2025: Slop Fatigue and Patent Judges Flocking to Fake, Unconstitutional and Illegal Kangaroo Court (UPC, Captured 'Justice')
Links for the day
Gemini Links 25/04/2025: Night Manager and Devuan in Hosting
Links for the day
Windows Falls to New Lows in Nicaragua, Now Below a Quarter (It Used to be Almost 100%)
Another all-time low for Windows
The Cost (to Linux) of LLM Slop
Slop 'artists' like Fagioli are far from harmless
Links 25/04/2025: Ubisoft Spyware, Hegseth Fails at Tech on Every Level
Links for the day
Gemini Links 25/04/2025: Food Forest Update and Facebook Destroying the Net
Links for the day
Streaming Apps Are “Investor Fraud” That Kills the Planet
Reprinted with permission from Ryan Farmer
Things Get Increasingly Nasty at Microsoft Ahead of the Fake Results and May's Mass Layoffs Wave
They try to get people to 'resign' so that they won't count as layoffs and the company's 'wellbeing' will seem better
IBM's Debt Ballooned by 8.5 Billion Dollars in Just 3 Months!
Hallmark of a company in a state of disarray, trying to spend its way out of trouble
Big Trouble in GNOME
even GNOME people admit the CoC went wrong
Slopping the Trough: Disney Plus Loses Billions and the Decline of Physical Media in America
Reprinted with permission from Ryan Farmer
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 24, 2025
IRC logs for Thursday, April 24, 2025
Links 24/04/2025: GAFAM Problems and No Peace (or Ceasefire) in Sight
Links for the day
Slopfarms on the Web Almost Always Generate Anti-Linux FUD When They Produce "Linux" Output
Welcome to the dying Web
Richard Stallman's Oxford Talk Has Just Ended, Here Are Some Photos
he might hop over to another European country
Gemini Links 24/04/2025: Birthday and Good Work of Academia in Esotericism
Links for the day
Links 24/04/2025: EU fines Apple and Facebook, Another Microsoft GitHub Security Blunder
Links for the day
New Article Explains How the GPL Came About and WordPress Having Copyleft Obligations
Having been involved in the WordPress development community since almost the beginning, I know why it chose the GPL and how it restricts abuse by Automattic
IBM Gained Almost 6 Billion Dollars in "Goodwill" Value in Just 3 Months, According to IBM
Congrats to the management!
In Belarus, Yandex is Now Measured as 50 Times More 'Popular' (by Usage) Than Microsoft
Yandex continues to gain, whereas Bing cannot even register at 1%. Last month it was registered or measured at a measly 0.65%.
IBM Cannot Lie to Shareholders Anymore
"I would not be surprised if we see a layoff every quarter this year."
Dr Richard Stallman (RMS) Gives Talk in Oxford University in 4 Hours
If you live nearby, go there (it's free as in gratis)
Using a Law Firm's Licence to Exercise Politics Through Frivolous SLAPPs and Nastygrams (to Silence People, Remove Pages, Demand Fake or Forced 'Apologies')
Things must be getting really bad when lawyers act for raving antisemites
We're Working to Make Full-Site Search Available
This site has over 1,000 'wiki' pages, many thousands of documents, several thousands of videos, and about 50,000 blog posts or articles. We need to make them easier to find/navigate.
Links 24/04/2025: IBM Loses Many Contracts, Intel to Lay Off Over 20% (Not Counting Those Who Leave 'Voluntarily')
Links for the day
Richard Stallman Can Explain to Oxford Artificial Intelligence Society Why LLM Slop is Not Artificial Intelligence and Why It Hurts Society
another 'crop' of LLM slop that damages GNU/Linux and facts
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, April 23, 2025
IRC logs for Wednesday, April 23, 2025