Bonum Certa Men Certa

Orwellian EIF, Fake Open Source, and Security Implications

George Orwell
Open is close enough



Summary: The manipulation of Europe's interoperability framework (by Microsoft lobbyists and others) is made more visible; other news of relevance

Yesterday we wrote about the European Interoperability Framework (EIF), which Microsoft front groups were leaning on [1, 2, 3] until "open" almost came to mean "proprietary" and "patent-encumbered". The original analysis has received a lot of response; for instance, Neko Nata compares this to Microsoft's corruption of ISO and Bob Robertson quotes Orwell as follows: "Languages evolve, sometimes faster than others." In ComputerWorld UK, E.T. Anderson compares it to "War is peace".



Here is new coverage from The Register:

The European Union has long promoted open source software, but it seems that years of expensive lobbying by big software companies has finally worn down the bureaucrats' resistance.

The latest version of the European Interoperability Framework - which aims to offer governments and businesses guidance on using open source software - has substantially weakened its definition of what open source is. This follows years of lobbying by the BSA, representing multinational, and substantially closed-source, companies.


Ars Technica covers this too:

The EIF's new definition of openness is also troubling. The text no longer explicitly requires that patents on standards be made available under royalty-free terms. Royalty-free patent grants are important because they ensure that open source implementations of the standard can be created without serious intellectual property impediments. The new draft attempts to address that same issue, but does so poorly—it requires that the standard be possible to implement "under different software development approaches" and indicates that open source software is an example of one such approach.

The ambiguity is potentially problematic. There are some cases where standards are provided under terms that make it technically possible to create open source implementations but with significant impediments that inhibit broad downstream redistribution or make it practically unfeasible. An arrangement like the controversial deal between Microsoft and Novell is arguably an example.


Yes, part of Microsoft's plan is to use patent deals (like that of Microsoft and Novell) to eliminate the Freedom of free software and to make it expensive. Steve Ballmer said at the beginning of 2007: "The deal that we announced at the end of last year with Novell I consider to be very important. It demonstrated clearly the value of intellectual property even in the Open Source world. I would not anticipate that we make a huge additional revenue stream from our Novell deal, but I do think it clearly establishes that Open Source is not free and Open Source will have to respect intellectual property rights of others just as any other competitor will."

The FSFE's founder, Georg Greve, became aware of this EIF subversion and he immediately responded. Deep inside he is not a fan of Microsoft's behaviour; just days ago he wrote: "Unethical, appaling and disgusting: #FamilyGuy corrupted by #Microsoft http://is.gd/4G5QH, a clear violation of http://is.gd/4G5Sh, it seems"

One of our readers gave us input by mail, referring specifically to the news about Skype playing similar tricks with "open source" and interoperability (David Gerard compares it to Helix at Real). According to SJVN, Skype is not going Open Source any time soon. Well, not yet anyway.

The basis for this? Some correspondence between Skype technical support and a Mandriva Linux user (Skype supports generally older versions of Debian, Fedora, openSUSE, and Ubuntu). In it, the French-speaking Skype technical support rep said that it's possible that the final version of Skype for Linux will be open source.

That wasn't much, but it did hint that it might be possible that Skype was going to at least make its Linux client open-source. I decided it was worth my time to look further.

I gave Skype a call in Luxembourg. A Skype public relations spokesperson quickly replied: "We appreciate our user community's enthusiasm and realize this is something they have been wanting for a while. We realize the potential of the open-source community and believe that making Skype for Linux an open source application will help to speed up its development and enhance its compatibility with different versions of Linux. While it is our goal to make Skype for Linux source code available to the community in the near future, we are not at a point to disclose an exact release date yet."


Our reader explains: "It seems Skype is joining the effort to mislead the public about openness and to try cash in on the need for FOSS while not actually providing it." A sort of retraction has just been posted.

Our reader continues as follows: "It would be great if it were true that Skype really released an open source package, but like most things that are too good to be true, it isn't true. The new Skype will be neither open source nor open standards. It will contain a blob and still use that same tired old insecure, proprietary protocol instead of SIP."

