11.14.13

Gemini version available ♊︎

In This Age of Fog/Cloud (Surveillance-Friendly) Computing, Can OwnCloud Be Trusted?

Posted in Free/Libre Software at 6:01 am by Dr. Roy Schestowitz

Spooks love the fog as it lets them spy on people without the people knowing about it

Fog

Summary: Looking at the problems with “cloud” (fog) computing, even when it is driven by Free software and is self-hosted

Fog Computing is one of the most disturbing emerging trends. It’s often proprietary by design (no access to source code) and it is a lot worse because it’s remotely controlled (no control over the binaries, either). Red Hat's embrace of OpenStack represents a strategic shift wherein Red Hat facilitates the deployment of Fog Computing by other companies [1]. It’s not Red Hat which does the violations, but oftentimes the companies which Red Hat helps will go on violating people’s privacy and dignity (Amazon for instance).

OpenStack is one of those cases where one has access to source code, but one cannot verify that this code is actually what’s executed as there is no access to the binaries (for the client side). Microsoft partners like Citrix are also embracing OpenStack [2], which sure enjoys growing influence [3]. It’s better to use something that’s Free/Open Source than something that’s proprietary, but when the code runs remotely, it is still far from freedom-respecting, unless of course it’s self-hosted, in which case NSA surveillance of OpenStack instances (possible [4]) is getting hard.

There is only one project that I know fulfills the above needs. It is the Germany-based OwnCloud [5,6,7], which has roots in SUSE (the key staff). The problem is, this project’s code has had a lot of vulnerabilities which basically would be easy for the NSA to exploit and gain access to servers. MEGA is said to be privacy-respecting, but it is proprietary and Flash-based. This option too has been found to have security vulnerabilities.

So the bottom line is this: keep your sensitive data on the local disk, stored by a reliable system like GNU/Linux. This data should not shipped without encryption (e.g. SSH) down a wire unless it only moved locally (within local network or hub). In this age of personal targeting, politically-motivated smears, espionage, etc. we need to protect our personal data. If we didn’t have anything to hide, we wouldn’t mind uploading our entire hard drives to be made publicly accessible by all, right? Well, not really. Apparently, even if you’re doing nothing wrong, you still need privacy. The NSA doesn’t give a damn about that.

Related/contextual items from the news:

  1. Red Hat Delivers More Tools, Services for Enterprise OpenStack

    Red Hat has a sterling reputation for advancing and supporting Linux in the enterprise, but the company is structuring much of its future growth around cloud computing, and OpenStack in particular. The company has recently announced the Red Hat Enterprise Linux OpenStack Platform, an Infrastructure-as-a-Service certification program for OpenStack, a deepening partnership with Canonical and Ubuntu surrounding the new Havana release of OpenStack, and more.

  2. Citrix Embraces ‘Anyness’ and the OpenStack Cloud

    VIDEO: The general manager of Citrix’s cloud efforts explains how his firm both supports and competes against the open-source OpenStack cloud.

  3. OpenStack Summit Highlights Cloud’s Global Influence

    The open-source OpenStack Foundation held its semiannual Design Summit here Nov. 5-8, discussing all manner of topics related to the cloud. As the first OpenStack Summit held outside of the United States, the event had a strong emphasis throughout on the global nature of the OpenStack cloud platform and, more specifically, the high levels of interest, participation and deployment of the platform in China. According to data released at the Hong Kong event, China is now home to more OpenStack developers than anywhere else in the world. China is also home to some of the largest OpenStack deployments on Earth, including one with Qihoo 360, a Beijing-based online security and mobile vendor. Qihoo 360 is using OpenStack to provide cloud-based security for 450 million user

  4. OpenStack Cloud Vendors Vigilant in the Face of NSA Snooping

    The Edward Snowden revelations about NSA snooping in the cloud are not having an impact on OpenStack cloud vendors, including Rackspace and Dreamhost.

