Slashdot Mirror


U.S. Gov't Planning To "Help Us" Secure Computers

BahdKo writes: "CNN reported today in this article that the U.S. government is working out a plan to help protect Cyberspace from attacks by "hackers and terrorists." This plan will include the distribution of government-provided software to help clean up insecure Windows installations. It's hard to picture myself executing government provided software on my workstation (we were supposed to be *increasing* the security of the PC's, right?)"

446 comments

  1. Nice by zapfie · · Score: 1

    One more reason why operating systems should be less bound to a commercial entity and be more like a publicly funded/designed infrastructure.

    --
    slashdot!=valid HTML
    1. Re:Nice by C0deM0nkey · · Score: 1
      At least they got part of it right...

      From the article: "We want to transition the bulk of this work to the vendors," Air Force chief information officer John Gilligan said. "That's not an unreasonable expectation."

    2. Re:Nice by ichimunki · · Score: 1

      Didn't you see the references to the NSA? This means free Linux distros for everybody!!! Woohoo! (oh wait. we have that already don't we?)

      --
      I do not have a signature
  2. Americas Army? by bberg · · Score: 1

    I already installed that patch...

  3. Let's just say by Wolfier · · Score: 1

    I'll not trust them until they install the same thing on their own PC's first.

    1. Re:Let's just say by drDugan · · Score: 2

      that wouldn't be enough for me

      try... open source and I'll compile it myself.
      HA!
      ... like that would happen.

    2. Re:Let's just say by WolfWithoutAClause · · Score: 5, Funny

      Good. So you're not worried about that line 3029 that says:

      if (slashdotId == "Wolfier")
      {
      openBackdoor();
      sendHisDodgyWebAccessesURLsToUncleSam();
      triggerIRSAudit();
      }

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    3. Re:Let's just say by H310iSe · · Score: 2

      right, like i used the NSA group policy templates to secure some Win2k web servers without even a second thought. I knew they'd been widely used and there was nothing on the webserver I'd really care to hide from the Snoops so it wasn't a matter of trust on that level. Besides, things like group policy templates are easy to audit yourself.
      I say so long as their tools are this transparent then bring them on, the more help the better.

      --
      closed minded is as closed minded does
    4. Re:Let's just say by Anonymous Coward · · Score: 0

      One line, eh? So, I take it the government agency responsible is a big fan of the IOCCC?

    5. Re:Let's just say by Isle · · Score: 1

      Why?

      Why do you trust Microsoft more than your own government?
      A government can be changed by the will of people, and exists to do the will of the people (even populism gives people what they think they want).
      A corporation exists to make as many money as possible for their own benifit, that ever benifit that gives to society is a sideeffect.

      If you're so paranoid why do you install binary files from a convicted felon(corporation)? Who knows what those binaries contain.

    6. Re:Let's just say by quantum+bit · · Score: 2, Funny

      Is triggerIRSAudit available as a Perl module?

    7. Re:Let's just say by jejones · · Score: 3, Insightful
      Why do you trust Microsoft more than your own government?
      A government can be changed by the will of people, and exists to do the will of the people (even populism gives people what they think they want).
      A corporation exists to make as many money as possible for their own benifit, that ever benifit that gives to society is a sideeffect.

      I don't trust either of them.

      You say a government can be changed by the will of the people...but at least for a while, incumbents had a better chance of being re-elected in the US Congress than they had in the Supreme Soviet, and the government has a power that, so far at least, even Microsoft doesn't have--they have an army and a police force that can come and take my property and throw me into jail if I don't go along. So far, I have yet to go to jail for not using Windows.

      Besides, what's so great about the will of the people? I like my will better, and in a business transaction, I get to say what I trade my money or goods for; I don't have to go along with what the majority or its alleged representatives decide.

    8. Re:Let's just say by Anonymous Coward · · Score: 0

      Talk about letting the fox into your hen house

    9. Re:Let's just say by Isle · · Score: 1

      Good points, but for the "government" to put you in jail, they need to sue and convict you of a crime. Microsoft can do the very same thing.

      In business transactions you get the same choices as in politics, as only the popular choices are going to stay in business. Monoplies are even directly compareble to the government, it the representatives of the choice most consumers have made. The point is that althought politians are hard to replace, they are easier than businessmen and therefore they are more likely to be interested in your oppion.

    10. Re:Let's just say by Wolfier · · Score: 2

      >Good. So you're not worried about that line
      >3029 that says:
      >if (slashdotId == "Wolfier")
      >{
      > openBackdoor();
      > sendHisDodgyWebAccessesURLsToUncleSam();
      > triggerIRSAudit();
      >}

      What buggy code!! You forgot to

      closeBackdoor();

      before the closing brace!

      Please patch before sending it to me. Thanks in advance.

    11. Re:Let's just say by quantum+bit · · Score: 1

      openBackdoor() calls

      atexit(closeBackdoor);

      so the backdoor stays open as long as the program is running.

    12. Re:Let's just say by Anonymous Coward · · Score: 0

      Yep, that's our government. They just can't keep anything small, even when programming. Is anybody else not suprised they rely completely on global variables?

    13. Re:Let's just say by amitola · · Score: 1

      Not worried at all, since those silly government programmers are comparing pointers to strings, which will almost certainly not work.

      Now, if they had said if(!strcmp(slashdotId, "Wolfier")) .. well, he'd better start looking for receipts for those "business expenses"...

    14. Re:Let's just say by WolfWithoutAClause · · Score: 2
      What buggy code!! You forgot to

      closeBackdoor();

      before the closing brace!

      No they didn't ;-)

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    15. Re:Let's just say by Creepy · · Score: 1

      Depends on the language used.

      In C++, for instance, you can override the == operator and create one that works with strings. This would have to be in their universal headers, since I don't see any #include statements anywhere.

      Some scripting languages take string matching like that, as well (but not Perl or Java - I think it was WinRunner scripts where I've seen this).

      I personally like the special install program, which reduces your 128 bit encryption to a more universal 56 bit and installs the CIA mandated Eavesdrop program listening on port 666 (usurping Doom and mdqs on that port).

  4. go go gadget gov't by kin_korn_karn · · Score: 4, Funny

    It's almost like the US gov't has a list of things techies hate, and they're going down the list and doing each thing, just to piss us all off.

    1. Re: go go gadget gov't by Black+Parrot · · Score: 5, Funny

      > It's almost like the US gov't has a list of things techies hate, and they're going down the list and doing each thing, just to piss us all off.

      If your hypothesis is correct, we can expect to see the gov't eating vegetables pretty soon.

      --
      Sheesh, evil *and* a jerk. -- Jade
    2. Re:go go gadget gov't by goid · · Score: 0

      You mean that isn't their job? Nuts, all this time...

      --
      "Star Wars Moral Number 17: Teddy bears are dangerous in herds."
    3. Re:go go gadget gov't by leucadiadude · · Score: 1

      This just in....

      The US Govt will require all recreational computer users to rtestrict their computer use to the hours of 6:00 A.M to 2:00 P.M. in each time zone.

      No more late night gaming and sleeping in till noon.....

    4. Re:go go gadget gov't by rant-mode-on · · Score: 2, Funny
      • It's almost like the US gov't has a list of things techies hate, and they're going down the list and doing each thing, just to piss us all off.
      Looks like we're stuck with Microsoft then.
    5. Re:go go gadget gov't by Anonymous Coward · · Score: 2, Funny

      Yep, next they're gonna have a shower and parade their girlfriends on TV. FUCK YOU nerdlings! Us Govt in da house.

    6. Re:go go gadget gov't by 0x0d0a · · Score: 2

      Funding the development of Windows software (partly because MS leaves security holes around) with my tax dollars is definitely high on the "annoying" list.

      I say an equal number of dollars be sent to Linux security development.

    7. Re:go go gadget gov't by jmccay · · Score: 2

      Everything I have seen about this seems to indicated you run it once and it tells you about potential security holes. Granted for most techies that is not useful, but for the average layman out there, it is a great things...especially on those Microsoft machines.

      --
      At the next eco-hypocrisy-meeting, count the private jets used to get to the meeting. Should be interesting to see that
  5. NEVER by tiedyejeremy · · Score: 1

    never let it be the governments job do a half-fast :) job of doing something for you when you can do a better job yourself! Keep them out of my computer always!

    --
    Anything you say will be held against you. ... "tits"
  6. who do you trust more? by soellman · · Score: 3, Insightful

    the gov't or micro$oft?

    1. Re:who do you trust more? by Anonymous Coward · · Score: 0

      Carnivore here we come!

    2. Re:who do you trust more? by Anonymous Coward · · Score: 0

      We know what microsoft wants...market domination [and money]. Given that their agenda is obvious, it makes sense to trust them over a government whose intentions aren't clear.

    3. Re:who do you trust more? by jazman_777 · · Score: 1
      the gov't or micro$oft?

      At least Microsoft doesn't have an air force to bomb you.

      --
      Slashdot: Failed Car Analogies. Amateur Lawyering. Anecdote Battles.
    4. Re:who do you trust more? by anthony_dipierro · · Score: 2

      I don't trust either, but I think the government is better at keeping a secret.

    5. Re:who do you trust more? by perljon · · Score: 0

      He does have an aircraft carrier!

      --
      This isn't the sig you are looking for... Carry on...
    6. Re:who do you trust more? by Sojourn7 · · Score: 1

      The .gov for a couple of reasons. Remember, several branches have worked on and paid for many advancments to the Open Source community.

      This being said, if they don't bring it to the table as an open source initative no one I know would be trusting enough to install any .gov software. Especially in a enviroment such as Microsoft provides.

    7. Re:who do you trust more? by Com2Kid · · Score: 1

      At least Microsoft doesn't have an air force to bomb you.

      No, but they are working on amobile infantry

    8. Re:who do you trust more? by Anonymous Coward · · Score: 0

      The answer should be obvious, the gov't will contract the programming out to micro$oft.

    9. Re:who do you trust more? by Anonymous Coward · · Score: 0

      Do your part today! Install C:\Windows\System\Carnivore.dll

    10. Re:who do you trust more? by Rogerborg · · Score: 2
      • who do you trust more, the gov't or micro$oft?

      You're saying there's a difference?

      --
      If you were blocking sigs, you wouldn't have to read this.
    11. Re:who do you trust more? by Chief+Crazy+Chicken · · Score: 1

      It all depends upon which part of the gov't you're talking about, and trust for what purpose. If you're talking about which part can make an operating system more secure, for that purpose, I'd trust the NSA more than Microsoft. Of course, I wouldn't trust them very far when it comes to keyword scanning phonecalls and emails. But that's not what this particular issue is about.

    12. Re:who do you trust more? by GreyPoopon · · Score: 2

      Personally, I think the government should bill M$ for all of their time spent on this....

      --

      GreyPoopon
      --
      Why is it I can write insightful comments but can't come up with a clever signature?

    13. Re:who do you trust more? by Anonymous Coward · · Score: 0

      I can live with the Air Force bombings.

      It's the millions of PR weasels and lawyers that Microsoft has that worry me.

  7. jeez by aitala · · Score: 2, Insightful

    Anyone think its time us techies got together and voted these idiots out of office?

    --
    Eric Aitala
    www.f1m.com
    1. Re:jeez by cford · · Score: 1
      The problem is... you can't vote anyone out of office. You can only vote their opponents in, which effectively pushes them out, but we have no assurances that the opponents will be any more "tech-friendly", or for that matter, "tech-aware" than the incumbents.

      What we should do, is somehow let them (the politicos) know that we constitute a significant voting block. After that, we could distribute surveys on key issues that matter to us, and publish responses like other SIGs do. It probably wouldn't change much, but at least it would let them know that we're paying attention to what they do.

      Another approach would be to put some techies in office. But I can't think of any that would be willing to take those kinds of jobs.

    2. Re:jeez by Tackhead · · Score: 1
      > What we should do, is somehow let them (the politicos) know that we constitute a significant voting block.

      Which would be nice, if we were a significant voting block. Unfortunately, we aren't.

      > Another approach would be to put some techies in office. But I can't think of any that would be willing to take those kinds of jobs.

      Which is the real problem. The only people that want these jobs are power-hungry lawyer types. So we get laws written by power-hungry lawyers for power-hungry lawyers.

      Look on the bright side - if government were as efficient as it could be, every MP3 downloader would be in prison. (On the other hand, every spammer would be a greasy smudge near an automated laser cannon. Lose some, win some.)

    3. Re:jeez by Anonymous Coward · · Score: 0

      yeah and while your at it how about geeting a couple techies in office... oh! yeah why hasn`t anyone posted this?
      http://www.washingtontimes.com/national/200 20716-7 5882632.htm

    4. Re:jeez by xtermz · · Score: 2

      We tried to ... but somebody else got in..

      --


      I lost my concept of community when my community lost all concept of me.
    5. Re:jeez by Anonymous Coward · · Score: 0

      You're going to have to STOP voting Republican then, and I'M going to have to stop voting Libertarian (because Liberty died 9-11-01 and no Libertarian is likely to get into office any time soon)

      Speaking of 9-11, with Bush in office Osama could have saved his efforts. Bush and his Enron/Worldcon/Merc friends are busy destroying America and all it stands for WITHOUT any help from Afghans or expatriate Saudies.

      -steve
      Springfield Fragfest

  8. brilliant by s4m7 · · Score: 1

    If ever the phrase "The blind leading the blind" applied, it sure applies here.

    Is this the new Magic Latern distribution?

    --
    This comment is fully compliant with RFC 527.
    1. Re:brilliant by uncledrax · · Score: 1

      The funny part is the other day I actually did see a blind woman leading another blind person down the street..

      I had to snicker..

      --
      ----- The internet has given everyone the ability to have their voice heard equally as loud.. even if they shouldn't be
    2. Re:brilliant by Anonymous Coward · · Score: 0

      Look at the website [cisecurity.org]. They allready have a tool out. The Unix version is a Perl script that can be easily examined. I'm guessing that the 2000 version is similar. Basically, it's a security scanning script.. looks for unpatched holes, services that aren't normally necessary, etc, and gives your system a score based on what it finds. You can compare this score to other organization's scores, or try to reach a certain score on your own systems. Think of it as a Security 3DMark. As bad as it sounds, it's not really very sinister at all... you may find yourself running it some day.

  9. Secure Linux by barnaclebarnes · · Score: 3, Insightful
    It's hard to picture myself executing government provided software on my workstation (we were supposed to be *increasing* the security of the PC's, right?)"

    Remeber that the government has released security extensions to linux already. so don't be to quick to beat them down. If the software they provide is open and auditable then why not?

    --
    [Please type your sig here.]
    1. Re:Secure Linux by Skuld-Chan · · Score: 1

      Key word here being the gov is talking about a Windows program. On linux source is pretty well audited, but on Windows even if they provide the source how many users at home are going to read it - and understand it?

    2. Re:Secure Linux by Anonymous Coward · · Score: 1, Insightful
      If the software they provide is open and auditable then why not?

      That's a pretty big "if".

      Somehow, I doubt that Ashcroft and friends really have our best interests as a free and open society in mind. What I don't get is why conservatives -- people who claim to cherish their freedoms and despise government interference -- get behind this guy when its obvious that he considers civil rights to be a nuisence to be done away with. Maybe so long as they can buy assault rifles they feel safe, but I'd rather have the right to talk with my lawyer and have an open trial any day.

    3. Re:Secure Linux by Anonymous Coward · · Score: 0

      You mean that waste of 1,000,000 of your tax dollars on a piece-of-shit distribution that is less effective than OpenBSD and jail (total cost to the taxpayer: $0)?

      No thanks. I'll think I'll pass.

    4. Re:Secure Linux by tlh1005 · · Score: 1

      Correct. I'm not saying I'll sign over everything I own to Uncle Sam but I also don't think we ALWAYS have to be skeptical of what they're doing. Yeah I know the govt. does some shady things here and there but there aren't too many of us who don't at some point in time. The govt. IS this powerful body which SHOULD be questioned at times, but afterall it only consist of people like you and me. Whether this whole thing does any good or not remains to be seen but at least they're trying.

    5. Re:Secure Linux by Anonymous Coward · · Score: 0

      It is? Why the hell are 10 year old BIND bugs *still* being found? Why was a bug in Apache allowed to languish for years before being found? I'll tell you why. Linux code is not audited any where near as much as it should be. Or as much as you keep saying that it is. In fact in any cases it's not audited *at* *all*. Repeat after me. "Saying it is so does not make it so." When was the last time you audited all of Linux?

    6. Re:Secure Linux by Anonymous Coward · · Score: 0

      Tell them to send me the source, I'll look it over and compile it for myself. I'll never trust their binaries.

    7. Re:Secure Linux by Anonymous Coward · · Score: 0

      IF (opensource == true)
      THEN { RTFS(); }
      ELSE { rm * }
      ENDIF

    8. Re:Secure Linux by Anonymous Coward · · Score: 0
      Somehow, I doubt that Ashcroft and friends really have our best interests as a free and open society in mind.

      Number one: I didn't see Ashcroft's name anywhere.

      Number two: if every techie on the planet has figured out that unpatched Windows systems are an annoyance, why can't the Gov't?

      Number three: wouldn't the gov't make a much more effective voice for explaining the well known exploits of an OS than a vendor with a record of deception and obfuscation? Who's to say they don't just mean to distribute Windows service packs and home firewalls?

    9. Re:Secure Linux by jazman_777 · · Score: 1, Offtopic
      Key word here being the gov is talking about a Windows program. On linux source is pretty well audited, but on Windows even if they provide the source how many users at home are going to read it - and understand it?

      Absolutely right. I myself am only about 65% of the way through the Linux kernel. When I'm done with version 1.2.4 I'm not sure what to do next. Any ideas?

      --
      Slashdot: Failed Car Analogies. Amateur Lawyering. Anecdote Battles.
    10. Re:Secure Linux by Anonymous Coward · · Score: 0

      Maybe because most "conservatives" judge him based on his actual comments and actions rather than media hype and left wing propaganda designed to "bring him down". If you fully research all the supposed scary stuff attributed to him you find out it is standard stuff done and said by virtually everyone who's ever been in his job. And not really very scary at all, just blown out of proportion, out of context and/or made up comments.

    11. Re:Secure Linux by Anonymous Coward · · Score: 0
      but afterall it only consist of people like you and me.

      How dare you say they're like me? If they were, they'd not be ditching all our civil liberties in favor of a police state where all is monitored and recorded.

      The obvious next step is to prevent audited and passed computers from making connections in either direction with unaudited oned, thereby setting up an increasing number of choke/isolation points.

