Bonum Certa Men Certa

Bristol Council Claims it Chose Microsoft for 'Security'

Bristol coat of arms



Summary: The laughing stock of the security world is said to have been favoured because it bought some expensive certifications

A FEW months ago we wrote about a bizarre dodge from Free software [1, 2], which happened after everything seemed finalised. No proper explanation was given and those involved were questioned about the sudden change of heart (with the suspicion that something nefarious had happened). Only months later, under persistent pressure from the public and from investigative journalists, we finally see this apparent excuse, which goes like this: "It has been considering a number of open source email solutions, but Bristol City Council confirmed to eWEEK Europe UK that none of them have the necessary government security accreditation to enable the council to use them."



Is this the same reasoning which they gave to those companies? Is this an afterthought? An excuse? Being blessed by some expensive process (that carries no liability either) does not actually make the software more secure. It is not as though when Microsoft software gets cracked the certificate plays any role and somehow gives another target to point the finger at. This smells like dishonesty and since the White Houses uses Drupal and GNU/Linux, this claim holds no water, either.

There are many new examples of insecure proprietary software, one of which came last week from Novell on Windows. To quote:

"Unfortunately, a problem has been discovered with this file, which can potentially result in a system crash in certain circumstances.

The problem has been fixed, and the Client software has been re-released as Novell Client 2 SP1 for Windows (IR9a), available at: http://download.novell.com/Download?buildid=rSUN_TTVSf0~

Please remove the (IR9) build, and use the (IR9a) version instead. We regret the inconvenience.

Thank you."


How would certification have resolved such an issue? It wouldn't have. In practice, Microsoft software and proprietary software are not secure, they are just more secretive and expensive.

The tale of Bristol has been followed quite closely by Mark Ballard, who writes about excuses such as the above (excluding all Free software in one fell swoop, pretending that Microsoft is the only secure option) in the following text:

Bristol City Council's open source push has suffered another series of set-backs that point a finger of blame at CESG, the cyber security arm of government intelligence unit GCHQ.

Leaders at the local authority claim that the need for CESG security certification of e-mail systems effectively means the council has no choice but to buy Microsoft.

Senior Cabinet Office IT leaders have been asked to help as Bristol's faltering open source strategy, still showing little progress after a year, highlighted problems besetting the coalition government's own open source policy.


What a sham. As many other governments use Free software quite happily, this concern has little or no validity. It is a good excuse though -- like one an employer uses to reject a candidate for reasons that are not technical/skills-related but qualifications-related.

In other news of interest, "U.K. Liberal Democrats urge open source," but given the story of Bristol it seems like lip service. From the article:

The British government should ensure it owns all software code it pays for and should share that code for free within the public sector, says a policy paper adopted Sept. 20 by the Liberal Democrats party, the minority partner of the two-party ruling coalition forming the United Kingdom's government.

In addition, the paper urges the British government to embrace collaborative software development along the lines of models on display at GitHub, an open source software project hosting website.


Someone should tell the Lib Dems that Bristol rejects British firms that offer Free software in favour of proprietary software from a foreign company with criminal history -- software that the British public overpays for and has no control over.

Comments

Recent Techrights' Posts

This New Determination on a Case Echoes the Modus Operandi of Microsoft's Serial Strangler vs Techrights (Its Online Decision/Judgment Says Truth and Public Interest Defend the Publisher)
Noel Anthony Clarke hopefully has enough money left to pay his victims, which include the publishers
 
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, August 26, 2025
IRC logs for Tuesday, August 26, 2025
Richard Stallman (RMS) Was Right About "Sideloading" in 1996
We now have computers that treat booting GNU/Linux like an act of "Sideloading"
Panama: Windows Down From 97% "Market Share" to Less Than 30%
In 2009, Windows was measured at 97.24% (compared to 62.32% right now or less than 30% if one also counts Android)
The UEFI 9/11 - Part I - Introduction to Impending Catastrophe (Microsoft Preventing People From Booting Non-Windows Systems)
eight-part series
Why Techrights is Slow Today (Bot Floods)
We don't know if those bots are connected to LLMs (we have not checked), but that is a possibility
Slopwatch: DDoS Slop, LinuxBSDos.com Spam, and Slopfarms in Google News, Including webpronews.com
Among the news we also found fakes, albeit not so much today
Links 26/08/2025: "Ballooning Debt" in France and "Transnational Repression in the UK"
Links for the day
Gemini Links 26/08/2025: Listening to Alcest and Google Doing Evil (Users Installing Software is "Sideloading" and Prohibited)
Links for the day
Links 26/08/2025: DNS Tampering and TikTok Layoffs
Links for the day
Microsoft's Windows "Market Share" Overestimated
Microsoft's income sources are shrinking
We Shall See...
My wife and I are hardly the first victims of Brett Wilson LLP
Going Offline
There was life before the Net
The Register MS Has Apparently Shut Down Its Office
It is basically a fake address on the face of it
There Are Also Expectations of IBM Layoffs Very Soon With "Narrative Control."
Some of them mention Red Hat and how IBM failed to achieve anything substantial with that acquisition
After at Least Two Rounds of Mass Layoffs in August Microsoft Said to Have "September Layoff Confirmed - Performance Based"
Those "M5 level meetings" sound plausible
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, August 25, 2025
IRC logs for Monday, August 25, 2025
Slopwatch: Slopfarms All Over Google News and Real News Sites Pushed Out of Visibility
Google News is dying (as a tool of value)
Gemini Links 25/08/2025: Numeric-only VM and Alhena 5.3.0
Links for the day
Links 25/08/2025: ‘Panama Playlists’ and Live Nation/Ticketmaster Suit Aims at Class Action
Links for the day
Gemini Links 25/08/2025: Empathy Towards Autistic People and Old Gadgets
Links for the day
Links 25/08/2025: Datacentres Versus Water Supplies and "The IPv6 Divide"
Links for the day
Links 25/08/2025: Data Breaches, Politics, and Financial Strain
Links for the day
GNU/Linux Distros Ought to Replace Firefox (and Firefox ESR) With Something Like LibreWolf
Perhaps it's come to replace Firefox
Father of Julian Assange Said the US Government Was Trying to Bankrupt WikiLeaks, Now the Assange Family Promotes Fake Currencies
Using the name for bad purposes?
Bailing Out GAFAM, Giving Taxpayers' Money to Failing Companies, and Trying to Outlaw Lawsuits Against Them
What would the late Lincoln have said?
Software Freedom Conservancy (SFC) Inc. Lost 2 Million Dollars Last Year and Its Chief Took a Salary Increase of Almost $6,000
Another year or two like this... and the SFC will be bankrupt [...] Hallmark of mismanagement
The "New Techrights" Turns Two Very Soon
Accomplishing something each year is what's important, not merely "finishing" another year
Gulf Nations Leave Microsoft Behind
How much lower will Microsoft stoop in an effort to raise money from oil-rich lenders?
How to Combat IRC Trolls (in Our Experience)
Today I want to share my experience (or knowledge) of how to deal with IRC trolls
The Register MS Needs to Stop Participating in the "Hey Hi" (AI) Hype, But It Gets Paid to Participate in This Hype
the publisher (The Register MS) wants to have it both ways
Gemini Links 24/08/2025: Living With Your Parents, Zürich Zoo, and Macondo
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, August 24, 2025
IRC logs for Sunday, August 24, 2025