  5. Why I love OwnCloud: answer to Dropbox lock-in

    I recently covered the release of Dropbox platform and my thoughts on the impending cloud storage lock-in. I was also fortunate enough to run across what the guys over at NimbusBase are doing over the weekend. They seem to be the answer to the open API for mobile and web applications, providing a cross-cloud storage layer and a GPL reference implementation while they do it. I also penned a few thoughts on their model.

  6. Own Your Data with OwnCloud
  7. Pure open source, open standard based Google Docs, iWork, Office 365 competitor arrives
Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

DecorWhat Else is New


  1. Links 25/1/2022: GPL Settlement With Patrick McHardy, Godot 4.0 Alpha 1, and DXVK 1.9.4 Released

    Links for the day



  2. Proprietary Software is Pollution

    "My daughter asked me about why are we throwing away some bits of technology," Dr. Andy Farnell says. "This is my attempt to put into words for "ordinary" people what I tried to explain to a 6 year old."



  3. Microsoft GitHub Exposé — Part XV — Cover-Up and Defamation

    Defamation of one’s victims might be another offence to add to the long list of offences committed by Microsoft’s Chief Architect of GitHub Copilot, Balabhadra (Alex) Graveley; attempting to discredit the police report is a new low and can get Mr. Graveley even deeper in trouble (Microsoft protecting him only makes matters worse)



  4. [Meme] Alexander Ramsay and Team UPC Inciting Politicians to Break the Law and Violate Constitutions, Based on Misinformation, Fake News, and Deliberate Lies Wrapped up as 'Studies'

    The EPO‘s law-breaking leadership (Benoît Battistelli, António Campinos and their corrupt cronies), helped by liars who don't enjoy diplomatic immunity, are cooperating to undermine courts across the EU, in effect replacing them with EPO puppets who are patent maximalists (Europe’s equivalents of James Rodney Gilstrap and Alan D Albright, a Donald Trump appointee, in the Eastern and Western Districts of Texas, respectively)



  5. Has the Administrative Council Belatedly Realised What Its Job in the European Patent Organisation Really Is?

    The "Mafia" which took over the EPO (the EPO's own workers call it "Mafia") isn't getting its way with a proposal, so it's preventing the states from even voting on it!



  6. [Meme] Team UPC is Celebrating a Pyrrhic Victory

    Pyrrhic victory best describes what's happening at the moment (it’s a lobbying tactic, faking/staging things to help false prophecies be fulfilled, based on hopes and wishes alone), for faking something without bothering to explain the legal basis is going to lead to further escalations and complaints (already impending)



  7. Links 24/1/2022: Scribus 1.5.8 and LXLE Reviewed

    Links for the day



  8. IRC Proceedings: Sunday, January 23, 2022

    IRC logs for Sunday, January 23, 2022



  9. [Meme] Team UPC Congratulating Itself

    The barrage of fake news and misinformation about the UPC deliberately leaves out all the obvious and very important facts; even the EPO‘s António Campinos and Breton (Benoît Battistelli‘s buddy) participated in the lying



  10. Links 24/1/2022: pgBadger 11.7 Released, Catch-up With Patents

    Links for the day



  11. The Demonisation and Stereotyping of Coders Not Working for Big Corporations (or 'The System')

    The war on encrypted communication (or secure communications) carries on despite a lack of evidence that encryption stands in the way of crime investigations (most criminals use none of it)



  12. On the 'Peak Hacker' Series

    Hacker culture, unlike Ludditism, is ultimately a movement for justice, for equality, and for human rights through personal and collective emancipation; Dr. Farnell has done a good job explaining where we stand and his splendid series has come to a close



  13. Links 23/1/2022: First RC of Linux 5.17 and Sway 1.7 Released

    Links for the day



  14. Peak Code — Part III: After Code

    "Surveillance perimeters, smart TVs (Telescreens built to Orwell's original blueprint) watched over our living rooms. Mandatory smart everything kept us 'trustless'. Safe search, safe thoughts. We withdrew. Inside, we went quietly mad."