    12. Re:Secure Linux by junkgrep · · Score: 1

      You're confusing rights libertarians (small "l") and conservatives. Some libertarians are conservatives, but not all conservatives are libertarians. Conservatism isn't always directly about just running around protecting our rights from the government: it's about protecting a certain set of values (which only sometimes, not always, includes protecting certain traditional rights that people claim they have) and maintaining a stable social order. Sometimes this means a larger more intrusive government, sometimes a smaller less intrusive government. Some of the traditional civil rights certainly are imporant to these values, but they aren't the ONLY thing on the table, and they don't always trump what are seen as major threats to the conservative vision of America.

    13. Re:Secure Linux by tlh1005 · · Score: 0

      Lets see,

      Are you human?
      Do you have a brain?
      Do you eat?
      Do you sleep?
      Do you breathe?
      Do you ever make mistakes?

      Unless you are a very intelligent lab rat, I'd say they are "like" you and me. If none of the above listed apply to you I apologize.

    14. Re:Secure Linux by Tackhead · · Score: 5, Insightful
      > Remeber that the government has released security extensions to linux already. so don't be to quick to beat them down. If the software they provide is open and auditable then why not?

      And even if it isn't open, why not? Whether it's designed to be auditable or not, it's gonna be audited. Bigtime.

      NSA has two mandates - 0wn non-Americans' b0x3n, and help us secure our b0x3n against non-Americans. This seems to be part of the latter mandate.

      For those speculating that this isn't an NSA thing to secure your boxes, but is instead a sneaky way to get you to install FBI trojanware - finding proof of such a claim would probably be the greatest prize in hackerdom.

      With that much fame at stake, you don't think every hacker and cracker on the planet isn't gonna be disassembling every last byte of this code, looking for precisely this sort of evidence? Once the binary's released, there'll be no way to put the cat back in the bag once an army of determined reverse-engineers goes over it. With that many eyes, even trojans/bugs in closed-source apps are shallow.

      Our government may be dumb, but they're not that dumb. So odds are very good that this is merely what it claims to be - a quick-and-dirty tool to help secure a system.

      Much as it can be fun to imagine otherwise, sometimes a cigar is just a cigar.

    15. Re:Secure Linux by Anonymous Coward · · Score: 0

      Hrmn, then I guess the long standing bugs in IIS (including a similar bug found in Apache), IE, MSIM, etc mean windows code also isn't audited *at* *all*.

    16. Re:Secure Linux by DaytonCIM · · Score: 1

      Good point. Keeping an open mind is good. However, keeping a skeptical, open-mind is better.

    17. Re:Secure Linux by ZxCv · · Score: 2

      On linux source is pretty well audited, but on Windows even if they provide the source how many users at home are going to read it - and understand it?

      Just because most Windows users won't doesn't mean that all people that must use Windows won't. I guarantee there are plenty of people that would read and understand it that it would provide exactly the same auditing benefits as the Linux version.

      --

      Perl - $Just @when->$you ${thought} s/yn/tax/ &couldn\'t %get $worse;
    18. Re:Secure Linux by Anonymous Coward · · Score: 0
      With that much fame at stake, you don't think every hacker and cracker on the planet isn't gonna be disassembling every last byte of this code, looking for precisely this sort of evidence? Once the binary's released, there'll be no way to put the cat back in the bag once an army of determined reverse-engineers goes over it. With that many eyes, even trojans/bugs in closed-source apps are shallow.
      They'll have to do this in secret, less they be violating the DMCA!!
    19. Re:Secure Linux by Skuld-Chan · · Score: 2

      I'm just saying you can probably be rest assured that no code has made it into the linux kernel that would say - monitor what you do on your computer.

      Bugs are one thing - trojan horses are another.

    20. Re:Secure Linux by DGolden · · Score: 2

      A state where everything is monitored and recorded may not be so bad - provided *everyone*, not just the police/government, has access to the monitors and recordings. See "The Transparent Society" by David Brin, or read Ian M. Banks' Culture novels.

      --
      Choice of masters is not freedom.
    21. Re:Secure Linux by plague3106 · · Score: 1

      Um, no sorry. What i do in my house is my own buisness.

      Lets see you start this ball rolling by installing cameras in your house we can access 24hrs a day 7 days a week.

      Or move to a country that already lacks any concept of privacy.

    22. Re:Secure Linux by Anonymous Coward · · Score: 0

      The govt. IS this powerful body which SHOULD be questioned at times, but afterall it only consist of people like you and me. Are you sure about that last part of the sentence?

    23. Re:Secure Linux by ndogg · · Score: 1

      Any hacker that compiles SELinux first before examining it is an idiot.

      --
      // file: mice.h
      #include "frickin_lasers.h"
    24. Re:Secure Linux by schlach · · Score: 1

      Our government may be dumb, but they're not that dumb. So odds are very good that this is merely what it claims to be - a quick-and-dirty tool to help secure a system.

      Much as it can be fun to imagine otherwise, sometimes a cigar is just a cigar.


      Depends whether you're the type that still looks both ways before crossing a one-way street...

    25. Re:Secure Linux by DGolden · · Score: 2

      Actually, I intend to install open-access cameras in my house. Problem is, I can only afford 1 crappy camera at the moment, not to mention the fact I'm behind a 33.6 modem line. Wait a couple of years.

      Since, where I am (Ireland), camera-mobile-phones are just beginning to hit the stores, it's probable that in a few years everyone will have cameras anyway - camera mobile phones are actually useful, not for the idiotic "face to face" communicators that most western people seem to abhor, but for pointing at *something else*, and saying to your mates "here, take a look at this" - it'll probably alter society significantly, but subtly.

      --
      Choice of masters is not freedom.
  10. hmmm by drDugan · · Score: 3, Interesting

    I wonder if it will be free (either way) and/or open source? I'd bet not.

    1. Re:hmmm by Anonymous Coward · · Score: 0

      Why would they make it open source if it's a security fix? Even assuming they're doing this entirely for the good of the public (slightly suspect), that would just let the neredowells know what had been fixed, and what was still vulnerable...

      Open source isn't always a good idea, it depends entirely on the circumstances.

    2. Re:hmmm by drDugan · · Score: 2

      The only reason I can see for NOT wanting open source fpr any software is for near or long term profit motive, either directly from the software, or from related components using the software. If there are others, I'd like to hear them.

      my opinion: given decompilers, and the expertice in the top tier cracking community, hiding sourcef does not prevent people knowing exactly what software is doing -- especially in such a high profile example.

    3. Re:hmmm by The+Man · · Score: 4, Insightful
      Open source isn't always a good idea, it depends entirely on the circumstances.

      I happen to disagree, but even if I didn't I'd suggest that this is one of the times when having the source code is most important.

      The US federal government is not a trustworthy entity. Various departments within that organisation are known to disregard laws concerning privacy and security and many of these also have institutional goals, official or otherwise, that involve spying on American citizens and others. Therefore a reasonable person would consider binary-only software from the federal government to be untrusted in the same way as an unsolicited mail attachment or unsigned binary files found on arbitrary web or ftp sites. The reasonable and prudent assumption is that such untrusted binaries are malware until proven otherwise.

      If the government wants to convince systems administrators that its security-enhancing software is in fact *not* malware, the best way would be to provide the source code in full. If doing so exposes new vulnerabilities, the government should, before releasing the tools in any form, follow normal vulnerability reporting procedures. If Microsoft or other vendors are unresponsive, the proper procedure includes full disclosure of the vulnerabilities and their fixes. The source code to these tools constitute fixes, and should be released either in coordination with vendors or in the event that vendors are unresponsive. In short, the government should follow the same procedures regarding vulnerability disclosure and dissemination that most other people do.

      Internally, of course, I expect and hope that systems would be patched as soon as possible. Naturally I would patch my own company's systems even before a vendor releases a patch if I initially discovered the problem and its solution. But internal dissemination is a separate matter.

    4. Re:hmmm by Callamon · · Score: 2
      It'll probably be free, but not open-source. I suspect they'll want everyone to run their stuff blindly, saying that to give out the source would make it too easy for virus writers and hackers to get around it...

      I would not be surprised if it starts out as a simple virus scanner, totally benign.. But baloons into a full blown security enforcement tool that would close off ports and such.

      Security violation detected! Disabling FTP port
      Security violation detected! Disabling sendmail (Please use US Gov't approved mail server software such as MS Exchange)
      Security violation detected! Your mail is not housed on a Gov't monitored host. Forwarding all mail folders to FBI.GOV
      Security violation detected: Removing non-commercial software (please see US Gov't website for approved applications)
      (etc...)

    5. Re:hmmm by Anonymous Coward · · Score: 1, Insightful
      If the government wants to convince systems administrators that its security-enhancing software is in fact *not* malware, the best way would be to provide the source code in full. If doing so exposes new vulnerabilities, the government should, before releasing the tools in any form, follow normal vulnerability reporting procedures. If Microsoft or other vendors are unresponsive, the proper procedure includes full disclosure of the vulnerabilities and their fixes.
      We're quite aware of the standard and responsible procedure. Now can you explain why tax dollars should be spent doing this? Why should a government do the bug fixing of a supposedly successful company? Why throw money at a problem when the problem (as described) is closed source, commercial binaries?
    6. Re:hmmm by dsoltesz · · Score: 2
      Okay, I'm not 100% on this, but here's how I believe it works (based on some experience):
      • The gov't can't copyright stuff.
      • The gov't can patent stuff.
      • If the gov't publishes software (as opposed to developing software strictly for in-house use), it has to give the source code to anyone who asks for it (I think this comes from FOIA rules).
      Of course, if the gov't cries "National Security" then all bets are off :-D
  11. Don't trust government provided software? by Anonymous Coward · · Score: 0

    Absolutely. After all, this OS has twice, or three times the amount of bugs posted to Bugtraq as does and Windows system.

    1. Re:Don't trust government provided software? by 0biJon · · Score: 1

      Of course that's cuz nobody cares to deal with all of the bugs in Windows (and they tend to be bigger bugs too)

      --
      ?Who controls the past now, controls the future.
      Who controls the present now controls the past.?
  12. Simpler solution... by Anonymous Coward · · Score: 0

    Force Windows users to get a new Mac! Since BSD is dead, less people will be attacking it (Even though Jobs says there are 3x as many BSD boxes as Linux -- in your face Tux!)

  13. no, not Redundant. Flamebait. by Frothy+Walrus · · Score: 1

    mod this guy down, and let's move on, ok?

  14. What about the Lock Box? by tmasssey · · Score: 3, Funny

    Maybe they could put the Internet in the same lock box they put Social Security in? Doesn't get any safer than that!

  15. Which version? by Theologian · · Score: 1

    So will I be installing the FBI or CIA patch....?
    Decisions, decisions.....

    --

    Crapdot
    News from birds. Stuff that splatters.
    1. Re:Which version? by Skyshadow · · Score: 2

      If you don't trust the government, the terrorists have already won. I know: I saw John Ashcroft say so on Fox News.

      --
      Every year during my review, I just pray the words "slashdot.org" aren't mentioned.
    2. Re:Which version? by Theologian · · Score: 1

      Or the Carnivore and Eschelon satellites went down.....

      --

      Crapdot
      News from birds. Stuff that splatters.
    3. Re:Which version? by Anonymous Coward · · Score: 0

      Most likely the NSA.

    4. Re:Which version? by Anonymous Coward · · Score: 0

      It doesn't matter. They will act like media player and real player on the same system. Get some popcorn, cuz we'll have a serious battle being waged in there.

  16. In other news by Ctrl-Z · · Score: 1

    This just in ... US Government provides patches to Windows users that will disable their Windows operating system and replace it with Linux, in an effort to clean up insecure Windows installations.

    The only setback is said to be the choice of Linux distribution to use.

    --
    www.timcoleman.com is a total waste of your time. Never go there.
    1. Re:In other news by GoatEnigma · · Score: 1

      Yes, that would be great. Then all those extremely intelligent Windows users out there can manage their own linux systems and can leave all their unconfigured daemons running, for a well secured internet.

    2. Re:In other news by jazman_777 · · Score: 1
      This just in ... US Government provides patches to Windows users that will disable their Windows operating system and replace it with Linux, in an effort to clean up insecure Windows installations.

      If it's the gov't doing it, more like this: "President Bush announces Department of Computing Security, focused mainly on securing windows computers" and yet another bloated bureacracy crops up. Worse than a Social Security office are the offices of Computing Security, un-airconditioned and full of computer illiterates with their hardware, waiting for a loser (aka "Government worker/bureaucrat") to install all the relevant patches. All computer security failures are now attributed to "a lack of funding" and Congress, when allocating funds for DCS, adds stuff like "Research for bee-keeping in Arctic climes" and some highway funding.

      --
      Slashdot: Failed Car Analogies. Amateur Lawyering. Anecdote Battles.
  17. Going at it wrong by TheKubrix · · Score: 1

    Why home users? In my experience as a sys admin (and a "home user"!) its mainly companies that spread around viruses and are far more likely to get attacked than the average home user. Lets just hope this doesn't escalate and the government poses "requirements" that your PC must maintain....... :\

    1. Re:Going at it wrong by Anonymous Coward · · Score: 0

      your an idiot. and you wonder why your a sysadmin.

  18. Control by Anonymous Coward · · Score: 0

    Isn't this one step closer to having parts of the OS controled by Big Brother? What next? Only approved programs will be allowed to be installed?

    1. Re:Control by Anonymous Coward · · Score: 0

      > Only approved programs will be allowed to be
      > installed?
      >
      Oh, you mean like Palladium under the guise of "Digital Rights Management"? You know, they might actually mean DRM...just in a very different way than you do. And given, that this initiative comes from the very company, who strangely enough got off *exceptionally lightly* in the face of grave judicial adversity and that said company coincidentally owns most people's data one way or another, it should not come as a surprise that the government now takes an active part in the "securing" of said company's main product.
      Coincidentally just as "Hackers" get life in prison and kid's games are now "Good Guys vs. Hacker". And coincidentally just as proposals are floating around to create the ADR (American Democratic Republic), complete with citizen informants and other wonderful Errungenschaften. Bush - Er lebe hoch, hoch, hoch!

  19. I demand source code by Anonymous Coward · · Score: 0

    Or I will help disassemble

  20. really? by mike77 · · Score: 1
    who wants to bet that this patch gives the federal gov't a "backdoor" into all our files in the interest of national security...?

    nope, not a troll, just paranoid about my constitutional rights is all...

    I know one puppy who ain't installing that little patch...

    --

    --Keeping the flame wars alive, one post at a time

    1. Re:really? by Anonymous Coward · · Score: 0

      Paranoid is correct. Who here doesn't think such a "patch" won't be disected 20 different ways by the tech community.

      The government would have to be stupider than even the government is (or much smarter than it could possibly be) to put a backdoor in.

    2. Re:really? by mike77 · · Score: 1

      right, but how many people won't think to look or dissect it...
      It's the computer illiterate that worries me here...

      --

      --Keeping the flame wars alive, one post at a time

    3. Re:really? by Anonymous Coward · · Score: 0

      Since when does acting paranoid and throwing around jargon like "backdoor" constitute trolling on Slashdot?

    4. Re:really? by Anonymous Coward · · Score: 0

      I don't want them checking out my 5,000 mp3's, tons of DivX movies, anarcist cookbook, DeCSS code, and everything else that is illegal on my computer. It's like going to the police when you are high on weed, you just don't do it.

    5. Re:really? by Anonymous Coward · · Score: 0

      paanoid? not only do they want to control you and your computer. now their going to be able to find out who all you geeks are that wont conform...read this...
      http://www.washingtontimes.com/national/2 0020716-7 5882632.htm

    6. Re:really? by DragonTHC · · Score: 1

      the NSA already has backdoors into any pc on the planet. That's what they do.

      --
      They're using their grammar skills there.
  21. Silicon, Gas, and Credit? by absterge · · Score: 1

    The effort has brought together some of the biggest names in business, including computer chipmaker Intel Corp., Chevron and Visa -- part of the group that helped create the standards and is encouraging their use.

    So, these three mega-corps (among others. [like who]) are providing the USGov. with recommendations on how to secure W2K? Huh?

    We can be sure that Intel, Chevron, and Visa are making recommendations that keep their own corporate goals at heart.

    --
    Try my nuts to your fist style!
  22. Not Likely... by gdyas · · Score: 5, Insightful

    Now, the general populus isn't paranoid about their gov't, but even so most people will balk at the gov't saying, "Here's some nice friendly software courtesy of Uncle Sam that we'd like EVERYONE to run on their computer. It, um, looks for flaws 'n stuff."

    For myself, and I assume most of the geeks here, I'd want to read every single line of any code given to me to run by the gov't, compile it myself, and run it. Love your country, yes. Trust your country, never.

    --

    The only tool you've got against psychosis is experience.

    1. Re:Not Likely... by jhines · · Score: 2

      It certainly is a gaunlet tossed at the community, in that if they only release a binary, it is going to be one of the most reversed engineered in history.

      Given the relative success that NSA SE Linux has had to date, yes making the tool open source would only benefit everyone.

    2. Re:Not Likely... by Anonymous Coward · · Score: 0
      are you some God-hating, anti-American, anti-Capitalist, communist-terrorist?? fuck Y0U!

      If you question the actions of your government, you're only helping the terrorists. Don't you watch the O'Reilly Factor?

    3. Re:Not Likely... by Anonymous Coward · · Score: 0

      Even though it's been riddled with security holes? Oh yeah, not if you patch, and patch and patch. And only then if you're paying attention, which has been shown often is far too inoften. More Linux user head in the sand.

    4. Re:Not Likely... by pjt48108 · · Score: 0, Redundant

      To quote Reagen (re.: missile agreements with the Soviets): "TRUST, but VERIFY."

      --
      Mmmmmm... Bold, yet refreshing!
    5. Re:Not Likely... by quantaman · · Score: 3, Funny

      I'd want to read every single line of any code given to me to run by the gov't

      Actually I'd be content to just let you read it and wait for anything suspicious to pop up on /. :)

      --
      I stole this Sig
    6. Re:Not Likely... by Anonymous Coward · · Score: 0

      Um personally, I think if you're trusting enough to run a Microsoft OS on your machine, then you probably shouldn't have many worries about running government software on your machine.

    7. Re:Not Likely... by jazman_777 · · Score: 2, Insightful
      Love your country, yes. Trust your country, never.

      Love your country, keep your powder dry.

      --
      Slashdot: Failed Car Analogies. Amateur Lawyering. Anecdote Battles.
    8. Re:Not Likely... by Liora · · Score: 2

      What's even more unlikely is the idea that they'd let you read it and then exploit every bug you can find. The whole point is that it would make things secure. They know it's not going to be perfect, hardly anything released these days is at least for a few months. Heck, Bill might offer to find some folks to write it himself, and maybe get out of some of that little antitrust trouble...

      --
      Liora
    9. Re:Not Likely... by ffatTony · · Score: 2

      are you some God-hating, anti-American, anti-Capitalist, communist-terrorist?? fuck Y0U!

