I came across an NPR Article this morning discussing malware believed to have been installed by China on many small office / home routers across the United States.

National Cyber Director Harry Coker Jr. alluded to the fact that the US does the exact same thing by advising The House Select Committee on the Chinese Communist Party to “continu[e] operating with confidence, not yielding the initiative, not merely staying on the defensive, but being as strong as the United States has always been”

The vulnerability that was exploited was “outdated Cisco or NetGear devices that were no longer subject to software updates.” These vulnerabilities were present because proprietary equipment and software was no-longer being maintained. This is far less likely to have occurred with routers using FLOSS, like OpenWRT. Such routers regularly receive updates for many years after the original equipment manufacturer has stopped supporting them.

Only with FLOSS hardware, software, and shared standards can nation states have digital sovereignty, compatibility, and security. If all sides are using the same FLOSS standards, then they can host their own services without dependence on a foreign tech sector, they can maintain international compatibility, and any vulnerabilities affect all parties equally. Therefore, it is in the best interest of each party to contribute fixes which ensure their own infrastructure is secure, and simultaneously provide security & functionality to each other party.

You are viewing a single thread.
View all comments
39 points

I’ve always felt that public money should require public code. It makes total sense, unless you are a politician who wants to give favors and earn kickbacks.

permalink
report
reply
19 points
*

Sane way that publicly funded science should be published and freely accessible.

It’s a pipe dream, coz capitalism.

permalink
report
parent
reply
4 points

Capital interests certainly oppose the public domain, but I don’t think it’s a pipe dream, I think it’s a policy change. Everything has swung in favor of private capital for long enough that it’s time for the pendulum to swing back toward the public interest. I think the iron is hot, and right now is the time to start imaging and building better institutions.

permalink
report
parent
reply
2 points

Things are definitely moving in this direction, a number of changes at the federal level are happening in the US. The US and EU have many grant/funding programs where open publishing is a requirement, not an option.

permalink
report
parent
reply
9 points

Absolutely, and I’m glad someone else has thought the exact same thing! “Public money == public code”.

permalink
report
parent
reply
0 points

When the government contracts for IT equipment, it comes with terms about maintenance, updates, and life cycle. It would require a much higher cost, especially in FTE funding, to ensure that open source code is viable and safe before deployment. I’m not implying that there are zero risks or errors with contracts, though they do provide some benefits.

permalink
report
parent
reply
3 points

to ensure that open source code is viable and safe before deployment.

It takes the same amount of time to develop closed source as open source software. So doea validating and certifying it.

Not sure why it should be more expensiv to put the moeny towards a OSS solution.

permalink
report
parent
reply
1 point

Because the government would have to hire the employees directly for this, versus the company that is contracted to do so.

permalink
report
parent
reply

Open Source

!opensource@lemmy.ml

Create post

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

  • Posts must be relevant to the open source ideology
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

Community stats

  • 3.9K

    Monthly active users

  • 1.8K

    Posts

  • 30K

    Comments