back

by runningmike·5y ago·view on hn ↗
20 years ago I discovered antivirus software did not detect spyware by design. So never ever trust software that is not FOSS. Use Foss with reproducible builds to be a bit more safe against these by design created weaknesses.
3 comments
Sadly, most people when hearing this will prefer to argue to the death to support their "choice" of ${favorite giant corporate product} and try to tell you "you're just being paranoid". We live in a world where a great many people will accept the most outlandish conspiracy theories as undeniable fact with little to no supporting evidence, but when you try to warn them about real and verifiable concerns, it doesn't matter how much proof there is… You're automatically wrong in their eyes. What's more terrifying than that? Some of those people hold positions of great power in this world.
We've got to get to them before microsoft and google do. Teach Linux in schools and about the importance of FLOSS. In my school in California it was all windows in the 1990's and 2000's.
> In my school in California it was all windows in the 1990's and 2000's.

Yeah, it was that way even before that. Microsoft and Apple got into a "donation war" tryin'a get their corporate garbage into schools back when I was a kid. Looks like Microsoft largely won that war. Hard to fight multiple generations deep corporate brainwashing.

Ah yes, the efficiency of the free market. Where companies with deep pockets get kids hooked on their product early so they can abuse them for the rest of their lives.

In these cases I think administrative oversight of broad and long term benefits to society is important, rather than the more narrow decision of "this choice will benefit next year's budget". Early offers by Microsoft were in a way a trap that kept schools and students paying for decades.

Ah yes, the efficiency of the free market.

Schools in California are government-run, zoned, and compulsory. A complete opposite of the free market.

I suppose I specifically mean free-market thinking applied to government services. This would be a symptom of neoliberalism. [1] Allowing discounts from private corporations to influence government policy, instead of looking at what would be best from a broader perspective.

[1] https://en.wikipedia.org/wiki/Neoliberalism

That purchased operating systems created by the free market.
Eh, I mean, I grew up with Macs at home and school and have definitely seen the light of free/libre software. That said, it took a long time, and it was also largely because I have always been quite conscious of privacy (and to a lesser degree, security). It is still indeed an uphill battle for all the "I have nothing to hide" average people who just act like you're paranoid for even bringing up the subject of privacy.
>tryin'a
Do you have an example of someone who holds that belief? That feels like one of those stereotypes that people are sure exists but actually doesn’t.
> Do you have an example of someone who holds that belief?

Which belief? The belief that corporate spyware devices and software are infinitely superior to anything in the F/L/OSS world? I literally can't escape 'em. Especially in "gamer" circles, I get endlessly hassled by Windows users tryin'a convince me with decades old Steve Ballmer FUD that Linux is inferior junk and a cancer on the software industry, and that I should just switch to Windows.

> That feels like one of those stereotypes that people are sure exists but actually doesn’t.

Sadly, you name a stereotype, and I promise you there's people out there that'll do their best to prove that stereotype true. Cryin' shame, because they're just doin' harm to an entire group of folks who never asked for it, and harming an entire other group that believes false stereotypes are true by reinforcing their wrongness with "proof".

As to the bein' called "paranoid" from my earlier comment, it happens to me frequently when I try to talk to people about backups, network security practices, or passwords, and I'm not alone there. I've had more'n a few discussions with other IT folks who've met frequent resistance to security ideas until after there's been an issue, and then the "people in charge" still generally wanna seek the absolute minimum solution they can get that they think would cover their asses, even if it's nowhere close to enough of a solution for the problem at hand.

>Sadly, you name a stereotype, and I promise you there's people out there that'll do their best to prove that stereotype true.

The point is that it takes more than just a few people to validate a stereotype; otherwise, I could make up any stereotype I want, and by your admission, it would be valid. But that isn't how sterotypes work.

>The point is that it takes more than just a few people to validate a stereotype; otherwise, I could make up any stereotype I want, and by your admission, it would be valid. But that isn't how sterotypes work.

The point wasn't to have a discussion of the semantic definitions of what makes something a stereotype, GP was merely asserting that such people might not actually exist and asking for an example. An example was provided.

