In my day a framework was a major piece of generic software used to deploy databases, large scale data flow and service millions of reequests per minute.
These days you write a fucking preprocessed CSS file, a few JS helper functions and it's a framework.
Even if the only purpose is to propagate absurdly naive and ineffective ideas?
What, google and apple "fighting" the US Government they've gladly been cooperating with since forever???
Why doesn't Schneier call them out for what these corporations really are, government snitches? What makes Schneier think any of these companies want to do what's "moral"??
This article is one of the most naive pieces I've ever read. It parts on the principle that these companies want to do what's moral, but the government is keeping them from doing it. That is absurd.
Google, Apple and friends have been willingly cooperating with the government in exchange for perks, for immunity against FTC probes and so on. They're NOT gonna "fight" because they have nothing to fight against.
Moral hazard cuts both ways, including giving someone the benefit of the doubt. Opportunity for wrong-doing doesn't confer guilt, it just means we should take the possibility seriously.
Look at it this way: if every tech CEO is complicit without coercion (a strong possibility), the purpose of the article is to take away their shield, and convince the reader that those CEOs are morally culpable for not defending their customers. It's about calling the bluff by proxy.
Any company with over 1k employees probably is. I'm just saying if there are any systemic backdoors in Intel chips, AMD probably doesn't have them because they are 5 - 10% of the market and the gov't doesn't care to jump through hoops to get them implementing whatever backdoor they want.
You know who else cooperates with the NSA? The Linux community. You know, that whole "SELinux" thing? Yeah, that's an NSA project.
Turns out cooperating with the NSA doesn't automatically mean spying on the public, it could instead be hardening crypto security. Which is the NSA's other job, it turns out.
Yes and no better example than DES in which the NSA hardened DES against differential cryptanalysis and then reduced the key size from 128 bits to 54 bits so they could break it. Given the prior actions of the NSA is doesn't seem unbelievable that they would both harden and backdoor linux.
If I hadn't disabled it... which of the dozens of times it's gotten in my way on a new image? Most recently last week, by the way. I disable it because it prevents correct code from running in an already-secure environment. I don't bother beforehand, because I inevitably forget. And then waste ten minutes before I realize I need to turn off the magic "break everything" switch.
In the last seven days, has the fundamental incompatibility between SELinux's design and traditional Unix permissions and tools been suddenly corrected? Has tooling been created to allow us mere mortal sysadmins and engineers to understand and manipulate the byzantine SELinux configuration?
System Apache unable to listen on non-standard port.
> Not possible.
Tell me of a vulnerability on a fully-updated RHEL 6 image running only SSH and a basic Apache configuration serving static files which would be prevented by the stock SELinux configuration.
> You mean labels? No, that's pretty fundamental to SELinux.
Exactly. So my explicit decisions about file permissions must be duplicated. No thanks.
Fucking Google is manipulating these threads, trying to white wash their secret spying deals.
Don't fall for this bullshit, Google has been in the spying business for ages now. They joined the NSA program in 2009 and have been in trouble constantly in every spy scandal there is some google product involved. Wake up already.
If you're referring to the whole wifi thing, tell me, what information do you expect the street view car to be able to pick up in the 10 or so seconds it would have been associated with the AP? Their engineers have basically come out and said that was a fuckup, and I'm inclined to believe them because I find it hard to imagine what use that random data would be.
And to be honest, I'm more likely to believe a Google engineer rather than a namecalling troll who's virulently against them for no good reason.