      What? No of course not! Well, actually... Yes.

  23. who will protect us from the protectors by Anonymous Coward · · Score: 0
    and who will protect us from Big Brother, er, the Gubmint? It isn't enough that Carnivore, et al are monitoring us. There will probably eventually be NSA mandated trojans installed on all 'secure' Windows installations.

    Besides, isn't it Microsoft's job to make Windows secure? How about making them rewrite their EULLA to address security of user data etc. That should be the first step.

  24. no thanks I'll just drink bleach by gelfling · · Score: 2, Flamebait

    "The effort has brought together some of the biggest names in business, including computer chipmaker Intel Corp., Chevron and Visa -- part of the group that helped create the standards and is encouraging their use"

    Holy fucking shit. I didn't know gas companies, credit card companies, probably some banks and insurance companies too care so much of a shit about my cybersecurity they're willing to coopt with the Pentagon to do it.

    And what have these nimbots come up with. oooooh yeaaahhhhhh! some hardening instructions for Windows code.

    Can I get a Wit-nesss!

    Honestly this is muy lame-o. What kind of MS or other vendor driven crap are they going to 'certify'???? These wankers lead the known universe in their utter fucking indifference to what you or I want or need, so what do you think they're going to accomplish, aside of course for some more lobbying opportunities.

    Boo-Yah,

  25. All gov't-developed software is public domain... by Rayonic · · Score: 4, Interesting

    But does that necessarily mean that the source is too? I think it does, but I'm just wildly guessing now.

  26. Why is "help us" in quotes? by AintTooProudToBeg · · Score: 2, Insightful

    Why is it cool to think that the United States Government is out to spy on everyone and in general fuck things up?

    Slashdot views are so far to the left that they've wrapped around to those of the ultra right Montana Freemen.

    1. Re:Why is "help us" in quotes? by Anonymous Coward · · Score: 0

      help us is in quotes because. think about it.

      what are the great lies:

      the check is in the mail.

      im from the govt, Im here to help

      they are incapable of being actually helpful

    2. Re:Why is "help us" in quotes? by tiedyejeremy · · Score: 1

      Because this is reality. My views were never conspiracy oriented 'til my place of business was raided by the feds - they took what they wanted and have levied NO allegations. If we want copies of our documents, we have to go to their offices and make copies with the copier we provide. 250 boxes to sift and the only reason we can conceive is a personality confict between two inspectors. ...and they work for us.

      --
      Anything you say will be held against you. ... "tits"
    3. Re:Why is "help us" in quotes? by roachmotel3 · · Score: 2, Interesting

      You know, investment funds always say "Past performance is not an indicator of future performance", but they know you make your decision based on how well the fund has done over the past 10 years.

      Trusting the government is the same way. Let's look at their security record over the past few years:

      1. The Clipper Chip
      2. Carnivore
      3. Expanded rights for home surveillance

      There are more, and I'm sure if we all sit down we can think of a list that's truly huge. But, looking at past performance, what am I to extrapolate about this move? The government should have no real interest in my personal PC. There hasn't been a large public outcry for the government to get involved in securing end-user's desktops. So, it seems pretty clear to me that this is a way for the government to get a foothold in every windows PC inside the US. No one has asked for this, but it's an easy way for them to get in and make us think it's for our own good.

      Besides, it's not always about what their intentions are right now. Social Security numbers were never invented to be completely unique identifiers used for everything from customer numbers at Jiffy Lube to student ID's at colleges, but that's how it turned out. Why? Because power corrupts. If the government has software on every PC in the US, and there is another terrorist attack, how long before people cry out to add some backdoors that allow good old uncle sam to read your email?

      It's all in the interest of national security, and anyone who opposes it must be a terrorist. Any logical american who has nothing to hide wouldn't mind, right? We're trying to look out for everyone else? Granted, I doubt that Uncle Same will say "You know, once the threat is over, we'll get rid of this monitoring, because we don't need it anymore."

      Instead of being so quick to dismiss the protectors of liberty as being right-wing nutcases, maybe you should read some history and try to think of their motives. Not everyone in the government is a saint with your best interests in mind.

    4. Re:Why is "help us" in quotes? by Bearpaw · · Score: 3, Insightful
      Why is it cool to think that the United States Government is out to spy on everyone and in general fuck things up?

      [sarcasm] Yeah! I mean, just because the US govt has a history of spying on people and fucking things up is no reason to get all suspicious. [/sarcasm]

      It's not "cool" to be suspicious of one's government. It's every citizen's responsibility to question the govt's motives and actions. Trusting the US government is the most unAmerican thing a US citizen can do. The system was intentionally not set up to work on trust.

    5. Re: Why is "help us" in quotes? by Black+Parrot · · Score: 4, Insightful

      > Why is it cool to think that the United States Government is out to spy on everyone and in general fuck things up?

      It isn't "cool", it's a simple recognition of the facts. Did you miss the news last month when it came out that the FBI had a 2^16 page file on one of CA's uni presidents in the 70's, simply because they didn't think he was "tough enough" on liberal professors? Or the earlier revelation that they had a whopping big file on that Dangerous Enemy of the Republic, Albert Einstein?

      These people have been at it so long that their primary motive for spying now is that they've forgotten how else to act.

      > Slashdot views are so far to the left that they've wrapped around to those of the ultra right Montana Freemen.

      What has Left-Right got to do with it? Not wanting to be spied on is "normal".

      --
      Sheesh, evil *and* a jerk. -- Jade
    6. Re:Why is "help us" in quotes? by MrResistor · · Score: 2

      Why is it cool to think that the United States Government is out to spy on everyone and in general fuck things up?

      Because the current administration is doing everything it can to prove it.

      --
      Under capitalism man exploits man. Under communism it's the other way around.
    7. Re: Why is "help us" in quotes? by Anonymous Coward · · Score: 0

      Oh dear god no! They actually COMPILED information? They INVESTIGATED someone? Those bastards!
      Who do they think they are? The Federal Buerau of INVESTIGATION? Oh wait, that is who they are.

      Jeebus. It's not like they tied the guy to a chair and beat him with rubber hoses.

    8. Re:Why is "help us" in quotes? by SquadBoy · · Score: 3, Insightful

      Becuase the government has a long proud history of fucking us over at every turn. Think about it the whole point when the founding fathers set up the government was to provide for those things that are needed but to give the governement as little power as possible. Ever since then they have been trying to get more. The kind of men who run for office are the kind who want to control *everything*.

      I do not agree with the nuts who say that Bush/Ashcroft wanted 9/11 to happen but I do think that they where *very* excited about the chances it opened for them to tighten control of society. This is the man who said during the campaign that "we need limits on speech".

      http://www.lp.org/

      http://www.lp.org/press/archive.php?function=vie w& record=593

      --

      Cypherpunks: Civil Liberty Through Complex Mathematics. Those who live by the sword die by the arrow.
    9. Re: Why is "help us" in quotes? by Anonymous Coward · · Score: 0

      Or the earlier revelation that they had a whopping big file on that Dangerous Enemy of the Republic, Albert Einstein?

      I'm no apologist of the Feds by any stretch of the imagination, but why would that be news? He was working on the ATOMIC BOMB! Guess what? The FBI investigates everyone that needs to get security clearance. I think atomic secrets would qualify.

      That said, anyone who installs this software is crazy.

    10. Re: Why is "help us" in quotes? by Planesdragon · · Score: 2

      t isn't "cool", it's a simple recognition of the facts. Did you miss the news last month when it came out that the FBI had a 2^16 page file on one of CA's uni presidents in the 70's, simply because they didn't think he was "tough enough" on liberal professors? Or the earlier revelation that they had a whopping big file on that Dangerous Enemy of the Republic, Albert Einstein?

      *gasp!* You mean that the FBI investigates people? Or that they actually *know* what *famous people* did?

      Gee, what a shock! How dare they do their job, when they're supposed to automatically know who the "bad guys" are and go after them and them only!

      (Yes, I know the FBI used its investigations as a form of intimidation; but that doesn't mean they shouldn't as a group still do it, just that the folks in charge need to be smacked & fired.)

      What has Left-Right got to do with it? Not wanting to be spied on is "normal".

      No, it isn't. No one "normal" stands next to the ATM so the camera doesn't capture your picture, or changes telephone lines "because this might be tapped", or routinely spends hours searching their PC for "spyware."

      "Normal" people simply don't care, as they know it happens. They only care when it wrongly happens to them (i.e., their nude spyware photos are slapped on the web), and that's the only tiem they should.

    11. Re: Why is "help us" in quotes? by Anonymous Coward · · Score: 0

      Or the earlier revelation that they had a whopping big file on that Dangerous Enemy of the Republic, Albert Einstein?

      They kept a file on one of the most famous physicists of the 20th century? You don't say. Why on earth would they want to do that? It's not like he was some wacko german scientist who could up and leave and take all his knowledge to some foreign country to help them build atomic weapons right? Next I suppose you're going to tell me they had files on Al Capone and Marilyn Monroe.

    12. Re: Why is "help us" in quotes? by Skyshadow · · Score: 2

      Er, Einstein was never a member of the Manhattan Project. If you review the file, they seemed mostly concerned that he was jewish and therefore not to be trusted.

      --
      Every year during my review, I just pray the words "slashdot.org" aren't mentioned.
    13. Re: Why is "help us" in quotes? by Anonymous Coward · · Score: 0

      "Normal" people simply don't care, as they know it happens. They only care when it wrongly happens to them (i.e., their nude spyware photos are slapped on the web), and that's the only time they should.

      But when something bad happens to these people, they can't do anything about it because it already happened. I like to take precautions, and I try try to make sure that nothing bad happens.

      Just because "normal" people don't care about privacy, doesn't mean that I shouldn't either.

    14. Re:Why is "help us" in quotes? by jazman_777 · · Score: 1
      Why is it cool to think that the United States Government is out to spy on everyone and in general fuck things up?

      Because it's true?

      --
      Slashdot: Failed Car Analogies. Amateur Lawyering. Anecdote Battles.
    15. Re: Why is "help us" in quotes? by SirSlud · · Score: 2

      > They only care when it wrongly happens to them (i.e., their nude spyware photos are slapped on the web), and that's the only time they should . (emphasis mine - ss).

      I hope you never go into the field of project management. I can see it now:

      "Well, gee, the best way to go about the problem is to agree that it will happen. Then, when it does, we'll figure out what we should have done before to ensure it doesn't happen!"

      Whats the matter? Ripped out the page in your dictionary that carries the defintion of "proactivism"?

      --
      "Old man yells at systemd"
    16. Re:Why is "help us" in quotes? by Anonymous Coward · · Score: 0
      Why is it cool to think that the United States Government is out to spy on everyone and in general fuck things up?

      Slashdot views are so far to the left that they've wrapped around to those of the ultra right Montana Freemen.

      "The price of liberty is eternal vigilance."

      -- Thomas Jefferson (the fucking lefty bastard!)

    17. Re: Why is "help us" in quotes? by goid · · Score: 1

      I think you are overreacting to FBI files. They have files on me, so I guess that makes me an enemy of the state too, right?

      Hardly. The reason is that I worked for the same people that Albert Einstein did, and they check _everything_ about _everybody_.

      Hmmm... I hope it's OK if I post on /. :)

      --
      "Star Wars Moral Number 17: Teddy bears are dangerous in herds."
    18. Re: Why is "help us" in quotes? by Anonymous Coward · · Score: 0

      That's not the FBI's job. The DoD has that responsibility... So there

    19. Re: Why is "help us" in quotes? by ryman · · Score: 1

      You mean that the FBI investigates people...How dare they do their job...

      Good gosh, you think the FBI has the right to investigate anyone, on any whim? Maybe I've exaggerated your point, but this is ridiculous. Ever heard of just cause or reason to suspect? And no one said they're "pre-cogs" or anything like that; they just need to have their suspicion based on real evidence.

      No one "normal" stands next to the ATM so the camera doesn't capture your picture...or routinely spends hours searching their PC for "spyware."

      Ummmm...every used Ad-Aware before? If you haven't, I'm surprised you found your way to a (usually) intelligent site like Slashdot. Do you know where all the data programs like Cydoor collect goes? If you don't, you should be concerned.

      "Normal" people simply don't care, as they know it happens. They only care when it wrongly happens to them...and that's the only time (sic) they should.

      Geez, it's never your problem until it happens to you is it? "We're all somebody else to somebody else" seems to apply pretty well here, so I'll leave well enough alone...

      --
      "We are far too easily pleased." --C.S. Lewis
    20. Re: Why is "help us" in quotes? by Planesdragon · · Score: 2

      I hope you never go into the field of project management.

      I hope you don't either.

      "No, you can't have my corporate records! Those are trade secrets, and to divulge them to my employer would contitute a violation of my privacy!"

      To restate: you have no privacy from the government. You have no privacy in a public place. You have no privacy at your job. You have *NO* privacy on the interent.

      The government (specifically, the FBI & other internal police forces) has the duty of looking at all the places where we don't have privacy, and finding criminals and dangerous citizens. The *only* time this becomes a problem is when it's abused or used to wrongfully accuse someone.

      If you want, take out "to them" from the line you quoted. The meaning is more clear then, when applied as a general principle.

    21. Re:Why is "help us" in quotes? by Anonymous Coward · · Score: 0

      why? gee i dunno... err, maybe because of things like this...
      http://www.washingtontimes.com/national/2 0020716-7 5882632.htm
      i mean why would "they" care about millions of people who use computers that are able to transmit, print or chat openly on topics that would be contrary to thier point of view or agenda?
      case in point: world govt., cashless society, chip ID implant, GPS tracking (in cars, cellphones, clothes or chip implant), cameras with face recognition software. all of these things are about control and power. human nature proves no matter how noble mans intentions are someone else will come along and take advantage of what started as a good thing is now being used for evil.

      man has also proven that he repeats history but doesn`t learn from it.... the article in the washington times sounds like a page taken from hitler himself...
      so why don`t you help to keep this stuff from becoming a reality instead of calling others paranoid. better to be safe than sorry...

    22. Re: Why is "help us" in quotes? by SirSlud · · Score: 2

      Whoa now, I'm not in any way condoning that private companies have any right to privacy.

      Dunno where you picked that up from. I dont even think corperations should have the same rights as people due to their inherent size and weight on our pysical and social world, but thats another thread. I'm fairly anti-corperate, and I'm also not the staunchest advocate of privacy to be found here.

      The internet, to me, seems like the phone lines, and for what it's worth, I think that privacy over the phone (without a warrant) should be something we all have. No, its not a god given right, but its still something I think we should have and that I'd vote for. The internet is just like the phone .. a way of communicating betwixt parties from the privacy of our own home.

      My post was an attempt to point out how we generally dont mind seeing our priviledges (much better word than right, because it is surely something people should only have if, at large in a preagreed majority, we dont abuse it) eroded until it actually affects us. Privacy in itself is important because it prevents us from being persucuted by others for actions or opinions that may be subject to widespread public mob mentality.

      The internet, as a poorly defined public utility, has the ability to facilitate private peer-to-peer communication not intended for the public's consumption. Just because my phone line goes over public property eventually doesn't mean somebody should be able to intercept it. While phones were primarily intended for private conversion, the Internet supports private conversation .. and as it ties in to how we've historically treated the phone system, I believe those types of communications should not be subject to groundless evesdropping.

      So I'm interested in hearing what you think about this .. do you think the phone system should support a moderate amount of privacy in which wiretapping should only be conducted after authorities can provide grounds for the tap? (I understand that this is not the case anymore in the USA as of mildly recently?)

      And if so, how is that conversation eventually travelling over what is effectively public property (a park, say, where I am free to look, listen, etc) different from an internet protocal designed strictly for private peer to peer use?

      I think eventually this will become an issue, and some lines will be drawn in terms of low level technological conditions in which data is considered public or private. But thats just my guess once the social significance and nuances of the Internet become more familliar to the public just as the public has changed their opinion regarding other technologies (say, cell phones in cars, or cigarettes) once the neccessary education becomes embedded in the social conciousness?

      I'm curious to hear under what terms and for what reasons you consider the entire Internet infrastructure to be, essentially, a public park where anything you do can be seen by those who enter ...

      --
      "Old man yells at systemd"
    23. Re: Why is "help us" in quotes? by Anonymous Coward · · Score: 0

      they seemed mostly concerned that he was jewish and therefore not to be trusted.

      Being that Roosevelt and Truman were president at the time (especially Roosevelt), that is plausible. However, I need a link to confirm that.

    24. Re:Why is "help us" in quotes? by ElectricRook · · Score: 0, Flamebait
      Why is it cool to think that the United States Government is out to spy on everyone and in general fuck things up?

      I guess you did not believe the story about the woman who was sexually harased by a govenor who became president. When she complained, her husband lost his job (worked for a company whose CEO was a friend of said prez). They got audited by the IRS on their combined $18K income. They got smeared by the president's sexual harassment defense lawyer and the un-biased press.

      Now why would we want to limit the power of these people?

      --
      - High Tech workers, please say NO to Union Carpenters, their Union sees fit to control our compensation.
    25. Re: Why is "help us" in quotes? by Planesdragon · · Score: 2

      Good gosh, you think the FBI has the right to investigate anyone, on any whim?

      Yes. As long as they don't have anything better do to, and as long as they don't intimidate or obstruct the life of those that they don't have reasonable suspicion of.

      The FBI is more than welcome to know that I was in a "medivalist government" group, that my best friend from high school made noises about militias, and that my credit rating sucks.

      Geez, it's never your problem until it happens to you is it?

      (Actually it is--and I've gotten flamed for making is such.) It's not my problem until I make it mine, or it happens to me. And it's not *a* problem until it happens, either.

    26. Re:Why is "help us" in quotes? by Darby · · Score: 2

      I do not agree with the nuts who say that Bush/Ashcroft wanted 9/11 to happen but I do think that they where *very* excited about the chances it opened for them to tighten control of society.

      Wanted it is one thing, but the fact is that they knew it was coming and let it happen.
      Before you just blow this off and call me a nut look at the facts.
      Germany, Israel, Egypt and several other nations found out about it *beforehand* and warned them in detail. Germany, in fact, caught some of the terrorist conspirators and told our government the names of all of the hijackers, their targets and weapons, and the approximate date of the attacks.
      This was printed in German newspapers. I was in Europe when the attacks happened and saw this myself. The simple fact is that people do not want to believe that the president of the US would allow thousands of his citizens to be murdered to allow an insane power grab, but it is a fact.

      Almost every thing he has done as president has either taken freedom and privacy from Americans, or given power and privacy to the government. You are aware that he raped the Freedom of Information Act, aren't you? How is a free society supposed to function when the government's actions can *never* be scrutinized by the people who are supposed to select that government based on those same actions? It can't. Of course, that is the main goal of the Bush administration. To destroy America as a free society.

    27. Re: Why is "help us" in quotes? by Planesdragon · · Score: 2

      do you think the phone system should support a moderate amount of privacy in which wiretapping should only be conducted after authorities can provide grounds for the tap? (I understand that this is not the case anymore in the USA as of mildly recently?)

      Right now, tonight, I think that the phone system *should* be pseudo-private. But I also think that Keepers of the Peace (military, police, *not* anyone who's not paid by my taxes) should be able to listen in. I think an automatic system to locate probable suspects is a viable alternative to random wiretaps.

      I'm curious to hear under what terms and for what reasons you consider the entire Internet infrastructure to be, essentially, a public park where anything you do can be seen by those who enter ...

      Because that's what it essentially is. Or, rather, that's what it *should* be. The darn thing was originally a trust-based peer-to-peer network, and now it's a trustless client/server finnagle that doesn't realize that nothing's really changed about the 'net, we just stopped using a lot of it.

      There are three reasons I think that it should be considered public space.

      1: Every event that happens is logged. With a warrant, I could open up mail.nycap.rr.com and find the mail logs for everyone around me. I suspect that AOL has a similar cache of AIM messages, and that most other packet tranmissions are logged.

      2: Every event uses someone else's property. The entire 'net is built on people running connections between points at varying speeds, and then agreeing to let other connections connect to theirs for concurrencty.

      3: Resources are shared amongst all. If I start sucking bandwidth or doing other nasty things, I can cause problems for everyone nearby.

      While I'm all for allowing people to press tort claims (civl suits) for person-to-person and corporation-to-person suits of unwarranted invasion of privacy, I think the 'net would work best if everyone remembered that privacy is *not* something guaranteed on the 'net, and the only thing keeping them "private" is the relative PITA of tracking someone down.

      (The best examples of warranted privacy violation are tracking down a mischevious message to a community's boards, and keeping SPAM out.)

    28. Re: Why is "help us" in quotes? by SirSlud · · Score: 2

      >I think an automatic system to locate probable suspects is a viable alternative to random wiretaps.

      Automatic system? Jebus. (Pardon using Him in vain :) .. really? Even if, say, Christianity, in the distant future, becomes seen as an evil and unacceptable lifestyle in the eye of the public, to turn the tables? I'm not trying to discredit your faith, but its important to use something you view as important and ultimately non-bad in order to get you to think about it from a personal standpoint? You'd feel okay having to take what I believe is an acceptable ideology off of the Internet?

      Please don't counter that it's not possible. Take something you view as harmless, even personally neccessary, imagine the public wanting to lynch somebody for it, and then allow authorities to flag you via a computer?

      I agree with the fact that the Internet definately started as something in which privacy was not inherent, but I attribute that more to the fact that the thought of a right to privacy on the phone probably didn't pop into the heads of the engineer that developed the telephone either - its only when something becomes a fairly widespread form of communication upon which sensitive information is sent, iare there any reasons to begin considering the implications of access to privacy.

      Actually, that brings up an intresting point .. are financial documents by companies emailed across the Internet? If the law allows companies to keep this information private, are they waiving their right to privacy as outlined by law when they transmit that data across the internet? Wouldn't this anger companies? Or should companies be allowed to claim that their data should be illegal to sniff?

      --
      "Old man yells at systemd"
    29. Re:Why is "help us" in quotes? by zCyl · · Score: 2

      and told our government the names of all of the hijackers, their targets and weapons, and the approximate date of the attacks.
      This was printed in German newspapers.


      Can we have a link to any of these German news articles? It would be much appreciated.

    30. Re:Why is "help us" in quotes? by Darby · · Score: 1

      Can we have a link to any of these German news articles? It would be much appreciated.

      Well, curiously, the archives are no longer online.
      (I know, I know)
      But searching around will find you a lot of information. Of course, it being gone from the official site makes it more difficult to know what to believe, sadly.

    31. Re: Why is "help us" in quotes? by ryman · · Score: 1

      Well, I'm glad that you don't care that anyone who wants to can spy on you, but you're not the norm. In fact there are laws against that.

      It's not my problem until I make it mine, or it happens to me.

      Well trust me, if it happens to someone else, and you don't care enough (or have enough guts) to stand up against it, it will happen to you down the line. Just keep that in mind while you enjoy your temporary isolationist bubble.

      --
      "We are far too easily pleased." --C.S. Lewis
    32. Re: Why is "help us" in quotes? by Anonymous Coward · · Score: 0

      foia.fbi.gov, einstein was afilliated with 50-odd communist groups iirc. Headed some also. fat lot of good his IQ did him...

    33. Re: Why is "help us" in quotes? by Anonymous Coward · · Score: 0

      Wasn't Einstein involved in creating the atomic bomb?

      Jesus H. Christ, if you wanna invent a telephone or something, that's great, but when you start toying with the secrets to weapons of mass destruction, ya know what?

      I'd be fscking disappointed if the FBI *didn't* have a huge file on the guy.

      Christ.

    34. Re: Why is "help us" in quotes? by Anonymous Coward · · Score: 0

      What has Left-Right got to do with it?

      The right/left was used a vehicle to draw the consusion that slashdot people are just as fucked up as the montana freemen.

    35. Re: Why is "help us" in quotes? by Anonymous Coward · · Score: 0

      yea, sure "normal" people don't care. "normal" people are morons

  27. Right...... by keep_it_simple_stupi · · Score: 5, Insightful

    Because governent computers are so secure themselves... HA!

    1. Re:Right...... by Fluid+Truth · · Score: 1

      Oh, it's okay. If anyone tries to steal Gray Davis' identity, they'll either muck things up less for my state, or they'll be identified as not being the real thing because of their cluefulness.

      And, incidentally, if they broke into a Sacramento office and got people's payroll, such as Gray Davis', it was almost certainly the California State government, not the US Federal government.

      --
      Apparently, of the rich, by the rich, for the rich.
  28. Website by Anonymous Coward · · Score: 1, Informative

    For more info, including pdf docs and downloadable programs, see: http://www.cisecurity.org/bench_win2000.html

  29. Resistance Is Futile. You Will Be Assimilated. by Anonymous Coward · · Score: 0

    Exterminate! Exerminate! EXTERMINATE...!

  30. Great, I can see it now... by Anonymous Coward · · Score: 1, Insightful

    "Welcome to the USA-SECURE installation program. Please stand by while the installation wizard looks for security problems on your computer and fixes them."

    [..30 seconds pass..]

    [..BSOD appears..]

    "An error has occurred in file MAGICLANTERN.VXD at 0000-00CF-B0E3. Press Ctrl-Alt-Delete to restart your computer."

  31. If Al Gore made the Internet... by SpanishInquisition · · Score: 0

    then George W. will break it.

    Thank you very much Florida.

    --
    Je t'aime Stéphanie
  32. Green Lantern... by linuxrunner · · Score: 2

    Was this the best way the Government could think of to distribute it?

    --
    www.slightlycrewed.com - Because aren't we all?
    1. Re:Green Lantern... by Amazing+Quantum+Man · · Score: 2

      You mean "Magic Lantern", don't you?

      --
      Fascism starts when the efficiency of the government becomes more important than the rights of the people.
    2. Re:Green Lantern... by iabervon · · Score: 2

      Having just heard from the Fair Use people, the government has decided to share their favorite comic book with millions of their closest friends.

      Cool, my computer is surrounded by a glowing green light! That'll keep those cyberterrorists out!

      Anyway, back on topic, this software is part of a program to protect critical non-government services. They're definitely not going to introduce any new vulnerabilities with it. The NSA's mission includes both development of spy technology for the gov't to use and development of counter-intelligence and security technology to protect the US. Spying on most Windows users is so easy that the gov't actually wants to make it harder, so their special technology is actually necessary.

  33. 1984 by wub · · Score: 2, Funny

    Isn't it ironic that a few days ago /. posted an article about how 1984 DIDN'T happen. Now the U.S. Govt is trying to make it happen? ;)

    1. Re:1984 by Anonymous Coward · · Score: 0

      The story must have gotten cross-posted to slashcroft.gov

  34. Re:Redundant by Sp1n3rGy · · Score: 1

    I think the word you are looking for is oxymoron, not redundant.

  35. Install Bush/Ashcroft-provided software? by geophile · · Score: 2

    Time to emigrate to Canada.

    1. Re:Install Bush/Ashcroft-provided software? by GoatEnigma · · Score: 1

      Yes! Reverse brain drain! But we'll only take the Democrats, they're the only ones that meet our strict politeness standards.

    2. Re:Install Bush/Ashcroft-provided software? by Anonymous Coward · · Score: 0

      I think not, Democrats are far too right-wing to enter the country. No need to give the Alliance more lackeys.

    3. Re:Install Bush/Ashcroft-provided software? by Anonymous Coward · · Score: 0
      You're not safe in *Canada*.

      If the last few months have taught us anything, it's that merely moving to another country isn't nearly enough to keep Ashcroft & friends from hunting you down, telling the world you're a Taliban-Al-Queda terrorist and locking you up forever at some offshore military base without benefit of legal advice.

      Remember: If you think you're entitled to your Constitutionally-protected civil rights, the terrorists have already won.

    4. Re:Install Bush/Ashcroft-provided software? by Kwikymart · · Score: 1

      We don't want you ;)

      --

      Buying a Dell computer is equivalent to dropping the soap in a prison shower.
    5. Re:Install Bush/Ashcroft-provided software? by GoatEnigma · · Score: 1

      Either that was a joke about Americans in general, or you need to look up "right-wing" in the dictionary....

    6. Re:Install Bush/Ashcroft-provided software? by ElectricRook · · Score: 1
      Time to emigrate to Canada.

      Perhaps you should first read the Declaration of Independence
      Then ask yourself which side Canada was on in the war of independence, and why.

      --
      - High Tech workers, please say NO to Union Carpenters, their Union sees fit to control our compensation.
    7. Re:Install Bush/Ashcroft-provided software? by Anonymous Coward · · Score: 0

      Why is it that people always suggest going to freakin' Canada?

      Are you really naive enough to believe that Canada would last as an independent nation more than two weeks after a dictatorship was implemented in the United States? Hell, they're just barely independent now!

      I remember laughing my ass off at that idiotic "Handmaid's Tale" book (written by a Canadian, of course). Religio-fascism takes hold in the U.S., but Canada's still there as a refuge. Right.

    8. Re:Install Bush/Ashcroft-provided software? by Anonymous Coward · · Score: 0

      What?? If you think that Canada is ruled by a tyrannt...well, ok, maybe it is! But the point is that our government at least follows that of the USA in its studpidity (not always) so if you, ok maybe not you (you seem to have a bad attitude), immigrated to Canada you would probably have 6 months to 2 years before the government would send out software of its own.

      Long live King Jean!

  36. I can see this happening. by tcd004 · · Score: 2
    1. Re:I can see this happening. by Anonymous Coward · · Score: 0



      ACK! its a deep link! TERRORIST

  37. What the ... ? by Anonymous Coward · · Score: 0

    Why is my tax money going to secure a commercial system???? Shouldn't they be taking this outta MS's $40 bill hide???

    It's people's free choice to install and run an insecure system. And if they're stupid enought to do it, then they deserve the consequences of it.

    Is time again for a Boston Tea Party style insurrection???

  38. Going Nowhere by KoopaTroopa · · Score: 3, Interesting

    I don't forsee this initiative going too far. Most people barely know how to use their computers to send email or read Slashdot, much less secure their systems from attack.

    On the other hand, if anyone is going to try to design such a package of software, I imagine that the NSA knows their stuff pretty darned well. They have been advertising security-enhanced Linux on their website for a while now. I've never tried it, so I can't testify to its usefulness.

    --
    Sharpies don't just sniff themselves.
    1. Re:Going Nowhere by pmz · · Score: 2

      I don't forsee this initiative going too far. Most people barely know how to use their computers to send email or read Slashdot, much less secure their systems from attack.

      Also, don't forget that many computer systems, from the users' point of view, will be totally broken after they are secured.

      After seeing the high-quality configuration management tactics employed by Microsoft, Windows applications, and Windows users, I wonder if yet another recession would occur after applying such a wide-ranging security update. Even other operating systems like GNU/Linux, Mac OS X, *BSD, etc. will appear broken once firewalls are put in place and /etc/services gets stripped.

      Security, in many circumstances, may actaully be counterproductive, and, in those cases where it is necessary, it takes quite a bit of fine-tuning to get it right. Further, what happens when usage requirements change? For example, I keep a tight firewall at home but occasionally need to make a specific FTP allowance. Who, besides me, really wants to take several minutes to update the filter rules and interrupt the firewall before downloading killer-app-X?

  39. Talk about backdoors and wiretaps. by YT · · Score: 1


    So basically I can open up my computer to anybody in the government who wants to see whats on my computer. I might as well call up the CIA/FBI and ask with they want to come over and spend the weekend.

  40. where were you a week ago? by krog · · Score: 1

    More Attacks on Linux than Windows

    it's an old joke any damn way.

  41. Wait a second by Fone626 · · Score: 1

    Forgeting for a second about any paranoid feelings we might have about what the govt wants to put on our computer.
    Can we expect every software house that writes incredibly insecure software in the future to get a free security patch from the govt. If so, that could really cut down on the programing time for everyone in the future if we don't have to worry about security and just let the govt put out tax dollars to work!

  42. US Gov't does make one good piece of software by Anonymous Coward · · Score: 1, Informative

    This is the best Windows software for time synching I've found. It's free too!

    http://www.boulder.nist.gov/timefreq/service/its .h tm

    1. Re:US Gov't does make one good piece of software by Peyna · · Score: 2

      windows has had time sync support for a long time. It's now part of the GUI in XP. Just double-click on the clock and pick a server. Too bad it only does it once a week or so.

      --
      What?
    2. Re:US Gov't does make one good piece of software by alen · · Score: 2

      Win2000 server alreasy does this. You pick a time server for your PDC. Naval observatory is a good choice. Then all of your DC's sync of your PDC and the member servers and workstations sync off the DC's. All automatically.

  43. How to secure every PC in America* by maxphunk · · Score: 1, Insightful

    1) insert windows boot floppy
    2) a:\format c:
    3) insert linux install cd
    4) restart
    5) install linux
    6) boot computer
    7) repeat #6 as long as you own a computer

    * NOTE: those who run any sort of *NIX already (eg Linux, *BSD, Mac OS X, Solaris, HP/UX, etc) can skip driectly to #6, just don't forget to configure your firewall.

    --

    "The chief enemy of creativity is 'good taste'" -Pablo Picasso
    1. Re:How to secure every PC in America* by Anonymous Coward · · Score: 0

      Are you a *total* moron? That isn't even funny. It's a sick reminder that Linux goofs have their heads so buried in their asses that they don't even know the concept of daylight at all.

    2. Re:How to secure every PC in America* by teamhasnoi · · Score: 2

      Do I need to do this like, once an hour, day or will once a week do?

    3. Re:How to secure every PC in America* by Anonymous Coward · · Score: 0

      Have fun booting that computer, because following your instructions renders it useless for anything else. That being said, your current +3 moderation is remarkably unsurprising.

    4. Re:How to secure every PC in America* by Anonvmous+Coward · · Score: 2

      Well, it'd certainly mean that people rely on their computer less. "Bah, I need IE to view this site. I guess I'll go outside."

      Yeah, I could see that securing computers all over America.

    5. Re:How to secure every PC in America* by maxphunk · · Score: 1

      Only once should do, unless someone climbs in your window at night and infects your machine with the Windoze virus. =)

      --

      "The chief enemy of creativity is 'good taste'" -Pablo Picasso
    6. Re:How to secure every PC in America* by Anonymous Coward · · Score: 0

      You'll need to break down step 5 a bit more before *everyone* in America can do it.

    7. Re:How to secure every PC in America* by tg_schlacht · · Score: 1

      Yeah, right.

      You expect that a lot of people who can't even :

      - set the clock on their VCR

      - who can't conclude that if double-clicking a Word document on the desktop opens it, that double clicking on an Excel spreadsheet ought to open it as well

      - have not and cannot observe that File, Edit, View, Window and Help menus exist in almost every Windows program and operate in substantially similar ways

      - who can't bloody well remember that Ctrl-X, Ctrl-C, Ctrl-V will perform cut, copy, and paste in just about any Windows application you come across

      - who cannot grasp that you can have more than one document open at a time and that when a window is occluded that it is not forever lost

      - who have no clue what Windows Explorer is

      - who have no idea what a shortcut is

      - who can't even figure out that setup.exe and install.exe in the root folder of a CD are installation programs

      are going to be able to install Linux, properly secure it, and use it.

      GMAFB

    8. Re:How to secure every PC in America* by Anonymous Coward · · Score: 0

      However, apparently it's also "Insightful".

    9. Re:How to secure every PC in America* by maxphunk · · Score: 1

      then i guess our only recourse is to make a "autoinstall" cd that when inserted boots/restarts the computer and installs linux... all we need to do is discuise it as an aol cd and send it to everyone in america (and beyond). of course, i'd assume it'd be for x86 because that would cover every windows user on the globe.

      --

      "The chief enemy of creativity is 'good taste'" -Pablo Picasso
    10. Re:How to secure every PC in America* by Anonymous Coward · · Score: 0

      I would have modded it as insightful if he said OpenBSD. Linux is only secure when compared to anything produced by Microsoft.

    11. Re:How to secure every PC in America* by Jucius+Maximus · · Score: 2
      In the end, I think that if they really are hell-bent on securing every computer in the USA, there is only one solution:

      Prevent people from owning computers that can connect to networks via legislation.

      This is a highly Orwellian proposition (and yes I did see the 'George Orwell was Wrong' article posted recently) but seriously: People in general don't know and never will know how to properly manage a computer. Only experts know this. If all computers are to be secure, then only experts should manage them and the networks. This implies that all networked PCs should be houses in special locations where they can be used in a secured environment.

      I remember some years ago reading a mock press release from the President of the US thanking all USA citizens for complying with the ban on all home computers and how it would make the USA a much safer place.

      If things keep going the way they are going and there are a few more serious terrorist attacks on North America, we might want to get worried about this (currently highly theoretical) possibility.

  44. The tools can be found here by Global-Lightning · · Score: 5, Informative

    http://www.cisecurity.org/

    And to clarify alot of paranoia,
    These tools were built in conjunction with the Federal government, major manufacturers, service providers and academia. The are basically scanners that look for the most common vulnerabilities on systems. And no, you're not installing an NSA/CIA/FBI/TLA backdoor onto your system.

    1. Re:The tools can be found here by Worf+Maugg · · Score: 1

      "And no, you're not installing an NSA/CIA/FBI/TLA backdoor onto your system. "

      Prove it! Please.

    2. Re:The tools can be found here by daemones · · Score: 1

      -And no, you're not installing an NSA/CIA/FBI/TLA
      -backdoor onto your system

      That's because, chances are, that it's already there.

      --
      Alas, Babylon.
    3. Re:The tools can be found here by ortholattice · · Score: 3, Interesting
      I would not trust the downloads from this site. I can't believe this is run by security professionals who if anyone should be promoting public inspection of their programs' source code for security bugs. I could find no mention of source code (except for a handful of standard GPL'ed things like ncat), so you're blindly running a mysterious binary that who knows what it might do to your system, intentional or not. And look at their draconian terms; apparently you're not allowed to publish the results of any benchmark. This is supposed to be a non-profit outfit to benefit the public, that the government endorses?

      Limitations on Use

      Receipt of the CIS download package components does not permit you to:

      a. Sell the CIS download package components;

      b. Lease or lend the CIS download package components;

      c. Distribute the CIS download package components by any means, including, but not limited to, through the Internet or other electronic distribution, direct mail, retail, or mail order (Certain internal distribution rights are specifically granted to CIS Consulting and User Members as noted in (2.e.) below);

      d. In any other manner and through any medium commercially exploit or use the CIS download package components for any commercial purpose;

      e. Post the Benchmarks, software tools, or associated documentation on any internal or external web site. (Consulting and User Members of CIS may distribute the CIS download package components within their own organization);

      f. Represent or claim a particular level of compliance with the CIS Benchmarks unless the system is operated by a Consulting or User Member of CIS and has been scored against the Benchmark criteria by a monitoring tool obtained directly from CIS or a commercial monitoring tool certified by CIS.

    4. Re:The tools can be found here by tg_schlacht · · Score: 2, Insightful

      Anyone want to try and prove the government is doing something sneaky?

      - Make a clean install of whichever OS you use.

      - Apply all latest security patches (or not shouldn't really matter.)

      - Burn all files to CDROM(s).

      - Remove CDROM(s).

      - Run government security checking software.

      - Reboot.

      - Compare all files from CDROM(s) to those on the hard drive.

      - Document any significant differences.

      If you find Magic Lantern or altered binaries on the system report to /. and security sites and major news outlets. See government with egg on its face.

      If you do not find Magic Lantern or altered binaries on the system go back to writing posts about conspiracy theories, New World Order and black helicopters.

    5. Re:The tools can be found here by John+Hasler · · Score: 2

      "except for a handful of standard GPL'ed things like ncat"

      I don't know of a package named "ncat", but if you mean netcat, it isn't GPL.

      If they are applying those conditions to GPL software they are violating the GPL.

      --
      Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
    6. Re:The tools can be found here by MarvinMouse · · Score: 1

      I know

      NSA = National Security Agency (No Such Agency)
      CIA = Central Intelligence Agency
      FBI = Federal Bureau of Investigation

      But what does TLA mean?

      --
      ~ kjrose
    7. Re:The tools can be found here by Global-Lightning · · Score: 2

      TLA means "Three Letter Acronym", a generic reference for federal agencies. Other examples are:
      NRO, DIA, ATF, DEA, DoJ, DoD, DoS, DoT, INS, IRS, HHS, GSA, LoC, OPR, FAA, FCC... Ad Infinitum, ad nauseum...

  45. So let me get this straight: by faxafloi · · Score: 1


    The gov't is going to spend tax money making Microsoft secure? after declaring them a monopoly?

    --
    Exit, pursued by a bear.
  46. heh by Anonymous Coward · · Score: 1, Funny

    From the makers of Carnivore, comes a new an exiting new product! ...

  47. Grants by macdaddy · · Score: 5, Insightful

    What I would like to see is Government "grants" to better security at other federal and state agencies like universities, police departments, DMVs, etc. Then open it up to businesses and whatnot. My Unv would love to find a grant to help offset the costs of a good security solution. Our physical security is a joke. Odds are, you can walk right through our office, into our server farm, take a server, and leave with it with minutes, hours, maybe even days to spare before someone even notices it's gone. A grant to help pay for a keycard system and remodeling to accomadate heightened security would be great.

    1. Re:Grants by Mournblade · · Score: 1

      I'd like a gov't grant to offset the costs of a good security system for my house, too, but i'm not going to get one. It sounds like your school needs to rethink it's spending decisions. Most universities are not so cash strapped that they cannot afford to install physical security for their IT infrastructure. A more likely explaination is that they're putting off spending the money until they have to - i.e. *after* someone steals a server. A government grant to pay for that is not necessary.

    2. Re:Grants by quantum+bit · · Score: 1

      Odds are, you can walk right through our office, into our server farm, take a server, and leave with it with minutes, hours, maybe even days to spare before someone even notices it's gone.

      Where was this again...?

      I could use a new server

    3. Re:Grants by McGiraf · · Score: 1

      Good sig! can i use it ;)

  48. I sure am glad I'm not american by Anonymous Coward · · Score: 0

    And I feel pity for whoever you guys that are.

  49. Chasing their tail by Shagg · · Score: 5, Insightful

    So let me get this straight. They're saying "download and install this software, which looks for security problems that are most commonly caused by users being too lazy to download and install software (updates)". Does anybody else find that amusing?

    --
    Unix is user friendly, it's just selective about who its friends are.
    1. Re:Chasing their tail by Longfeather · · Score: 1

      lol. Ain't that the truth.

    2. Re:Chasing their tail by Anonymous Coward · · Score: 0

      Consider the amount of computer imbeciles that would follow the instructions from the US gov't in a "be a patriot", "be a good american" context, vs. the ones that would click the windows update icon and "read all that technical babble"..

  50. The NSA patch duh! by Niadh · · Score: 1

    Everyone knows to _NOT_ be a terrorist you need the NSA patch. Oh wait, Windows comes with it? nevermind.

  51. ExtremeTech Article by Anonymous Coward · · Score: 0

    http://www.extremetech.com/article2/0,3973,386905, 00.asp

  52. close by Lord+Omlette · · Score: 3, Insightful

    Love the country, yes. Trust the government, only when appropriate.

    --
    [o]_O
    1. Re:close by elemental23 · · Score: 1

      See .sig :)

      --
      I like my women like my coffee... pale and bitter.
  53. NSA Security Recommendations by ShaunC · · Score: 4, Informative
    The article mentions:
    Clarke spoke to reporters as well as government and corporate officials to announce government-wide standards for securing Microsoft's Windows 2000, the most commonly used operating system for government and corporate computers.

    The Pentagon, the National Security Agency and other private and government organizations devised the standards.
    The NSA's security recommendations for Win2K have been available to the public for some time now. See here. They've also published security guides for NT and Cisco routers, as well as "best practice" suggestions for dealing with email and executables, see here. Yes, that's really an NSA site; I don't know why it's not hosted where you'd expect it to be.

    Shaun
    --
    Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
  54. government isn't that bad by Xzzy · · Score: 5, Informative

    > (we were supposed to be *increasing* the security of the PC's, right?)

    I mean if the government was that incompetent, we'd already know who really killed JFK, right? ;)

    At any rate, I happen to work for the government, and I've also held a few commercial jobs, and speaking on a reletivity scale, the government network has a much better security model than any place I've ever worked.

    They also have a fanatical security "reaction" team that enforces security policy, scours vulnerability lists, and watches logs daily for signs of intrusions. When that apache hole came out a few weeks ago.. they gave every website at the facility about three days to fix it, otherwise they would start black hole-ing ports of machines running unpatched servers.

    Now whether we're an exception or a rule I'm not qualified to state, but the government isn't quite as stupid as you're suggesting. ;)

    1. Re:government isn't that bad by Anonymous Coward · · Score: 0
      I mean if the government was that incompetent, we'd already know who really killed JFK, right?

      I'm pretty sure he committed suicide. The Zepruder film was faked to comfort his family and the nation.

  55. Antitrust by spbriggs · · Score: 1

    Did I just read that right? The US government reckon Windows is so insecure it represents a threat to national security? Billg's lawyers better start deciding what to spend the overtime payments on.

    --
    Time is an illusion, lunchtime doubly so.
  56. the other option by drDugan · · Score: 1

    Dateline: March 19, 2003

    Today the government ordered all TIPS volunteers to carry class 4 rated wire cutters (from GH Defense Inc., $399) and to cut all connections to computers suspected of being involved with any activity they think is not OK. Full story at 11.

  57. Where is it? by Eric+Smith · · Score: 2
    The CNN article says:
    The program released Wednesday checks a computer for such flaws and shows how to fix them.
    So if it was released on Wednesday, why can't I find it?
  58. not so terrible? by tps12 · · Score: 1

    Okay, jokes about Windows bugs and government inefficiency are probably warranted. But when all is said and done, I don't mind this idea, at least in concept.

    The need for a central source for security updates and patches is extremely glaring. I noticed this during the recent Apache exploit's publicity. I wanted to patch my installation, but I had no idea to whom to turn to get the patch. This is a big problem for all computer users, both at home and in business.

    So, we accept the necessity of a central source for bug fixes and security patches. Now who will do it? Personally, I'd be more willing to place this responsibility in the hands of our government, which has no ulterior motives, than in the hands of some greedy business.

    Let's not throw the baby out with the bathwater here. And if we need to play it safe, we might want to consider saving the bathwater, too.

    --

    Karma: Good (despite my invention of the Karma: sig)
    1. Re:not so terrible? by RailGunner · · Score: 2
      "our government, which has no ulterior motives"

      You're either a troll, or a prepubescent who just doesn't know any better. The government has no ulterior motives? What about the kind, loving, altrustic government witholding treatment to African Americans with syphilis? Intentionally using SmallPox against Native Americans? What about all of our troops who have Gulf War Syndrome? What about the vietnam troops that were exposed to Agent Orange? My father still bears the scars from this.

      The best policy when dealing with Government is a Russian proverb quoted by Ronald Reagan. Trust, but verify.

      As far as a "greedy" corporation, let me ask you something. Have you ever gotten a job from a poor person? Some corporations are definately bad, (cough cough microsoft cough cough) but others offer quality products at competitive prices without screwing over everyone they can. Now do me a favor: STEP AWAY FROM THE KARL MARX BOOK!

      As far as the Apache fix.. it was all over the net. There was a multitude of sites you could get it from.

      If any thing, the Government almost ALWAYS has an ulterior motive.

  59. Metal Gear Solid 2 by nigord · · Score: 1

    Funny how this remind me Metal Gear Solid 2. US Gov distributed a Y2K patch that was then used to control the internet... Is it me or ---> Reality is now like a big video game ???

    1. Re:Metal Gear Solid 2 by Maserati · · Score: 2

      Not a problem, I'm getting great FPS.

      --
      Veteran, Bermuda Triangle Expeditionary Force, 1992-1951
  60. Before people start screaming, "Big Brother!"... by flogger · · Score: 3, Insightful

    This could be a good thing. Standardized security platforms that help PCs to be just that: Secure is a good idea. Now there are so many routes to go for a "Secure system". What is secure for one person/business is totally unacceptable for another. If the government stepped in and gave everyone a "All-In-One-Grand-Security-FireWall-Intrusion-Alar m-Type-Program"(tm), users could then have "acceptable" security. Yea, I know. How the hell is the Gov't supposed to know what security means. But it would be better than it is now. It seems that 90% of the people I know have no idea about open ports or filesharing.

    Anyway, back to the point: Hopefully this discussion won;t turn into a bunch of people yelling (and getting modded up for yelling) "Big Brother-Ware! I'll Never install this."
    Trust the Gov't a little. This might be what it takes to get Average Joe Blow User to stop sharing his C drive on the phone company's DSL network.

    flogger

    --
    ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
    "First things first -- but not necessarily in that order"
    -- The Doctor, "Doctor
  61. Why do I have to pay twice? by teamhasnoi · · Score: 3, Insightful
    First I buy Windows, then I pay taxes so the Government can write software that points out the patches I need and configuration changes I need to make?

    If MS is really serious about security (ahem), why don't they do this themselves? It would certainly help their reputation, and would fall in line with the *new* corp. responsibillity that good 'ol GW is talking about.

    And then I woke up!

    1. Re:Why do I have to pay twice? by Anonymous Coward · · Score: 0

      See, the gov't is paying MS to shut up about it, and let them do this. Why? So they can include some snooping software with these "patches" and MS will never say anything.

  62. odd by Restil · · Score: 2, Interesting

    That someone that won't take the effort to keep his system patched, won't run zonealarm or virus scanners, and happily contributes day after day to the sircams, iloveyou's, melissa's, and others, but THIS someone will take the initiative to run the government's software. How is THAT supposed to happen?

    Of course, if they bundle it with Kazza, it might be effective. Heavens only knows, a good percentage of the computers in the world install all the spyware crap, it couldn't really hurt any more. All security aside, I have my own problems with running government software on my personal computers, but thats beside the point. :)

    -Restil

    --
    Play with my webcams and lights here
    1. Re:odd by Anonymous Coward · · Score: 0

      maybe the users wont need to have initiative... maybe it will be mandatory. "Every PC running Windows bought in the US will have the gov. security program installed."

      Or maybe we can finally give the police officers something else to do other than eating donuts. They will go door 2 door and arrest all home users stupid enough to run M$ with default security settings. It will be like Social-Darwinism!

  63. Trust the government with my pc??? by Rober7+Pauls0n · · Score: 0

    I'll take a "hacker" inside my pc over the government anyday.

  64. Re:mod me up by teamhasnoi · · Score: 2


    You're right. But there is no +1 Important. :(

  65. I don't know about O.S., but it better be free! by tswinzig · · Score: 2
    --

    "And like that ... he's gone."
  66. Yeah! CyberHomeland Security in the fucking house! by dominion · · Score: 2, Flamebait

    This is fucking great! I wonder if one of the million Stalin-esque informants will help me install this software?

    I mean, it's really good that the same government that busts into a house, shoots an elderly black man, and then realizes the grand drug bust was supposed to go down across the street is going to help me secure my homeland. Yeah, I'm enduring my fucking freedom more and more every day!

    Dominion

  67. It does'nr matter by setrops · · Score: 1

    Sooner or later the government will force Microsoft to insert it into the operating system.

    Didn't the NSA already have a backdoor?

    All that Microsoft has to do is incorporate this as a patch to one of their numerous security fix and your tagged.

    Your choices will be leave you PC with the security hole or install the patch. It will be up to you to decide.

  68. huh? by finkployd · · Score: 5, Informative

    I understand the reason but I do not understand the execution. Ignoring all "magic lantern" issues, this is just the wrong way to fix it. The government and some companies (Chevron??!) are going to audit the security of Windows, find the flaws and distribute a program to alter it so they are fixed...

    This is easier than just asking Microsoft to design a secure version of Windows? Come on, you already found them guilty of being a monopoly, perhaps a nice sentence would be "make a secure version of Windows".

    If Windows insecurity is such a threat to homeland defense, shouldn't the government be cracking down on the company making the laughably insecure software? Or perhaps simply not using it since it is (by the government's own admission) insecure?

    Or just demand the source code and distribute their own secure version. It worked with NSA-Linux :)

    Finkployd

    1. Re:huh? by Mr.+Firewall · · Score: 1

      It's true that the Bush Administration has made some amazingly stupid blunders. However, this is not one of them and the large volume of ignorant, knee-jerk remarks being made in this thread is proof to me that slashdotters are just as capable of mindless FUD as our favorite corporate punching bag.

      I'm a security professional who happens to know three of the people in the White House office of cybersecurity. All three have a great deal more clue than anyone posting on this forum realizes. Judging from the maturity level of the posts I've seen here, I think it's safe to say that these gentlemen were securing computers when most of you were running around in diapers.

      Let's deal with some facts here. Please.

      The default install of Windoze 2000 contains at least 120 known vulnerabilities [source: SANS Institute].

      Many of us security professionals have had to deal with Neanderthal bosses unwilling to allocate to us the time and/or people to properly secure our connected systems.

      So the best minds among us some in industry, some in academia and some in Government have been working for the last couple of years or so on a consensus standard that defines minimum-acceptable and best-practices levels of security for various operating systems (FWIW, the Unix document was finished a long time ago). And yes, some of those best minds are working for the US military, the FBI and the NSA.

      With this standard in hand, and a tool to quickly and easily evaluate our systems, many of us believe that we now have something we can take to clueless bosses and say, THIS is the standard! Are we going to meet it, or not?

      Those of us in the security community believe that the US government is the best vehicle for publishing and communicating these standards. For one thing, Government agencies have been dragging their feet at complying with Congress' demands that they secure their systems, citing (among other things) the lack of a standard for secure configuration.

      But there is another, even more serious issue: millions of clueless Americans connecting home PCs to the Internet through high-bandwidth connections, oblivious to the collective danger that millions of potential DDOS zombies pose to the nation's critical infrastructure. I mentioned this to Dick Clarke (White House Chief of Cybersecurity) last month in a meeting with him, and I for one am damned glad to see that he's doing something about it. He's basically taken the Windows 2000 security consensus document and vulnerability scanner (which are finally ready) and taken it to the masses.

      Let's face it, we have people out there who couldn't get a clue if they were standing in a field of clues during clue mating season wearing clue musk, but if the President of the United States tells them they need to secure their home computers to make America safe, then they'll By God do it!

      The idiotic anti-government paranoia I've seen expressed in response to this is, frankly, highly inappropriate. Some of you need to grow up and learn not to piss in the village's well.

      --
      In times of universal deceit, telling the truth gets you modded -1 Troll
    2. Re:huh? by finkployd · · Score: 2

      The default install of Windoze 2000 contains at least 120 known vulnerabilities

      So my earlier question stands, why not (a) use something else if it is so insecure or (b) demand Microsoft fix it. Why is it the US government's job to do a private company's job for them?

      Many of us security professionals have had to deal with Neanderthal bosses unwilling to allocate to us the time and/or people to properly secure our connected systems.

      Don't I know it. My background in is s/390 security, DCE security, and I am currently working with PKI, and Internet2's shibboleth and OpenSALM products. I'm not the "clueless, diaper-wearing, anti white house slashdot weenie" you would like to portray me as :)

      Those of us in the security community believe that the US government is the best vehicle for publishing and communicating these standards.

      Agreed, their committment to PKI has helped move Universities to looking at it seriously and making plans to use it.

      But there is another, even more serious issue: millions of clueless Americans connecting home PCs to the Internet through high-bandwidth connections, oblivious to the collective danger that millions of potential DDOS zombies pose to the nation's critical infrastructure.

      However, many of these people would not trust a binary issues by the US Federal government. I never questioned their competance, but I (and many other) do question their motives. They have a well documented desire to electronically spy on citizens. From the FBI's prespective, it would be irresponsible to NOT include a "magic lantern" like program with this.

      The idiotic anti-government paranoia I've seen expressed in response to this is, frankly, highly inappropriate.

      The people that brought you Carnivore and Magic Lantern are to not be questioned when they give you a binary to run on your PC?

      Finkployd

    3. Re:huh? by Mr.+Firewall · · Score: 1

      So my earlier question stands, why not (a) use something else if it is so insecure or (b) demand Microsoft fix it. Why is it the US government's job to do a private company's job for them?

      Let's see if I can explain this. I am going to type very slowly and use small words so that you can understand.

      This is not the government doing a private company's job for them. The Government is not spending any money patching Micro$oft's bugs for them. The Government is not distributing any patches for them. The Government is only publicizing a security tool, written and reviewed by the country's best minds in information security, so that people will hopefully use it to secure their systems.

      To answer your first two questions, the current Administration believes (as I do) that it is not in the proper role of Government to decide for other people what operating system they should or should not be using on their computers. The Government wishes to stay out of those almost-religious squabbles.

      However, the Government IS demanding that Micro$oft fix its security problems. Did you not see the news item about the letter the Air Force's CIO sent to Micro$oft? (Look it up yourself, I don't have time)

      The people that brought you Carnivore and Magic Lantern are to not be questioned when they give you a binary to run on your PC?

      This may be difficult for you to grasp... but it's well-documented that the FBI does not want anyone knowing just what is in Carnivore and Magic Lantern. Therefore, it will be a cold day in Hell before they include either of those in a consensus-created tool that was reviewed by hundreds of security experts before it was released. They may be sinster, but they are not stupid.

      --
      In times of universal deceit, telling the truth gets you modded -1 Troll
    4. Re:huh? by finkployd · · Score: 2

      Let's see if I can explain this. I am going to type very slowly and use small words so that you can understand.

      This may be difficult for you to grasp

      We could have had a good discussion on this subject, and I concede that I had some misconceptions earlier regarding the nature of this project.

      However, I refuse to lower myself to your petty level of immaturity. It appears that you have yet to master the art of making your point without sprinkling in liberal doses of condesending remarks. I see no provocation on my part to illicite such a reaction, and I must conclude that you are either too young to engage in a mature conversation, or have some serious anger management issues to work out.

      Good day

      Finkployd

  69. UM... by drDugan · · Score: 3, Insightful

    Can someone please tell me why this is not the responsibility of Microsoft?

    Have there not been many discussions about increased liability for fscked up, insecure software?

    1. Re:UM... by AntiNorm · · Score: 2

      Can someone please tell me why this is not the responsibility of Microsoft?

      Because our current administration finds it unimaginable to restrict corporations.

      --

      I pledge allegiance to the flag...
      of the Corporate States of America...
  70. I feel the same sorta way about SELinux by Mysticalfruit · · Score: 2, Informative

    I've downloaded and looked at it, but I haven't really brought myself to install it.

    I'm sure it's legit through and through, but my Orwellian tendancies flare up when I think about patching the kernel of my machine with something developed by one of the most secretive organizations on the planet, whose primary job is snooping on everybody and everything...

    It's really not the place for the goverment to encouraging people to start installing goverment sanctioned patches. If your a goverment agency, that's a different matter. What the goverment should do is lean very hard on those who are providing unsecure software and enviroments.

    Here's the problem I have...
    The Senate and House of represenatives are way too friendly with big business (read: DMCA/SSCEA), this includes the current administration as well... What this means is that I don't trust them to not put all kinds of provisions to entitle them to stomp all over my civil and constitutional rights based on the premise that they're doing the common good... 'cause their not, they're merely ensuring that the current regime keeps it monopolyies.

    --
    Yes Francis, the world has gone crazy.
    1. Re:I feel the same sorta way about SELinux by WetCat · · Score: 1

      Use the code, Luke!
      Seriously, you have all source code for SELinux
      and it has already been reviewed by probably at least hundred
      indepedent users.
      You can browse it, use automated tools on it,
      lick it, eat it. Check the code by all means you have -\
      you have it!

  71. go flog yourself... by Anonymous Coward · · Score: 0

    Who cares if joe blow shares his c drive? Does that affect the national security of country? I think not... Of course this is going to be BigBrotherWare, and most Americans are gullible, complacent, dumb, or just ignorant and will let this shit happen. I'll be lmao when in 5 years this "recommendation" becomes "mandatory".

  72. And I'm not just trying to bash Bill... by Anonymous Coward · · Score: 0

    Who is going to pick up the tab for this soon to be debacle?

  73. Let's do the time warp again? by Interrobang · · Score: 5, Insightful

    Aiigh! This suddenly reminds me (particularly that juicy, slurpy opening quotation) of those old '50s propaganda items like Appreciate America, where "patriotism" and "being a good American" (whatever that means) are automatically equated with "doing your part" (not incidentally what everyone else is doing).

    So let's all be good Americans, well, those of us who are Americans (--points finger--), and spy on our neighbours, secure our piece of cyberspace, and whatever else our fearless leader says we should do, because then those damn Commi^H^H^H^H^Hterrorists won't be able to eat us all up as we sleep in our (all-American) beds at night.

    Theme music: "Exhuming McCarthy," REM, Document

    1. Re:Let's do the time warp again? by binner1 · · Score: 1

      ...But it was all right, everything was all right, the struggle was finished. He had won the victory over himself. He loved Big Brother.

      -Ben

    2. Re:Let's do the time warp again? by Anonymous Coward · · Score: 0
      How right you are! More than ever we are being assailed with requests to "do your part" in conserving water, using less electricity, burning less gasoline, even eating less meat!

      So let's all be good world citizens and do just as the all-wise groupthink tells us. Why, it's for your own good, don't you know?

  74. Secure? by Cyno01 · · Score: 1

    so the US Government wants to distribute software patches to stop terrorists and *hackers*, i'm sure this software will include a backdoor to be used by the fbi, cia etc for purposes of 'homeland security', now with a government controlled backdoor on every windows machine what do you think the special intrest groups are going to do, the RIAA and MPAA already tried to sneak some sort of permision for a virus that destroyed pirated media files onto the counter terror bill or whatever, i'm sure with enough soft money they'd be allowed access to this counterterror backdoor and wreak havoc on any windows box they wanted, and i'm sure the government would love it if M$ started shipping windows with with their backdoor software in it all over the world... (coherent post disolves into wild iluminati conspiracy rant)

    --
    "Sic Semper Tyrannosaurus Rex."
  75. Re:All gov't-developed software is public domain.. by Anonymous Coward · · Score: 0

    Incorrect.
    All government developed software is *NOT* public domain.

  76. Let's get this straight... by WolfWithoutAClause · · Score: 5, Insightful
    The US government is proposing spending tax dollars to find holes that Microsoft have left in their operating system because fixing them would have cost Microsoft money?

    Propping up that such poor 'down-on-its-luck company'? I think that the government should FINE Microsoft for each standard hole that each customer out there has; not fix the problems for it using public money.

    --

    -WolfWithoutAClause

    "Gravity is only a theory, not a fact!"
    1. Re:Let's get this straight... by Anonymous Coward · · Score: 0

      right on!!!

    2. Re:Let's get this straight... by Sloppy · · Score: 2
      No. The government, not Microsoft, is responsible for the safety of its own computers. The mistake was in buying Microsoft products in the first place. The customer knowingly purchased bad software (Microsoft's reputation is well-established, and has been for many years), and now it has to face the consequences.

      It might be different if Microsoft sold the stuff with a warranty, but that wasn't the deal.

      (Oh, and if the government buys Linux or OpenBSD, should it fine Linus or Theo whenever it finds a bug?)

      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
    3. Re:Let's get this straight... by Erris · · Score: 2
      (Oh, and if the government buys Linux or OpenBSD, should it fine Linus or Theo whenever it finds a bug?)

      I'm sure Linus will give the US government Double Plus all the money it gave him for any insecure kernels it got from him. I'm not

      I think you have missed the point, however. This is the nationalization of computing. Like income taxes it will start off voluntary. It is without doubt the most serious threat to freedom in the world today.

      --
      DMCA, Hollings, Palladium. What might have sounded like paranoia is now common sense.
    4. Re:Let's get this straight... by gad_zuki! · · Score: 2

      If the customer was made promises both implied through advertising and outright lies then the company is liable. Microsoft has been calling its products secure and unstoppable for a while now. At a certain point its false advertising. The customer here may be the US government, but they're not magically above marketing and are under the same monopoly the home consumer is.

    5. Re:Let's get this straight... by NetBoy · · Score: 1
      Yup, your TAX dollars at work, bailing
      out Microsoft to fight Terrorism.

      Running government just like big business,
      if you catch my drift....

    6. Re:Let's get this straight... by IncohereD · · Score: 1

      The government isn't proposing to FIX any of Microsoft's holes. It's building a tool that looks for KNOWN FLAWS that have already been fixed, by Microsoft, and letting you know what they are. Because although MS is distributing patches already, rather loudly (windowsupdate is right on the start menu), a lot of people still don't listen. So maybe they'll listen to the government instead.

      It's like blaming car manufacturers for not MAKING drivers wear their seatbelts. All they can do is put them in there and suggest that you use them, but some people won't actually do it till the gov't tells them so.

      What I find much more interesting is that when the cDc & co. makes this sort of tool, it's 'hacking'.

  77. Government Standards by Badgerman · · Score: 2

    Wow, so I can bring my computer up to government standards?

    Sorry. I prefer to set my standards MUCH higher.

    --
    "The Sage treasures Unity and measures all things by it" - Lao Tzu
  78. Paranoia by thales · · Score: 2
    Can I trust this software?
    Not fully if it's just a Binary, but in the Windows world often a Binary is the only option, and I'd put more trust in a Binary from the Federal Government than in some "Secure Win" Binary I downloaded off a free beer software site or even bought from a company that I hadn't checked out throughly.

    --
    Quemadmodum gladius neminem occidit, occidentis telum est
  79. Why people don't install security updates by TClevenger · · Score: 1

    "Windows Update is downloading critical security updates and service packs to your computer. Time remaining: 2 hours, 34 minutes at 53kbps."

    [Clicks "Cancel".]

    (The above, of course, applies to MS operating systems.)

  80. This is a joke right? by sielwolf · · Score: 2

    *Begin Sarcasm*
    The government? Trying to help... the People? What's the catch?
    *End Sarcasm*

    So often people seem to treat their relationship with their government as a monarchy: word comes down from on high, we pay taxes to be protected from other kingdoms, and we pay them or they will do mean things to us.

    Maybe it doesn't speak well for the government but its odd how that when the government tries to help people seem to think they are lying.

    Have things gotten that bad?

    --
    What is music when you despise all sound?
  81. Blurred perception by daemones · · Score: 4, Insightful

    "from attacks by "hackers and terrorists."

    Enough statements like this and there will be no effective difference between the two.

    Watch out, script kiddies: first you could get the death penalty, now you may not get a trial.

    --
    Alas, Babylon.
  82. how do you clean up insecure Windows installations by Anonymous Coward · · Score: 1, Flamebait

    "This plan will include the distribution of government-provided software to help clean up insecure Windows installations."

    so they will be providing *nix install disks?

  83. Clean up by john.wingfield · · Score: 1

    This plan will include the distribution of government-provided software to help clean up insecure Windows installations.

    Clean up eh? And have a poke around at the same time, no doubt. Hmm...

    J

  84. What about those (self-admitted: me too) lamers? by nani+popoki · · Score: 1

    Some of us run OLDER versions of Windoze (NT 4.0, for example). Is the government gonna help us, or is it a conspiracy to get everybody to fork over more bucks to Macrosloth?

  85. Whatever happened to "the zen of self-regulation" by guttentag · · Score: 3, Insightful
    So the U.S. government is going to step in and provide us with the security patches Microsoft has missed? This seems to go against President Bush's repeatedly-stated intention to let corporations conduct their business with little or no interference from the government.

    <SARCASM>It may also violate the EULA Bush agreed to by opening the shrinkwrap on Microsoft's campaign donations, so it probably won't be happening.</SARCASM>

  86. It really isn't as bad as you might think by ItaliaMatt · · Score: 1

    O.K. guys... I work for the government in a IT capacity. I just went through training on what these security updates are supposed to do. They were developed by a certain three letter company based in Atlanta in cooperation with the Department of Defense/NSA. If you download them and look at what they do it makes sense. Stuff that makes perfect sense in the *nix world like making sure that the last successful login doesn't appear after that user logs out in W2K (and therefore giving a potential h4x0r a login name) People might think that it is malicious code designed to run on a Windoze box to give a back door to your system. I would say to them that you should never accept or run programs/reg hacks/anything else from a company or someone you may or may not know without understanding what it does. I know what these "security baselines" do and have no problem applying them to my home machines (for my wife and kids of course - I am the linux geek in the family) So - flame away!! :)

  87. I got a chance to see the software... by Anonvmous+Coward · · Score: 2

    I got a chance to tinker with the beta firewall product that the US Gov't is developing. It's obvious they spent a lot of time on user-interface so that the general populace will be able to fight cyber terrorism. Check out this screen shot, you'll see what I mean.

    1. Re:I got a chance to see the software... by Peyna · · Score: 2
      The trick to understanding Linux is understanding how to properly misspell cmd's.

      Perhaps my favorite misspelling in the tech community is the REFERER tag. Apparently the spec was out and accepted and in use before the error was caught so nothing could be done. =]

      --
      What?
  88. Right... by hackwrench · · Score: 1

    So let me install the same lock on your door and my door...I get to be the only one with the key :D

  89. "tax Break" for Microsoft by Mr.Zuka · · Score: 1

    Does anyone else see this as the Government cleaning up Microsoft's mess. Microsoft makes really bad code to be first to market that needs patch after patch to update then Uncle Sam picks up the tab to make sure everyone updates.

  90. So What? Patch some people instead. by Anonymous Coward · · Score: 1, Insightful

    Install as many firewalls as you want, plug every hole in your system, scan every port you want. You can only make organizational systems secure to a point.

    When the chips are down, social engineering is the hole that no patch can fill. What good is an invincible system for which tech support can be tricked into giving the password?

  91. Re:Before people start screaming, "Big Brother!".. by gerardrj · · Score: 1

    Secure is a good idea. But even the government has different levels of security.
    My personal web server does not need triple DES public key kryptography with kerberos login via retinal scan, key fob and password. The computers that initiate missile deployment from our nuclear subs probably do.

    But the core question is this: Why would yoo advocate spending taxpayer $$ to fix the problems caused by a greedy predetory monopoly because of their low (lack of) corporate morals?
    If Ford sold billions of cars that the economy relied on, and those cars where known to frequenly cause traffic jams that disrupted or crippled traffic flow, should we the taxpayer be forced to pay for repairs/upgrades to those cars?

    --
    Article X: The powers not delegated... by the Constitution...are reserved...to the people
  92. In a related development.... by kitzilla · · Score: 1

    ...a program developed by Arthur Anderson accounting will soon be released to Quicken and Quickbooks users concerned about flaws in their bookeeping systems.

    --
    This is my post. There are many others like it. If you don't like what you read here, go try one of the others.
  93. this... by Anonymous Coward · · Score: 0

    combined with operating TIPS is a bit scarey....

  94. "Help us" get rid of "Scare Quotes" by PhotoGuy · · Score: 2

    Suck had a great article on "Scare quotes". They almost seem amateurish these days.

    Rather pathetic to see them in an article like this; seriously, we expect Microsoft to do sneaky and scary things with their software, and everyone's on the watch for it. If we find something, there are no repercussions on them at all, it seems.

    If the *government* were to be caught doing something sneaky on people's PC's, there would be a *huge* stink, heads would roll, etc.. Unlike Microsoft, they *are* accountable to the public,j especially with something as obvious as this. They're not stupid enough to put spyware or backdoors in stuff. With the slashdot crowd out there, they'd be caught in a second.

    Anyone who's really worried about this has watched too many x-files episodes. Go out for a walk, get some fresh air, dudes.

    --
    Love many, trust a few, do harm to none.
  95. It's already released by Anonymous Coward · · Score: 0

    I thought the gonvernment had already released such software.

  96. All I can think of... by Parsa · · Score: 1

    I keep trying to write something witty and insightful, but I keep getting scared thinking of installing gov. software on my computer and the only thing my fingers type is...BAD, VERY, VERY, BAD.

    --
    Abiit, excessit, evasit, erupit.
  97. lol by Cardhore · · Score: 2

    hahahahahahahaaaaaahahahahhahahahh

  98. Re:All gov't-developed software is public domain.. by gorillasoft · · Score: 2

    Incorrect.
    All government developed software is *NOT* public domain.


    The AC is right on this one - all government-developed software is most assuredly not PD.

  99. Big picture... by wowbagger · · Score: 3, Insightful

    You are running Windows, and you feel that running a program from the government reduces your security?

    Think about it - if the ONLY backdoor your Windows machine has is Uncle Sugar's, you are doing pretty well, what with all the Trojans, spyware, viruses, and bugs.

  100. A simple "No Thank You" by Anonymous Coward · · Score: 0

    will do. Otherwise I'll be off into some sort of paranoiac rant, black helicopters, aliens, secret societies...

  101. because security trough obscurity is no security by Edmund+Blackadder · · Score: 2

    That is a fact that has been widely recognised by most security proffessionals and people that take computer security seriously.

    For example banks do not use secret algortighms for their communications. They use well known algorithms so the mathematics community can examine them and point out any problems.

    Another example - computers games. They are usually closed source and yet almost every famous multiplayer game has been hacked.

    So no closed source doesnt give you much security.

    Open source would provide much more security because it would allow every one to check the code and correct mistakes.

  102. Re:If Al Gore made the Internet... by Skyshadow · · Score: 5, Insightful
    Thank you very much Florida.

    Don't blame Florida.

    Blame the puffy, middle aged guys named Chuck who think that the right to own firearms is the only civil libery that matters, since it's the only civil liberty you can use to make an exciting loud noise and put holes in cans.

    Blame the old people who don't understand the modern world, and as such believe all of the knee-jerk blame laying that demagogues spew out on cable news channels 24 hours a day.

    Blame people who see the whole world in moronic stereotypes. Blame the people who think that speech ought to be free only when it matches their own opinions. Blame the people with severely outdated understandings of capitalism who believe that big corporations can self-police and the market can self-regulate. Blame the people who are so cowardly that one terrorist attack which kills a few thousand people is justification enough to toss our most valued rights out the window. Blame the people who think that the flag (and not the hard-won liberties it symbolizes) is sacred. Blame the people who think that their religion should be forced on everyone, and think the founding fathers secretly wanted it that way despite rather obvious evidence to the contrary.

    Most of all, then, blame an education system that doesn't teach people how to think in an objective or independant manner. Blame parents who don't teach their kids to evaluate information or ask questions.

    But don't blame Florida -- those ballots were pretty confusing.

    --
    Every year during my review, I just pray the words "slashdot.org" aren't mentioned.
  103. Maybe the guv can patent away security flaws by hardcnxn · · Score: 1

    "It's hard to picture myself executing government provided software on my workstation"

    Don't worry. They'll grant Forgent a patent on all pictures of you NOT executing the government code, for security purposes. You will only be allowed to picture the above-mentioned process as all other pictures of you will be proprietary.
    A security recall will be necessary so you can have the new jpeg-filtration chip installed in your head, but the government is confident in their ability to perform this surgery due to the recent rallying of public monies and support for increased security projects.

  104. MiB? by bpfinn · · Score: 3, Funny

    Hmm... So along with protecting us from aliens, maybe the "Men in Black" will also run Windows Update for us too? ("Was that a security update?", "Nope, just a weather baloon." *flash*)

  105. What are those catch phrases? by Newer+Guy · · Score: 1

    Ahhh I remember.. I just got divorced. I've had a vasectomy. I won't come in your mouth. I'll respect you in the morning. and finally the #1 saying: I'm from the Government, and I'm here to help you! 'nuff said?

  106. We Need Software To Protect Us From #@ +1, Pot @# by Anonymous Coward · · Score: 0

    1. Seat warmer George W. Bush

    2. President Cheney

    3. President-Vice Rumsfeld

  107. Standards Documents by Atryn · · Score: 2, Informative

    Check out the Center for Internet Security where you will find posted the new Win2k and WinNT standard benchmark. Interestingly enough, there have already been benchmarks for other systems, such as Linux.

    --
    Come play Moral Decay!
  108. How to secure every PC in America by anthony_dipierro · · Score: 2

    1) insert windows boot floppy
    2) a:\format c:

  109. It's a cunning plan by Subcarrier · · Score: 1, Flamebait

    This makes it almost childishly easy for the government to identify terrorists and hackers. You pick your side: either install the software or join the Axis of Evil. The Evil Doers *will* be hunted down and captured.

    --
    "I have opinions of my own, strong opinions, but I don't always agree with them." -- George H. W. Bush
  110. Rule of the thumb by Thoron · · Score: 1
    I would like see the day when people learn diffrence between hackers and crackers.

    Simple rule of the thumb:
    • Hacking is legal, it's done by hackers.
    • Cracking is illegal, it's done by crackers.
    I hope some journalist reads /. in distant future and gets it. Maybe 3042?
  111. Rainbow Books? by NevarMore · · Score: 1

    a few years back i downloaded all the rainbow books (at 28K, that was a big deal) and perused them.

    has the government discontinued or updated that series? it had some good info on securing large scale computer systems such as those in big buisness and the banks as well as infrastructure control systems.

  112. Assume the worst by aoeu · · Score: 2, Funny

    Suppose that most computers are insecure. The (MS)OS gives up the HD to anyone who asks,users won't apply patches, the admin is an idiot, whatever.

    The Feds are already wherever they want to be and I think that they would rather be the only ones there. I still want to keep out the rest of the world and the Feds want to help. How could this be any worse than what we have.

    The really paranoid (or sensible) people will use strong encryption which is more to the point.

    All your database are belong to U.S.

    --
    All your database are belong to U.S.
  113. America's Army by CoreyG · · Score: 4, Funny

    They're releasing this software to check how well their backdoors inside America's Army worked. Duh!

  114. Well, this is new... by VValdo · · Score: 3, Insightful

    It occurs to me that when security tools such as nmap, or crack or airsnort or SATAN come from places OTHER than the government, they are seen as threats to Internet security. Some people in government even want to make them illegal.

    But when the government itself comes out with software to expose security holes, it's called the "Gold Standard".

    What gives?

    --
    -------------------
    This is my SIG. There are many like it, but this one is mine.
  115. All I have to say is this: by thedbp · · Score: 2

    Anyone who would run this software on their computer deserves whatever they get.

  116. Not a "chance", it's a fact... by The_Guv'na · · Score: 1
  117. Ask and ye shall receive (source) by verytass · · Score: 1

    How about the perl script it runs? If anyone bothered to prowl around the site, they'd find that the binary is a wrapper to run a perl script and that there are instructions to run the perl manually from your very own secure and audited interpreter.

  118. Re:All gov't-developed software is public domain.. by PastorOfMuppets · · Score: 1

    Technically, you're correct, all govt. property is owned by the public. So, technically, Area 51 is public property, but that doesn't mean you're going to get a tour of the place. That would be a security risk, and in the eyes of whatever govt. agency that developed this software, releasing the source would be too. In fact, I'd bet that reverse engineering it would be considered an act of terrorism.

    --
    If you don't have anything nice to say, shut up you stupid prick.
  119. Re:All gov't-developed software is public domain.. by The_Shadows · · Score: 5, Insightful

    That is not entirely accurate. All government developed software may wind up as public domain, but I would guess that most, if not all, of it will not be available for at least 20 years after it's written. If all the software (and especially source) was public, we'd have some major security holes and exploits possible. Just think about it.

    We've got gov't programs running major systems (though NT on Aircraft Carriers, IIRC). A lot of gov't created systems are running gov't machines. Much of the software is so specialized that it's probably not much use to any of us, but there's a few pieces that if crackers got a hold of would be disastrous.

    Just to illustrate this, one of the guys I worked with (he left, maybe a week after I started) had worked with the DoD before working here. Me, being the inquisitive student, asked about it. He told me that most of their programmers and engineers don't know what they're working on. The engineers get told, "build this part," not "build this part for this machine."

    Programmers are treated more or less the same way. They're not told to write a program. They're told to write a class, or maybe just a function. They aren't told what they're working on, just to code. The higher ranking/clearance guys then put it together.

    So, eventually, yeah, maybe we'll get to see the code. But there is a lot of classified stuff in the government. You don't get to hear about everything.

    And, correct me if I wrong, we don't even get to see the code for the America's Army game, do we? Of course it wasn't developed by them, just for them. Thoughts?

  120. Re:Website includes some source by verytass · · Score: 1

    besides the docos and exes, there's the perl script which the binaries wrap and instructions to use that directly. see the FAQ -- http://www.cisecurity.org/bench_FAQ.html#2.4 -- "I'm concerned about running an untrusted binary on my system. Can I run the benchmark test without running the cis-scan binary?"

    A:Yes. The cis-scan binary is really a simple wrapper program which has been linked against a copy of the Perl interpreter library (libperl.a) so that sites can run the tester without installing the Perl distribution. cis-scan simply runs the Perl code in the tester.sub file.

    Assuming, your system already has Perl installed, you can run tester.sub directly with only minor modifications:

    1.Edit the tester.sub file and locate the line which reads

    sub tester {

    Add an additional line above this line so that the file reads

    &tester();
    sub tester {

    2.If Perl is not installed on the local machine as /usr/bin/perl, change the first line of tester.sub ("#!/usr/bin/perl") to use the appropriate path name.

    3.Save your changes to tester.sub and exit the editor

    4.Execute tester.sub directly by running /opt/CIS/tester.sub

  121. Secure Stable User Friendly OS ? by Quazion · · Score: 2

    Thats what they should create instead of making it MS easy, instead of MS doing its job let the US goverment do it.

    Not that i care. 1 i dont live in the US, 2 i dont use MS products.

    Quazion :)

  122. Re:All gov't-developed software is public domain.. by BlueWonder · · Score: 2

    According to many online sources (e.g. the U.S. Copyright Office or Lawnotes), works created by the U.S. Government are not copyrightable. However, the government can aquire copyrights for works created by others.

  123. Re:Redundant by Shadow+Wrought · · Score: 1

    Oxymoron would imply that Window$ is actually secure. The point of the joke is to point out that it is not hence, redundant. But thanks anyway. No one else seems to understand it either. Oh well...

    --
    If brevity is the soul of wit, then how does one explain Twitter?
  124. Stupid stupid Ashcroft by Slur · · Score: 2

    Wow, so I guess anyone who believes there's room for improvement in the federal government is a terrorist! Wow, how can we trust a government or a culture that labels reformers as terrorists? They don't trust us, we don't trust them, so they don't trust us.... Something's got to give.

    Sounds like the government is trying to co-opt faith for itself.

    Isn't it bad enough that they've started using the word "terrorist" for anything and everything that disagrees with the status-quo?

    --
    -- thinkyhead software and media
  125. can Microsoft be sued if terrorits use... by kipple · · Score: 2

    can Microsoft be sued if terrorits use holes in M$ operating systems to do cyberspace attacks that can cause real victims? ..thinking about the death penality introduced for "hackers" guilty of death of people via computer attacks..

    on the other hand, YES I KNOW that gnu/linux, BSDs, etc. have holes, but who're you going to sue for linux? the owner of the name 'linux'...? Or maybe m$ cannot be sued because of their EULA that denies any responsibiliy...?

    funny..

    --
    -- There are two kind of sysadmins: Paranoids and Losers. (adapted from D. Bach)
  126. What seems to be the problem? by Guppy06 · · Score: 2

    "(we were supposed to be *increasing* the security of the PC's, right?)"

    How long ago did the NSA release their security templates for Windows 2000? In that time, have there been any documented rootings of a Windows 2000 machine that is using said security template? Anyone?

  127. Re:All gov't-developed software is public domain.. by mangu · · Score: 2

    They are not copyrightable, but they may still be secret. Suppose software used to develop new weapons were public domain?

  128. strong crypto for all by phaxkolumbo · · Score: 1


    First of all, I'm not an american, so you decide my bias...

    ...but, if they want to secure computers, why (oh why) don't they promote strong crypto for all?

    This may sound whiny and naive, but, really, when you think about, this would help a lot. At least that's the way I see it. Cryptographic signing, secure communications, the whole lot.

    Looks like they just want access to the US citizens' computers, even if the intentions seem good on the surface.

    Well, that's what I think, anyway.

  129. If they were serious by Anonymous Coward · · Score: 0

    If the Government about security it would stand behind OpenBSD. How many YEARS without a root exploit?

  130. Yes, It Is. by Anonymous Coward · · Score: 0

    And not just stupid but fanatically dangerous, at least as much so as those they are attempting to whip up hatred and paranoia against. At least those guys had an honestly held ideology, rather than just a policy of screwing everybody simply for more personal and institutional power, bigger budgets and further promotion.

  131. Distribution? by ProfMoriarty · · Score: 2
    This plan will include the distribution of government-provided software to help clean up insecure Windows installations.

    Oh great ... now I'll have >100 U.S. Government CDs laying around ...

    Will they pack them in tins?

    FTHI (for the humor impaired): This is a spoof of AOL, this is only a spoof. Move along there is nothing else here.

    --
    Karma? Karma? I don't need no stinkin' karma.
  132. Didn't Microsoft already do this? by Anthracks · · Score: 1

    Ignoring people's opinions on the quality of any security scanner Microsoft might develop, isn't the Baseline Security Analyzer pretty much the same thing? And it's only made by one shadowy evil coproration, instead of many shadowy evil corporations AND the shadowy evil government!

    --
    Rock over London, Rock on Chicago. Wheaties: Breakfast of Champions.
  133. the government should FINE Microsoft by mangu · · Score: 3, Interesting

    How about the government fixing the problems and charging Microsoft for the cost? I wouldn't trust a Microsoft solution for the problems they created themselves. If the problem is really as serious as the article author wants us to believe, a serious and hard-working government would impound the Microsoft source code and contract a team of experts to create a solution.

    1. Re:the government should FINE Microsoft by pmz · · Score: 2

      How about the government fixing the problems and charging Microsoft for the cost?

      Because that would bankrupt Microsoft (perhaps not so bad, but humor me).

      There are tens upon tens of millions of lines of code in Microsoft software ranging from Win 2K to IIS to IE to whatever else they bought and rebranded.

      I believe very strongly that software complexity increases exponentially with the size of the software. Now, given that Microsoft harbors perhaps the most complex system on the planet, auditing it in OpenBSD fashion would make that $40 billion evaporate so fast Microsoft would almost think they were just in a dream for all these years.

      Complexity--unmananged complexity--spawns risk and cost that Microsoft's marketing department is masterful in covering up. Fortunately, I saw through all this and switched to OpenBSD, for simplicity, and Solaris or Linux, for relative simplicity, for all of my tasks.

  134. all your windoze boxes are belong to the gov't! ;) by DC1 · · Score: 1

    I wonder who came up with this "bright" idea... In my opinion i *might* do (none/one/many) of the following: 1) Run Gov't@Home seti clone for NSA's cause 2) Provide Feds with some inforamtion/backdoor 3) Provide means of updating XP with bogus licenses? 4) Make all thinking people more paranoid than one can image?

  135. Two words... by snake_dad · · Score: 1

    Clipper XP

    --
    karma capped .sig seeking available Slashdot poster for long-term relationship.
  136. Uhmm... by kludge99 · · Score: 1

    The Government can't even secure their OWN computers ... Why would any semi-intelligent person even allow them to try to secure their's.

  137. Offtopic-2nd Amendment matters the most by dfenstrate · · Score: 2

    Blame the puffy, middle aged guys named Chuck who think that the right to own firearms is the only civil libery that matters, since it's the only civil liberty you can use to make an exciting loud noise and put holes in cans.

    For the most part, I agree with you, but not with this crack about firearms. If you where trolling, or being sarcastic, I'll bite regardless.

    It may be the only civil liberty that matters, because as armed citizens, it allows us to preserve all the other civil liberties. The world, or our nation, is not so utopian, so full of people looking out only for their brethen, so lacking in criminals, as to allow us to disarm ourselves.
    Criminals prowl our streets. But they do so with far less frequency in areas where even a 20th of the population is likely to be armed (florida-they still go after tourists- Vermont, New Hampshire, or, for the Europeans out there, switzerland.) The police have no obligation to protect you (see Riss vs. New York City)so you must protect yourself. The surest way to do that is to own a firearm, and know how to use it.

    Our government is infringing on our rights more each day- being a low user number slashdotter, I'm sure you've been reading about the DMCA and it's ilk for quite some time. How long before our own government becomes as oppressive as Great Brittain was originally? Betcha it'll be a lot longer- if ever- as long as the populace is well armed. Incidentally, the United Kingdom now has the strictest gun control laws in Europe- and the highest violent, confrontational crime rate. (Google cache of Boston Globe)

    Gun Restricting laws protect no one but criminals, because only honest people obey them. If someone is willing to ignore laws about theft, rape, and murder, what makes you think they'll obey gun laws?

    The right to live includes the right to defend one's life effectively. This was once best done with a spear, then a sword, then a musket, now a handgun. The right to defend our lives against the lawless, and ourselves against tyranny, ensures all other rights. Without the natural right (listed, not given by the 2nd Amendment) to arms, all your other rights are disposable at the conveinance of criminals or the ruling class.
    Karma to Burn, do your worst moderators

    --
    Alcohol, Tobacco and Firearms should be the name of a store, not a government agency.
    1. Re:Offtopic-2nd Amendment matters the most by gad_zuki! · · Score: 3, Insightful

      I don't know whether to laugh at your post or just feel sorry for you. What kind of armed resistance can even a large militia give against even light armor and artillery from the US's military? None.

      I have a gun license and am a gun owner, but I'm not stupid enough to buy into this ridiculous "citizens will overthrow a corrupt regime" conspiracy.

      I think both sides of the gun control issue would do better if they understood weapons to be tools for self-defense and not tools for revolution or tools for crime.

      Actualy, gun control laws do protect. In many countries gun licenses are earned through a process much like getting a driver's license. There are permits and tests which weed out those unable to perform the simplest attempts to use a weapon safely. In the US all you need is a face and you can walk off with a powerful and dangerous tool without the slightest idea of how to use it properly or how you can use it legally.

      Also arguably the Brady bill has stopped many domestic disputes from turning into murder.

    2. Re:Offtopic-2nd Amendment matters the most by mOdQuArK! · · Score: 2
      What kind of armed resistance can even a large militia give against even light armor and artillery from the US's military?

      The primary safety against the use of military force against civilians is to make sure that the military forces have many connections to the civilian population (family, friends, etc). It's difficult to get many people to shoot in cold blood an unarmed man or woman they were just having a beer with the other day. They're more likely to turn their weapons on the people giving the orders.

      In many of the situations where a country's military has been used against the civilian populace, the military has been carefully conditioned for personal loyalty to the people giving the orders, rather than to "protecting the populace". They're isolated from the rest of the populace, prevented from establishing any positive emotional ties, given special privileges (to make them feel good about their positions) & careful propaganda.

      If the military didn't care about the general populace, I sincerely doubt that the minor weapons available to a typical citizen in the US would slow any properly equipped military unit down, even with many such armed citizens (especially considering the US preference for airstrikes).

      If you want to worry about that kind of thing, then worry about all of the automated drone systems which the US military (and the related defense industry) are developing. Whose hands are going to be on those triggers?

      It might be good to worry about simple incompetence as well - wasn't there a story recently about somebody who ended up with a bomb in their living room - in TEXAS?

  138. I love this! by Anonymous Coward · · Score: 1, Interesting

    This confirms what I humbly call my 'circle theory'. In essence, anything pushed to an extreme wraps around and becomes its own opposite. Witness the macho man, who works out shirtless with other men and hates women, we think of him as a super-male, but he is so male, he becomes a homosexual.

    Capitalism, especially in the US, combined with your taste for religion, has turned into communism.

    Where to flee? the more rational among you ask. Canada? Hardly. We're the US' little lapdog, the annoying little curly-haired with the high-pitched yelp kind.

    No, you have to go where circle theory has also had time to work, but from another starting point: RUSSIA. That's going to be the next great country to live in. Russia needs YOU to make it a great country.

    Let the US become increasingly insular and insane. There's nothing you can do with a mental patient the size of a country anyways.

    1. Re:I love this! by dlt074 · · Score: 0

      if they let me mod... i'd give you some points. some co-workers and i were just talking about Russia the other day. their flat tax system sounds great, but i'm far far far from making the leap.

  139. And the point of this is? by zangdesign · · Score: 2

    Even if I was running the world's most insecure operating system, which waved it's little electronic "tool" in the face of every hacker, skript-kiddie, and 733t-wannabe out there on a continual basis ...

    THERE IS NO WAY I AM GOING TO RUN GOVERNMENT MANDATED SOFTWARE ON ANY COMPUTER I OWN.

    I will destroy my computers first, as painful as it might be.

    That is my final word on this subject.

    --
    To celebrate the occasion of my 1000th post, I will post no more forever on Slashdot. Goodbye.
    1. Re:And the point of this is? by Anonymous Coward · · Score: 0

      No AmryOps on your PC (and its free)

  140. More Free CD's! by KC7GR · · Score: 2

    Think of it this way: AOL made it a point, for the longest time (they may still be doing so), to plaster everyone they could think of with CDs via mail. There's no reason to assume Our Government would be any different.