He then cites the original story about EIF being subverted by Microsoft and its allies. "This comes at a time where the word, and advantages, of 'open' are under attack even in the EU," he explains. He adds some links for perspective:

"You'd think that with recent news

Der Spiegel: Mossad hacked Syrian computer to uncover nuclear site

"...and with not so recent news

US software 'blew up Russian gas pipeline'The Farewell Dossier[ISN] Interview: Theo de Raadt of OpenBSD

"...and with downright old news

David A. Wheeler’s Page on Countering Trusting Trust through Diverse Double-Compiling (DDC) - Countering Trojan Horse attacks on Compilers

"...and with just plain ancient news

Reflections on Trusting Trust

"...that jobs, economies and sometimes lives are at stake."

This leads to another important issue which is cost/debt, not just death.

We previously wrote about Windows malware at NASA facilities that are located in space [1, 2]. They foolishly relied on Microsoft Windows and another reader of ours wrote about "anti virus software on the ISS" in light of this new interview:

Have you ever had hackers infiltrating the ISS systems?

"The software we use to interface with the ground is just a file transfer back and forth, and it would be a very difficult thing to do. The chances of someone hacking up into the station is pretty much non-existent and it has never happened. Even if they could, the laptops themselves do not have a critical function like life support. There is a set of laptops that do provide the crew with cautions and warnings, but from a daily standpoint the astronauts really don't use them -- the ground monitors everything for them."


"This is 2009," says our reader, "we should all be going round in flying cars, yet even NASA can't protect itself from Microsoft Viruses... From the tone of the questions, it's even considered normal to get 'viruses'."

Even Microsoft is finally admitting the scale of the Windows worms epidemic, soon using "malware" to encourage people to pay more to Microsoft.

Microsoft blames malware on illegally copied software



[...]

Jeff Williams, the principal group program manager for the Microsoft Malware Protection Center claims there is a link between use of illegally copied software and malware infection rates.


They are just trying to upsell "licensed" Windows and charge for it in places where Microsoft does not really mind counterfeiting because it is used as a weapon against GNU/Linux adoption.

Our reader Ryan (fourth one mentioned in this post) sent us a pointer to this new Microsoft patch, which he summarises as "new IE patch patches the last patch." Yes, Microsoft can't even get its patches to work right the first time. It usually means that the code is messy and thus hard to maintain (modify reliably). Ryan also points out that T-Mobile is suffering another major outage following the Sidekick fiasco that we wrote about in:



The next post will look at more distortion of openness, in the context of document formats.

Comments

Recent Techrights' Posts

IBM Culling Workers or Pushing Them Out (So That It's Not Framed as Layoffs), Red Hat Mentioned Repeatedly Only Hours Ago
We all know what "reorg" means in the C-suite
Free Software Foundation Subpoenaed by Serial GPL Infringers
These attacks on software freedom are subsidised by serial GPL infringers
Publicly Posting in Social Control Media About Oneself Makes It Public Information
sheer hypocrisy on privacy is evident in the Debian mailing lists
 