  15. IRC Proceedings: Saturday, January 22, 2022

    IRC logs for Saturday, January 22, 2022



  16. Links 23/1/2022: MongoDB 5.2, BuddyPress 10.0.0, and GNU Parallel 20220122

    Links for the day



  17. A Parade of Fake News About the UPC Does Not Change the General Consensus or the Simple Facts

    European Patents (EPs) from the EPO are granted in violation of the EPC; Courts are now targeted by António Campinos and the minions he associates with (mostly parasitic litigation firms and monopolists), for they want puppets for “judges” and for invalid patents to be magically rendered “valid” and “enforceable”



  18. Welcome to 2022: Intentional Lies Are 'Benefits' and 'Alternative Facts'

    A crooks-run EPO, together with the patent litigation cabal that we’ve dubbed ‘Team UPC’ (it has nothing to do with science or with innovation), is spreading tons of misinformation; the lies are designed to make the law-breaking seem OK, knowing that Benoît Battistelli and António Campinos are practically above the law, so perjury as well as gross violations of the EPC and constitutions won’t scare them (prosecution as deterrence just isn’t there, which is another inherent problem with the UPC)



  19. From Software Eating the World to the Pentagon Eating All the Software

    “Software is eating the world,” according to Marc Andreessen (co-founder of Netscape), but the Empire Strikes Back (not the movie, the actual empire) by hijacking all code by proxy, via Microsoft, just as it grabbed a lot of the world’s communications via Skype, bypassing the world's many national telecoms; coders need to fight back rather than participate in racist (imperial) shams such as GitHub



  20. Links 22/1/2022: Skrooge 2.27.0 and Ray-Tracing Stuff

    Links for the day



  21. IRC Proceedings: Friday, January 21, 2022

    IRC logs for Friday, January 21, 2022



  22. Peak Code — Part II: Lost Source

    "Debian and Mozilla played along. They were made “Yeoman Freeholders” in return for rewriting their charters to “work closely with the new Ministry in the interests of all stakeholders” – or some-such vacuous spout… because no one remembers… after that it started."



  23. Links 22/1/2022: Ubuntu MATE 21.10 for GPD Pocket 3, MINISFORUM Preloads GNU/Linux

    Links for the day



  24. Computer Users Should be Operators, But Instead They're Being Operated by Vendors and Governments

    Computers have been turned into hostile black boxes (unlike Blackbox) that distrust the person who purchased them; moreover, from a legislative point of view, encryption (i.e. computer security) is perceived and treated by governments like a threat instead of something imperative — a necessity for society’s empowerment (privacy is about control and people in positions of unjust power want total and complete control)



  25. Peak Code — Part I: Before the Wars

    Article/series by Dr. Andy Farnell: "in the period between 1960 and 2060 people had mistaken what they called "The Internet" for a communications system, when it had in fact been an Ideal and a Battleground all along - the site of the 100 years info-war."



  26. Links 21/1/2022: RISC-V Development Board and Rust 1.58.1

    Links for the day



  27. IRC Proceedings: Thursday, January 20, 2022

    IRC logs for Thursday, January 20, 2022



  28. Gemini Lets You Control the Presentation Layer to Suit Your Own Needs

    In Gemini (or the Web as seen through Gemini clients such as Kristall) the user comes first; it's not sites/capsules that tell the user how pages are presented/rendered, as they decide only on structural/semantic aspects



  29. The Future of Techrights

    Futures are difficult to predict, but our general vision for the years ahead revolves around more community involvement and less (none or decreased) reliance on third parties, especially monopolistic corporations, mostly because they oppress the population via the network and via electronic devices



  30. [Meme] UPC for CJEU

    When you do illegal things and knowingly break the law to get started with a “legal” system you know it’ll end up in tears… or the CJEU


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts