Bonum Certa Men Certa

White House Asking Proprietary Software Companies That Add NSA Back Doors About Their Views on 'Open Source' Security

Video download link | md5sum 660351fe04a47c33611de299d17501b4 GAFAM Finger-pointing for White House Creative Commons Attribution-No Derivative Works 4.0



Summary: The US government wants us to think that in order to tackle security issues we need to reach out to the collective 'wisdom' of the very culprits who created the security mess in the first place (even by intention, for imperialistic objectives)

THE very same companies that back-door their own software (i.e. deliberately make their products not secure) have been asked by the American administration for their views on the security of Free software and security of such software, which isn't defective by design, maybe just by accident, occasionally.



We've already commented on this ludicrous situation in passing (in our Daily Links). The biggest National Security threat (Microsoft) is infiltrating panels on security, diverting attention away from the biggest threats to lesser threats, which are usually the solution, too. Lobbying? Outright political corruption? Both?

Either way, the above video concerns this new article, which is only one of many. We already listed about half a dozen earlier today. The author is so clueless that he calls the Linux Foundation the "Linux Open Source Foundation" and names IBM/Red Hat as if they're separate entities. The same for GitHub and Microsoft. To quote: "The full tech participant list includes Akamai, Amazon, Apache Software Foundation, Apple, Cloudflare, Facebook/Meta, GitHub, Google, IBM, Linux Open Source Foundation, Microsoft, Oracle, RedHat and VMware."

Of the above, only the Apache Software Foundation (ASF) actually speaks for Free/Open Source software. Yes, Zemlin's PAC is little but a front group for some of those other companies.

Why are all the companies invited (assuming Red Hat is just IBM) to discuss this matter dripping "conflict of interest" and how can this establish trust? Why don't they also discuss the threat posed by proprietary software? Some of the headlines that emerged afterwards want us to think that "Open Source" -- not Microsoft et al -- is the real "national security" threat. We'll omit links to those "reports"... (FUD)

“...any real plan has to eliminate Microsoft from both the desktop and the supporting infrastructure. That is a staffing problem, not a technical one.”
      --Techrights associate
"Speaking of politics," an associate noted today, "notice that the US' concern about critical infrastructure is shifting all of the blame and attention on to FOSS. At the same time only the big, proprietary vendors are invited to the planning sessions with the government. They bring in clowns instead of the big names. They should at least be consulting with Bruce Perens, Bruce Schneier, Dan Geer, Moxie Marlinspike, Eugene Spafford, Daniel Bernstein, Paul Vixie etc. (notice that Spaf's quote about Windows is now missing from pretty much every page that includes his old quotes...)"

And "even RMS and Linus Torvalds could add benefit if they had not been reframed as controversial by the attackers now moving in and out of DC. Wietse Venema is in the US too... Phil Zimmermann is still around too. Many of those involved in LibreSSL and OpenSSL are in the US as well... the list of knowledgeable, skilled, experienced people is long. No need for them to include any frauds, charlatans, or poseurs. But that's what we get when Microsoft reps got in on the campaign team. Microsoft created the problems, and therefore is unable to solve them and it would be inappropriate to even have them involved. There's a famous quote which goes approximately like this, "we cannot solve our problems with the same thinking we used to create them." As such Microsoft representatives have to be cleared from the room long, long before discussion can start. Ransomware is just one symptom of microsoftianism. Even if Windows is retained for a shorter period on the desktop, servers could run FreeBSD with OpenZFS.The snapshotting feature would make data restoration much less inconvenient. However, any real plan has to eliminate Microsoft from both the desktop and the supporting infrastructure. That is a staffing problem, not a technical one. Even Microsofters, such as Mitchel Lewis, observe that, but most don't dare speak up. I presume fear of NDAs and non-disparagement clauses in various contracts, especially terminations."

“Microsoft created the problems, and therefore is unable to solve them and it would be inappropriate to even have them involved.”
      --Techrights associate
The number of articles we saw about Log4j that cited Microsoft as if it was a security expert was truly worrying. Since when does Microsoft get to play "concern troll" about "Open Source"?

