QuicksearchGoogle the SiteSyndicate This BlogCC Licensesupersized.org |
Entries tagged as free softwareFriday, September 21. 2007How are Microsoft backdoors news?Everyone is talking about the way Windows Update silently updates itself when set to 'notify only' (but not when set to 'off', apparently). Bruce Schneier calls it 'a huge deal'. And it is. But only if you never considered what it really means to run a proprietary OS like Windows. Microsoft can remotely, silently modify your OS any way they choose. Does that scare you? What can you do about it? Only install their patches manually? But you still won't have a clue what those patches do. Not install them at all? The holes in a completely unpatched Windows XP give the entire world remote control over your PC, not just Microsoft. Microsoft can make your computer cooperate with some external entities against you. Do you think that's worse than 'mere' remote vulnerabilities? But how do you know your existing, unpatched OS isn't already betraying you? (It was when it downloaded that update.) How are you going to protect yourself against that? Use a host-based firewall? Your OS can bypass it; it works through Microsoft callbacks and lives on Microsoft sufferance. Use an external firewall? How can it tell the difference between legitimate browser access to tfosorcim.com and software calling home? Running Windows in a tightly locked-down VM is a hard but tractable engineering problem. Running it on bare hardware with Internet access is like keeping a huge tiger susceptible to radio mind control in your living room. You build a Faraday cage around your house and keep a tranquilizer gun in your pocket, and you pat it on the head after it feeds. Eventually the force of habit puts you off your guard and you let your children play with it and pull the tiger's tail. But the tiger only needs to bite your head off once for this to be a losing proposition. Windows only needs to let someone bring down or take over a billion computers worldwide once for all of today's troubles with 10-million-PC botnets to look like really small peanuts. I'll end with an insightful (and obvious) comment from Schneier's blog:
Continue reading "How are Microsoft backdoors news?"
Posted by Dan Armak
in Computers, DRM, FOSS, Microsoft, Security
at
16:46
| Comments (2)
| Trackbacks (0)
Saturday, December 9. 2006The threat of OO.o OpenXML support, take two
Last time I wrote that the threats presented by Novell's OpenXML support plugin for OO.o don't outweigh the benefits of having such support. Even broken and partial support is still better than nothing because it enables companies to do a one-off conversion, with a manual pass if need be, to migrate away from MS Office. And it lets individuals, and companies which aren't ready yet for that migration, read evil OpenXML documents sent by other companies (or your government, in some cases).
Of course OpenXML support in OO.o can also encourage people not to move away from MS Office, because if the metaphorical neighbours' kid who insists on using free software can read the documents your MS Word produces, he won't refuse to fix your computer. (A lucky few even have a government that wants to use open formats.) And it can also make people see OO.o as an inferior MS Office clone, because it can work with MS Office files but not as well as MS Office does itself, and it loses a bit of formatting data every time it opens them. But by that measure we should also condemn projects like Samba and Wine. They too deliver inferior and late implementations of proprietary Microsoft technologies. I haven't heard any cries out of Groklaw that Samba betrays the free software community. (And don't talk to me about pure-Samba no-Windows networks. You could have all the same features on top of NFS or whatever if a tenth of Samba's development effort had gone that way instead. Samba's purpose is Windows compatibility, period.) And what about the existing partial and inferior support for the MS Office .doc .xls etc. formats in OO.o and every other free office suite in existence? What about the FAT and NTFS filesystem support in Linux? I seem to remember PJ being proud of the community for such massive effort and dedication to often thankless projects of reverse engineering. Continue reading "The threat of OO.o OpenXML support, take two"
Posted by Dan Armak
in FOSS, Microsoft
at
11:00
| Comments (6)
| Trackbacks (0)
Defined tags for this entry: compatibility, free software, groklaw, linux, microsoft, novell, odf, office, opendocument, openoffice, openxml
Tuesday, December 5. 2006A "Fork" of OpenOffice.org? What the hell?Groklaw is running a story with the heading, 'Novell "Forking" OpenOffice.org'. PJ writes,
Except that, reading the article and comments and other sources such as Miguel de Icaza's post on the subject, there doesn't seem to be a fork. Not in any conventional sense of the word. Instead there is (or will be) an OO.o plugin that adds OpenXML support. The plugin has a BSD-style license, and if it requires changes to OO.o itself (which it shouldn't), those changes would have to be published under the LGPL (OO.o's license) or a compatible license. Continue reading "A "Fork" of OpenOffice.org? What the hell?"