Embrace, Extend, Replace the Original (Or Just Hijack the Word 'Sudo')
First comment? A Microsoft employee
Gemini Links 02/05/2024: Firewall Rules Etiquette and Self Host All The Things
Links for the day
Red Hat/IBM Crybullies, GNOME Foundation Bankruptcy, and Microsoft Moles (Operatives) Inside Debian
reminder of the dangers of Microsoft moles inside Debian
PsyOps 007: Paul Tagliamonte wanted Debian Press Team to have license to kill
Reprinted with permission from disguised.work
IBM Raleigh Layoffs (Home of Red Hat)
The former CEO left the company exactly a month ago
Paul R. Tagliamonte, the Pentagon and backstabbing Jacob Appelbaum, part B
Reprinted with permission from disguised.work
Links 01/05/2024: Surveillance and Hadopi, Russia Clones Wikipedia
Links for the day
Links 01/05/2024: FCC Takes on Illegal Data Sharing, Google Layoffs Expand
Links for the day
Links 01/05/2024: Calendaring, Spring Idleness, and Ads
Links for the day
Paul Tagliamonte & Debian: White House, Pentagon, USDS and anti-RMS mob ringleader
Reprinted with permission from disguised.work
Jacob Appelbaum character assassination was pushed from the White House
Reprinted with permission from disguised.work
Why We Revisit the Jacob Appelbaum Story (Demonised and Punished Behind the Scenes by Pentagon Contractor Inside Debian)
If people who got raped are reporting to Twitter instead of reporting to cops, then there's something deeply flawed
Red Hat's Official Web Site is Promoting Microsoft
we're seeing similar things at Canonical's Ubuntu.com
Enrico Zini & Debian: falsified harassment claims
Reprinted with permission from disguised.work
European Parliament Elections 2024: Daniel Pocock Running as an Independent Candidate
I became aware that Daniel Pocock had decided to enter politics
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, April 30, 2024
IRC logs for Tuesday, April 30, 2024
[Meme] Sometimes Torvalds and RMS Agree on Things
hype around chatbots
[Video] Linus Torvalds on 'Hilarious' AI Hype: "I Hate the Hype" and "I Don't Want to be Part of the Hype", "You Need to Be a Bit Cynical About This Whole Hype Cycle"
Linus Torvalds on LLMs
Colin Watson, Steve McIntyre & Debian, Ubuntu cover-up mission after Frans Pop suicide
Reprinted with permission from disguised.work
Links 30/04/2024: Wireless Carriers Selling Customer Location Data, Facebook Posts Causing Trouble
Links for the day
Frans Pop suicide and Ubuntu grievances
Reprinted with permission from disguised.work
Links 30/04/2024: More Google Layoffs (Wide-Ranging)
Links for the day
Fresh Rumours of Impending Mass Layoffs at IBM Red Hat
"IBM filed a W.A.R.N with the state of North Carolina. That only means one thing."
Workers' Right to Disconnect Won't Matter If Such a Right Isn't Properly Enforced
I was always "on-call" and my main role or function was being "on-call" in case of incidents
Mark Shuttleworth's (MS's) Canonical is Promoting Microsoft This Week (Surveillance Slanted as 'Confidential')
Who runs Canonical these days? Why does Canonical help sell Windows?
A Discussion About Suicides in Science and Technology (Including Debian and the European Patent Office)
In Debian, there is a long history of deaths, suicides, and mysterious disappearances
Federal News Network is Corrupt, It Runs Propaganda Pieces for Microsoft
Federal News Network used to be OK some years ago
What Mark Shuttleworth and Canonical Can to Remedy the Damage Done to Frans Pop's Family
Mr. Shuttleworth and Canonical as a company can at the very least apologise for putting undue pressure
Amnesty International & Debian Day suicides comparison
Reprinted with permission from disguised.work
[Meme] A Way to Get No Real Work Done
Walter White looking at phone: Your changes could not be saved to device
Modern Measures of 'Productivity' Boil Down to Time Wasting and Misguided Measurements/Yardsticks
People are forgetting the value of nature and other human beings
Countries That Beat the United States at RSF's World Press Freedom Index (After US Plunged Some More)
The United States (US) was 17 when these rankings started in 2002
Record Productivity and Preserving People's Past on the Net
We're very productive these days, partly owing to online news slowing down (less time spent on curating Daily Links)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, April 29, 2024
IRC logs for Monday, April 29, 2024
Links 30/04/2024: Malaysian and Russian Governments Crack Down on Journalists
Links for the day
Frans Pop Debian Day suicide, Ubuntu, Google and the DEP-5 machine-readable copyright file
Reprinted with permission from disguised.work
Axel Beckert (ETH Zurich), the mentality of sexual violence on campus
Reprinted with permission from Daniel Pocock
[Meme] Russian Reversal
Mark Shuttleworth: In Soviet Russia's spacecraft... Man exploits peasants
Frans Pop & Debian suicide denial
Reprinted with permission from disguised.work
Hard Evidence Reinforces Suspicion That Mark Shuttleworth May Have Worked Volunteers to Death
Today we start re-publishing articles that contain unaltered E-mails