"About the disappearance of the Spafford quote," our associate noted: "It used to be cited everywhere but most of those sites are gone and the rest seem to have redacted just that one quote."

Recent Techrights' Posts

Topics We Lacked Time to Cover
Due to a Microsoft event (an annual malware fest for lobbying and marketing purposes) there was also a lot of Microsoft propaganda
EPO Education: Workers Resort to Legal Actions (Many Cases) Against the Administration
At the moment the casualties of EPO corruption include the EPO's own staff
 
Links 22/11/2024: Dynamic Pricing Practice and Monopoly Abuses
Links for the day
Microsofters Try to Defund the Free Software Foundation (by Attacking Its Founder This Week) and They Tell People to Instead Give Money to Microsoft Front Groups
Microsoft people try to outspend their critics and harass them
[Meme] EPO for the Kids' Future (or Lack of It)
Patents can last two decades and grow with (or catch up with) the kids
Gemini Links 22/11/2024: ChromeOS, Search Engines, Regular Expressions
Links for the day
This Month is the 11th Month of This Year With Mass Layoffs at Microsoft (So Far It's Happening Every Month This Year, More Announced Hours Ago)
Now they even admit it
Links 22/11/2024: Software Patents Squashed, Russia Starts Using ICBMs
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, November 21, 2024
IRC logs for Thursday, November 21, 2024
Gemini Links 21/11/2024: Alphabetising 400 Books and Giving the Internet up
Links for the day
Links 21/11/2024: TikTok Fighting Bans, Bluesky Failing Users
Links for the day
Links 21/11/2024: SpaceX Repeatedly Failing (Taxpayers Fund Failure), Russian Disinformation Spreading
Links for the day
Richard Stallman Earned Two More Honorary Doctorates Last Month
Two more doctorate degrees
KillerStartups.com is an LLM Spam Site That Sometimes Covers 'Linux' (Spams the Term)
It only serves to distract from real articles
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, November 20, 2024
IRC logs for Wednesday, November 20, 2024
Gemini Links 20/11/2024: Game Recommendations, Schizo Language
Links for the day
Growing Older and Signs of the Site's Maturity
The EPO material remains our top priority
Did Microsoft 'Buy' Red Hat Without Paying for It? Does It Tell Canonical What to Do Now?
This is what Linus Torvalds once dubbed a "dick-sucking" competition or contest (alluding to Red Hat's promotion of UEFI 'secure boot')
Links 20/11/2024: Politics, Toolkits, and Gemini Journals
Links for the day
Links 20/11/2024: 'The Open Source Definition' and Further Escalations in Ukraine/Russia Battles
Links for the day
[Meme] Many Old Gemini Capsules Go Offline, But So Do Entire Web Sites
Problems cannot be addressed and resolved if merely talking about these problems isn't allowed
Links 20/11/2024: Standing Desks, Broken Cables, and Journalists Attacked Some More
Links for the day
Links 20/11/2024: Debt Issues and Fentanylware (TikTok) Ban
Links for the day
Jérémy Bobbio (Lunar), Magna Carta and Debian Freedoms: RIP
Reprinted with permission from Daniel Pocock
Jérémy Bobbio (Lunar) & Debian: from Frans Pop to Euthanasia
Reprinted with permission from Daniel Pocock
This Article About "AI-Powered" is Itself LLM-Generated Junk
Trying to meet quotas by making fake 'articles' that are - in effect - based on plagiarism?
Recognizing invalid legal judgments: rogue Debianists sought to deceive one of Europe's most neglected regions, Midlands-North-West
Reprinted with permission from Daniel Pocock
Google-funded group distributed invalid Swiss judgment to deceive Midlands-North-West
Reprinted with permission from Daniel Pocock
Gemini Links 20/11/2024: BeagleBone Black and Suicide Rates in Switzerland
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, November 19, 2024
IRC logs for Tuesday, November 19, 2024