Posted by Dan Armak
in FOSS, Microsoft
at
19:14
| Comments (0)
| Trackbacks (4)
Defined tags for this entry: free software, groklaw, linux, microsoft, novell, odf, office, opendocument, openoffice, openxml
Friday, November 17. 2006Windows can't be secured, because it lacks package managementI've written here before about some reasons free, openly developed software generally has fewer security issues than proprietary software. However, one would expect Microsoft to beat the odds, since they're capable of funding any development process they want. They can hire world-class programming and QA teams and make sure at least their software contains no bugs or vulnerabilities. Of course we all know that doesn't happen, but it might one day. I'd like to point out that there's another fundamental reason Windows and Office, or any similarly proprietary OS and applications bundle, can't be as secure as a good Linux distribution. Since I used to be a Gentoo Linux packager, I naturally consider package management to be the indispensable quality Windows lacks. Continue reading "Windows can't be secured, because it lacks package management" Saturday, November 4. 2006The Empire strikes back?Everyone's abuzz with the Microsoft-Novell deal. (Groklaw coverage 1 2 3 and surely more to come; you can also pick it up on Slashdot or anywhere else.) It's a trap! They're coming! Ack, they're using patents, run for the trees! So what's the big deal? Microsoft's strongest suit has always been marketing and FUD, rather than technology. This isn't an unexpected development by any stretch of the imagination. The only thing which might be surprising about it is the Novell side of the affair. And I always did think there was something weird about Novell, with their support of mono. Anyway, unless you're a Novell customer who now feels he has to switch, you probably don't really care what Novell do or don't do. Continue reading "The Empire strikes back?" Monday, October 16. 2006NVidia binary driver has security issues. Cat scratches man?There's a new security advisory for the NVidia binary video driver for Linux (story also carried by KernelTrap and slashdot). We immediately hear all the predictable arguments. On one side, that the bug is fixed in the latest (beta, unstable) version of the driver. On the other, that the bug was first reported way back in 2004. Some people just don't seem to grasp the fundamental idea: that widely used, production-quality FOSS is, as a rule, more secure than closed software - even though the latter may be just as good on most other counts, such as stability and features. Continue reading "NVidia binary driver has security issues. Cat scratches man?"
Posted by Dan Armak
in Computers, Security
at
22:19
| Comments (3)
| Trackbacks (2)
Defined tags for this entry: binary driver, free software, full disclosure, gpl, linux, nvidia, programming, security
Saturday, September 23. 2006Our crippled lingua franca (repost)Reposted from my old blog - the old comments are there. Dr. David Brin complains (first and second blog posts) that kids today can't learn the basics of programming in a way that is fun and, above, all, trivially accessible to every computer-owner. There's no lingua franca of modern programming - a language that is both ubiquitous (comes with every PC) and accessible (very simple and suitable to learning basic imperative programming). A storm of comments was generated by the Salon article. Most respondents didn't seem to understand Brin's real points. To be fair, the article itself was rather misleading. In any event, I'm responding here to what Brin wrote in his later replies, the first of which is here, starting with the words "your letter is cogent and intelligent". (Permalinks to individual comments on Blogger don't seem to be working.) Continue reading "Our crippled lingua franca (repost)"
Posted by Dan Armak
in Computers, Education, Microsoft
at
19:41
| Comments (0)
| Trackbacks (0)
Defined tags for this entry: computers, education, empowerment, evil, free software, learning to program, microsoft, programming
(Page 1 of 1, totaling 7 entries)
|
Tagged entriesArchives |

Owner login