An example wasn’t provided. A claim was made. That is not proof. I’m talking about a blog post, a Twitter thread, or something other than mere “trust me they exist” levels of proof.
Yeah, I'm not going to go do your research for you when literally ten seconds of Google search (yes, I do know what "literally" means, and no, I still won't waste the ten seconds doing your search for you if you can't be bothered to put forth even that much effort to support your assertion that I've never come in contact with these stereotypical FUD-spewing corporate product fanbois) can find you countless examples of exactly the type of hateful posts I describe. I've already wasted far more than ten seconds on this and now I feel bad for having even tried to engage in conversation on the topic.

If I cared to dig up actual examples I could link, I've numerous trolls that follow the word "Linux" around gaming forums spouting Ballmer-era anti-Linux FUD at every opportunity, just to begin the endless thread of examples, but the entire mentality sickens me and I'm actually trying to extricate myself from the Troll-pit that keeps wanting to drag me into pointless discussions of why A is better than B, when the true fact is that operating systems are tools to launch and run software. Use the one that lets you get your job or activity done in the way that works best for you and leave other people to their choice of tool if it's workin' to get their activities done for them.

>The point wasn't to have a discussion of the semantic definitions of what makes something a stereotype

That wasn't my point either, so we're all in agreement. We're talking about whether or not the stereotype is valid here, so it would be a good idea to use the term correctly instead of using a made up definition. "There's people out there" doesn't cut it.

One person living up to a stereotype is sadly enough to validate that stereotype in the eyes of those who want to believe that stereotype is true. If a certain group of people want badly enough to believe a stereotype, they'll freakin' track down that one and point them out as proof of their belief.
None of that is proof.
what kinds of examples do you want? A comment that someone bookmarked?

Maybe the Baader Meinhof syndrome will kick in and you'll start noticing Proton mail/vpn users or anybody that took drank some Youtuber's VPN koolaid trying to bargain for impossibly damning evidence about their particular service instead of recognizing the flaw in the entire concept

> 20 years ago I discovered antivirus software did not detect spyware by design...

Can you provide evidence to back up this statement? I'm not disputing your claim outright, I'd just like to see your evidence.

Obviously FOSS software is bug less and totally secure by "design" ...
Every single time I read about how safe and secure FOSS is, I think about this small issue: https://github.com/MrMEEE/bumblebee-Old-and-abbandoned/issue...

Yes, I know it's a decade old, but it's a great example of „open source is better/safer/whatever”.

what about this one[1] (no idea why I even remembered this one);

[1] https://securiteam.com/unixfocus/5hp0s1p75e/

haha wow, that's a rough one!
What about open source spyware?
It would probably have such a bad UX that no one will bother installing it. Problem solved.
That is both painful to read and accurate.
There was recently a big kerfuffle over something kinda like that. Look into recent noise about Audacity audio editor to see how that played out… ;)

Edit: Curious what part of the above statement is unhelpful or inaccurate…

Since the telemetry is opt-in, some people disagree that Audacity should be called "spyware" for including it as an option. From the original pull request:

> Telemetry is strictly optional and disabled by default. No data is shared unless you choose to opt-in and enable telemetry.

https://github.com/audacity/audacity/pull/835

Ars Technica published an article describing the controversy as "massively overblown" and I agree with their analysis:

https://arstechnica.com/gadgets/2021/07/no-open-source-audac...

> Since the telemetry is opt-in, some people disagree that Audacity should be called "spyware" …

I could totally see that I guess… My point was more that the way folks reacted to that would probably be a pretty accurate indicator of how well "open source spyware" would be likely received. ;)

It resulted in a spyware/telemetry free fork. Which is how free software spyware will generally go.

>Curious what part of the above statement is unhelpful or inaccurate…

I have no idea how you think the incident played out. Your post is basically "something like that happened, there were results."

> It resulted in a spyware/telemetry free fork. Which is how free software spyware will generally go.

Pretty much exactly my thinking on the topic. It also resulted in them changing and/or clarifying some of the things they thought were the cause of the complaints. Still led to a fork anyhow.

Not sure audacity telemetry will get you chopped to pieces in your country’s embassy
I sure do hope not, but these days it sometimes seems like too many humans are waiting for any excuse to chop each other to pieces (figuratively and literally).