Mike Gerwitz's GNU Social Instance
  • Login
  • Public

    • Groups
    • Recent tags

Conversation

Notices

  1. Yale Privacy Lab (privacylab)'s status on Thursday, 19-Jul-2018 17:50:51 UTC Yale Privacy Lab Yale Privacy Lab

    "Software like pcAnywhere is used by system administrators to access and control systems from a remote location to conduct maintenance or upgrade or alter software. But election-management systems and voting machines are supposed to be air-gapped for security reasons - that is, disconnected from the internet and from any other systems that are connected to the internet." #privacy #security

    https://motherboard.vice.com/en_us/article/mb4ezy/top-voting-machine-vendor-admits-it-installed-remote-access-software-on-systems-sold-to-states

    Thursday, 19-Jul-2018 17:50:51 UTC from mastodon.social permalink
    • Mike Gerwitz likes this.
    • Mike Gerwitz (mikegerwitz)'s status on Friday, 20-Jul-2018 02:03:51 UTC Mike Gerwitz Mike Gerwitz
      in reply to
      @privacylab The article also mentions:

      > In 2006, the same period when ES&S says it was still installing pcAnywhere on election systems, [attackers] stole the source code for the pcAnyhere software, though the public didn’t learn of this until years later in 2012 when a hacker posted some of the source code online, forcing Symantec, the distributor of pcAnywhere, to admit that it had been stolen years earlier. Source code is invaluable to [attackers] because it allows them to examine the code to find security flaws they can exploit.

      It's worth noting that access to the source code of the software should have no impact on the security of that software---"security through obscurity", as it is called, is not security. Users should expect that the source code for all software they use has been made publicly available (and is free/libre software) as a precondition for any claims of "security" so that anyone and everyone can audit it, track changes, and improve upon it.
      Friday, 20-Jul-2018 02:03:51 UTC permalink
      Chris Bowdon 🇬🇧🇪🇺, Shellkr and 😸 (。◕‿‿◕。) and 3 others like this.
    • Yale Privacy Lab (privacylab)'s status on Friday, 20-Jul-2018 15:42:45 UTC Yale Privacy Lab Yale Privacy Lab
      in reply to
      • Mike Gerwitz

      @mikegerwitz as we say in teaching materials... Access to source is a prerequisite for - not a guarantee of - software security.

      Friday, 20-Jul-2018 15:42:45 UTC permalink
      Mike Gerwitz likes this.
      Mike Gerwitz repeated this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

Mike Gerwitz's GNU Social Instance is a social network, courtesy of Mike Gerwitz. It runs on GNU social, version 1.2.0-beta4, available under the GNU Affero General Public License.

Creative Commons Attribution-ShareAlike 3.0 Unported All Mike Gerwitz's GNU Social Instance content and data are available under the Creative Commons Attribution-ShareAlike 3.0 Unported license.

Switch to mobile site layout.