    In both cases, the solution is the same, and you don't even have to take the CD out of the mailer.

    First, place the whole thing in a microwave oven and blast it for about three seconds. Next, mail it back to Lord Protector Ashcroft with a note explaining that you'd found a virus on the disc, and that it has been destroyed to prevent the further spread of such.

    If nothing else, it'd be good for the amusement value.

    --

    Bruce Lane, KC7GR,

    Blue Feather Technologies

  141. Why? by Psx29 · · Score: 2, Informative

    Why can't you just use the already provided NSA guidelines to secure your windows machine.

  142. reminds me of this one time... at band camp. by dlt074 · · Score: 0

    "i'm with the government, i'm here to help" Janet Reno -- Waco TX 1993

  143. Big Brother Wants You! by PipianJ · · Score: 1

    Aside from the obvious removal of privacy... Ever think that this could be the culmination of EVERYTHING?

    *fade to an office overlooking Capital Hill*

    Congressman 1: What are we going to do? We've got so many things we've got to do before the next Congress... There's Microsoft, that wants us to stop bugging it about its bugs and monopoly and instead make it illegal to write open-source code... There's the RIAA/MPAA that wants us to make sure that only RIAA-representatives assigned to every households can unlock a CD for a single play after paying them $200... And there's the whole "terrorism" thing so we can take away privacy...

    Congressman 2: I've got the solution to all of our problems!

    Congressman 1: Eh? What?

    Congressman 2: How about... We spend millions of tax dollars to code something that allows us to look at everyone's data on their hard drive, and monitors for any sound card and video card activity whatsoever... Reporting that to the MPAA and RIAA so they can charge people for it!

    Congressman 1: Sounds good... But I'm not sure we could get it through all the angry protesters...

    Congressman 2: I'm not done yet! I'll get to that! First... We need to make it Windows-only...

    Congressman 1: I'm listening...

    Congressman 2: Make everyone have to PAY for it...

    Congressman 1: This idea is sounding better...

    Congressman 2: And make a law requiring that this specific Windows-only software be installed on every single computer, RETROACTIVELY! Regardless of whether it has Mac OS, Linux, or Windows! Or else they'll be put in jail for 5 years...

    Congressman 1: It's still missing something though...

    Congressman 2: Let's tell everyone that it's a patch for Windows that will make it more secure!

    Congressman 1: THAT IT! Brilliant my esteemed collegue! Simply brilliant! Let's bring this up in the Senate tomorrow! They won't be ABLE to say no!

  144. What has happened to the criminals? by Fuzzums · · Score: 1

    Nowadays, in the post 911 days it seems, as fas as computers are conserned, you are either a hacker or a terrorist, but what has happened to the straight forward criminal doing computerfraud?

    Maybe a hacker hacks computers,
    a criminal steals computers,
    and a terrorist blows up computers.

    These are such confusing days...

    --
    Privacy is terrorism.
  145. Mod parent up, Insightful by pgilman · · Score: 1


    well stated; glad to think that reason still exists somewhere. thanks for taking the time to write this.

    --
    if i'm a grammar nazi, you're an illiteracy nazi.
  146. more worried... by Anonymous Coward · · Score: 0

    I'd be more worried about when they require everyone who accesses the internet to be running thier "security" program.

  147. Fire Department by Anonymous Coward · · Score: 0

    Remember, kids, the fire department works for the government, too. Just think about what they're really doing when they bust down your door and trash the place just because there was smoke pouring out of the windows.

    I'm just trying to figure out how they trick people into plugging 10 computers into one outlet in the first place.

    (Note: this is a backlash against the paranoia above. The government is not out to get you. Some parts of it will do things you don't like, and you have a right to complain. Other parts actually do Good things. They're all trying to do the Right Thing, but sometimes they fail really miserably.)

    1. Re:Fire Department by Noel · · Score: 2
      They're all trying to do the Right Thing, but sometimes they fail really miserably

      Yes, they are all trying to do what they think is the Right Thing. That's not necessarily the same as what I think is the right thing. Sometimes their perception of the Right Thing is quite different from mine.

      I find that the higher up a person is in any organization, and the larger the organization, be it government or corporation, the more differences there are between their perception of the Right Thing and mine. The higher a person is, the less I am likely to implicitly trust them until I have seen convincing evidence of trustworthiness.

  148. Someone should crack that tool immediately. by Anonymous Coward · · Score: 0

    The recommendations would not be mandated by law, Clarke said

    For now. Until govt. sites get hit by DOS attacks from unsuspecting users who got infected while downloading updates from Windows Update.

    There is way too much room for abuse from both the users and the authorites.

    From my experience with security, centralizing or creating a standard program like that creates one point of failure of the whole security system.

    e.g one could create a similar program and send it unsuspecting users...

    What they should do is create a standard guideline for the likes of M$ to create efficient methods of updating and patching software. If they don't adhere to the standards, fine them heavily.

  149. the same people? by commodoresloat · · Score: 2
    The reason is that I worked for the same people that Albert Einstein did

    Who was that; the KGB?

    ;^)

    1. Re:the same people? by goid · · Score: 1


      Nope.

      --
      "Star Wars Moral Number 17: Teddy bears are dangerous in herds."
  150. Ultimate Trojan by ThePlumber2 · · Score: 1

    I like how the gov sets this up as a "help service" for people. Created by the CIA, NSA, and "Private Corporations". Must be really good software.

    Hmmm... Isn't a Trojan Horse supposed to look appealing?

    Then they prattle about how they want the "Vendors" to be responsible. Who pays?

    We make the bugs, they ship them. They don't need a bill for this either I bet. No wrangling around in a senate because it is a good for them thing.

    Nice manuevering by the gov and corps. Doens't anyone understand why they get to take the money? Because they are "Smoove" enough to be able to get at it. And we are all sheep.

    Line up.

    --
    Thanks, Steve
  151. Re:All gov't-developed software is public domain.. by printman · · Score: 2

    Actually, you can file a FOIA request for any gov't software, including source code. As with printed documents, they can either blank out sensitive information (leave out code) or deny the request for national security or privacy reasons.

    --
    I print, therefore I am.
  152. TRUE story of government security! by Anonymous Coward · · Score: 1, Funny

    /.
    I was working at an aerospace center that Shall Not Be Named, doing various things related to testing missiles and preparing for a rain of thermonuclear death on the dirty commies (now superseded by dirty sand-nxggxrs).

    This suit from Lockheed comes in, and says "Let me see the checksum on your disks". To which I cogently replied "whurahuh?"

    The suit self-importantly explained that when the Navy did tests, they first performed a "checksum" on the data storage devices attached to their data acquisition systems. By comparing the checksum to a number he had cleverly kept in his wallet on a soiled scrap of index card, he could tell that the insidious Reds had not tampered with the system in order to mislead God's Own Nation.

    A light went on, and I said "Oh! You'd like a cyclic redundancy check code to be used on all the system and testing code, to ensure that change procedures are adequately followed! We can do that, I'll do some research on the algorithms and whip something right up for you."

    "No!" the suit cried, "I want to CHECKSUM the DISKS, not the PROGRAMS! I must have a checksum of everything, to ensure the safety and security of America! And don't try to hoodwink me with your technical mumbo-jumbo, I'm an ENGINEER!"

    I (patiently and tactfully, I thought) explained that this was impossible - I was quite familiar with the systems the Navy was using, and there were highly volatile swap areas on the hard drives that changed constantly. I even (unwisely) attempted to explain that checksums were nearly useless, and that what most people meant when they said "checksum" was ECC or CRCC, a more useful technique.

    The suit stormed off to report my recalcitrant incompetence to my boss. My boss called, and asked me what the hub-bub was about. I replied, to the best of my remembrance, "That idiot wants to make sure the test environment doesn't undergo unaudited code changes or random bit-rot. I can provide the level of security he wants, we just buy a nice Mosler safe, sink it into the concrete bunker wall, and give him the keys and combo. We label a full set of disks 'lockheed' and let him keep them in the safe when we aren't doing Lockheed tests."

    The boss said, "That isn't what he wants. He wants security just like the Navy does it. Give him his checksum."

    I got annoyed, and pointed out that anyone with physical access to the systems could readily substitute a program that simply printed out the same number every time.

    The boss said, "Now you're getting it. What do you think the Navy does?"

  153. I'm Doing MY Part by Compulawyer · · Score: 3, Funny
    From the article:

    "Every American relies upon cyberspace and every American has to do something to secure their part of cyberspace," Clarke said of the plan, which will be released September 19 in Silicon Valley. . . Clarke spoke to reporters as well as government and corporate officials to announce government-wide standards for securing Microsoft's Windows 2000, the most commonly used operating system for government and corporate computers.

    I'm doing my part. I'm using a Macintosh.

    --

    Laws affecting technology will always be bad until enough techies become lawyers.

  154. With Freebies! by CrazyDuke · · Score: 1

    I bet it comes with lots of extra cool features like "Magic Lantern" and a nice little utility that searches and catalogs all potentially illegal files on your hard drive. Even a phone home program that reports suspicious activity! Wow, I'm just dying to have this on my computer! Especially with the government's concern over its citizen's civil rights, freedoms, and privacy despite the war on terror.

    In other news today:
    Multiple flying pig sightings reported...
    IRS desolved...
    Congress votes itself a paycut...
    Blizzard conditions reported in Hell...
    God kisses Satan; onlookers applaud...

    Shall I go on? Think about it; who's security is really thier top priority?

    --
    Any sufficiently advanced influence is indistinguishable from control.
  155. and the government's different how ?? by Archfeld · · Score: 2

    they want World Domination, Control of all things Monetary, even your labor potential.....
    It has been a long time since a political agenda was not transparent as well...make as much money for your corporate master as possible...

    --
    errr....umm...*whooosh* *whoosh* Is this thing on ?
  156. I trust the Government more than I trust MS by Etcetera · · Score: 2, Insightful


    To all the libertarian and Ayn Rand-obsessed morons who think that corporations are the end-all and be-all to the worlds problems and exist to keep the government in check, please go away.

    Quite frankly, the government IS accountable to the people and DOES have to pay the penalty when they do something Bad. When MS does something bad, 94% of the computer-using public just has to bend over and take it. (The rest use a Mac.)

    Although it smacks of scary conspiracy theories and trojan horse monitoring programs, the government CAN'T do something like that. The US Government is not Kazaa. It will not install Gator on your PC. This is not a hidden backdoor to allow Carnivore to track your every move. Do you think something like that could remain hidden for ANY length of time with the amount of scrutiny this program will receive? No.

    And if it turns out *to* have a monitoring program in it, stand up for your rights (if you're a US citizen) and VOTE. Call your congressmen and senators. Bang on their doors until they explain themselves and do something about it.

    Quite frankly, I'd install this over the next version of Windows Media Player any day. Who knows what random shit MS will try to do with that...

  157. Heh by Xoxiro · · Score: 1

    Want bugs out fast? Call The Man!

    An Orkin Commercial which struck me as funny in light of this story.

  158. Gov't security software? by ColGraff · · Score: 2

    If it was free as in beer (or speech), I'd give it a look. They can't make my windows xp install any less secure than it is fresh off the cd, and I don't think they'll install some sort of evil spyware. Not saying I'd keep it, though, just because I don't really havy any need for better than marginal security, and this if this is anything more than a registry-tweaker, if it's an app than runs in the background, I probably won't want the overhead.

    --
    I'm the stranger...posting to /.
  159. Re:All gov't-developed software is public domain.. by Rayonic · · Score: 2

    Well, other than 'classified' stuff, isn't it usually released into the Public Domain?

    And about the Army game, they don't really own the code to that. The engine is licenced from Epic Games, so it's not really theirs to distribute.

  160. Nope. by Anonymous Coward · · Score: 0

    You apparently never got a security clearance. It IS the FBI's job. So there.

    1. Re:Nope. by AintTooProudToBeg · · Score: 1

      You apparently never got a security clearance. It IS the FBI's job. So there.

      You are wrong. The DSS handles this.

  161. I'm paranoid. by Anonymous Coward · · Score: 0

    It sounds like a really good idea.

    But with the constant abuse of the word 'security' by both companies and lawmakers when it's used in the context of DRM, sharing and creativity, I'm not sure if the program could be trusted.

    Unless they release the source, of course, because then we'll find out if they're doing what they're saying.

  162. Re:If Al Gore made the Internet... by Idarubicin · · Score: 2, Insightful
    Blame the puffy, middle aged guys named Chuck who think that the right to own firearms is the only civil libery that matters, since it's the only civil liberty you can use to make an exciting loud noise and put holes in cans.

    Blame the old people who don't understand the modern world, and as such believe all of the knee-jerk blame laying that demagogues spew out on cable news channels 24 hours a day.

    Blame people who see the whole world in moronic stereotypes.

    Although I may agree with many of the sentiments of the parent post, I must ask--does anyone else see the rich irony of opening the message with the first two statements above, only to follow with the third...?

    --
    ~Idarubicin
  163. I'm paying for Windows Mistakes!!!! by tacocat · · Score: 2, Insightful

    I quit! Now my tax dollars are going to pay for software to protect Windows from their own shitty design!

    Some days it doesn't pay to get out of bed!

  164. It seems to syncronize with the new hackers tools by chanio · · Score: 0

    I have been reading today about new tools that hackers are delivering for Windows users as well as Linux such as a way of encrypting files inside GIFs or BMPs. And new P2P ways of going through WWW.
    Would anybody comment about the peekabooty project?

    --
    Rwe obliged 2 save our future by choosing:O3 hole-greenhouse effect instead of accepting everydays gossip-nonsense chat?
  165. Is it Just me? by hagar� · · Score: 2

    Or are the terms Hackers & Terrorists becomming more closely related in recent days?

    How long before hacking becomes synonomous with terrorism in the Media?

    And who is then next?

    --
    Insert something insightful here, or I'll insert something painful there.
  166. Re:All gov't-developed software is public domain.. by neurosys · · Score: 1

    Umm.. if all govt. software is public domain, then where the public accessiable source for the project Carnivore virus brought to you all by the FBI in the name of "National Security", the spyware installed unknowingly on various system to "Monitor for illegal activity"? Keep in mind people that your govt. dumped biochemical weapons on their own people during Vietnam. You think YOUR best interests are at hand with their new "Secureware"?

  167. Why do they keep thinking I'm a terrorist? by interstellar_donkey · · Score: 2

    I have used file sharing software.

    I have purchased illegal drugs.

    I have snooped around my university's computer system when I was younger because I was curious, even though I probably shouldn't.

    I have made a joke about the sobriety of the pilot on an America West flight.

    I also am a patriot and love America. Why the fuck does the government, media, and corporate world keep wanting to throw me in the same catagory as a bunch of psychopathic assheads who fly airplanes into buildings?

    --
    The Internet is generally stupid
  168. Re:This is a great idea. by Anonymous Coward · · Score: 0

    you need to brush up on your trollin' skills, young padawon.

  169. Some of the most feared words... by CptnKirk · · Score: 2

    We're from the government and we're here to help...

  170. Outraged Conservative here. by Erris · · Score: 3, Informative
    JFK? Who cares about a single man?

    We are talking about the most massively unAmerican activity since voluntary compliance income taxes. The government wants me to install software on my computer, specific to a certian insecure comercial operating system I don't trust to begin with. No fucking way. At any rate, I happen to work for the government, and I've also held a few commercial jobs, and speaking on a reletivity scale, the government network has a much better security model than any place I've ever worked

    They got M$? They are incompetent, fanatical or not because they can not possibly autit all of M$'s massive core of crap, nor can they trust the tools M$ provides them. M$ has no security at all.

    This new uberpatch will NEVER accomplish it's stated goal. IT WILL BE A CARNIVORE that uses your machine's cycles to do it's dirty work. There's an obvious cure for this, the use of free audited operating systems. If they would come out and advise that I'd be much much happier, and NO I don't need your stinking secret patch.

    Remember the fourth amendment? You know, security in your personal papers and effects? This is NOT the kind of security the the bill of rights had in mind.

    Mr. Ashcoft, I call on you to remember your oath of office to uphold the constitution of the United States of America. Let me remind you exacly what you swore to uphold:

    The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.

    --
    DMCA, Hollings, Palladium. What might have sounded like paranoia is now common sense.
  171. SATAN for the desktop... by crovira · · Score: 2

    This should scare the ever lovin' crap out of lots of people when the see what a pullulating dish of agar their office, SOHO and home systems are.

    Its not just M$, (though people will be throwing a few of these out the window when they see sheer size of the system "vulnerability list",) but this should be part of the connection "pre-flight" process for everybody who is connecting to the net.

    --
    MSBPodcast.com The opinions expressed here are my own. If you don't like 'em... Think up your own stuff.
  172. I got better tools by Erris · · Score: 3, Interesting
    Debian
    OpenBSD

    I can't believe they think that yet another uber patch is going to fix Windoze. We all know the answers, and we all know that the ablsolute worst freaking securtity possible will come from a monoculture of M$ junk. This is NOT an honest move and it indicates that someone is serious about nationalizing computing through M$ .NET, Paladium/dongle hell.

    Yes, now is the time for hysteria.

    --
    DMCA, Hollings, Palladium. What might have sounded like paranoia is now common sense.
  173. OpenBSD isn't perfect by smiff · · Score: 1
    You mean that waste of 1,000,000 of your tax dollars on a piece-of-shit distribution that is less effective than OpenBSD and jail (total cost to the taxpayer: $0)?

    You may notice that OpenBSD now claims "One remote hole in the default install, in nearly 6 years!" If OpenBSD utilized an SE Linux type security system, the remote exploit from two and a half weeks ago would have been far more limited in its scope.

    Security Enhanced Linux was the motivating factor for the security framework being incorporated into the 2.5 Linux kernel. I would hardly consider that a waste of my tax dollars.

  174. Re:All gov't-developed software is public domain.. by millette · · Score: 1

    With a low number like 255371, I figured you have been reading /. for a while already, no? Or did you find that account in a crackerjack box? Security thru obscurity isn't. When are people going to get this? Also, other replies mention blanking our portions for security reasons - that would be the sensitive data, it shouldn't really be the code/method that is blanked.

  175. Re:All gov't-developed software is public domain.. by John+Hasler · · Score: 2

    Works produced by government employees on government time are effectively public domain. However, this does not require the goverment to distribute copies of such works. It just means that should you somehow acquire a copy of such a work they can't sue you for copyright infringement should you make copies of it.

    Works produced by government contractors are not public domain, even if the government paid for their production.

    --
    Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
  176. Good idea, but I have a better one by Anonymous Coward · · Score: 0

    Hey, I have a better idea... Why don't ENGINEERS WRITE SOFTWARE THAT DOESN'T HAVE SECURITY HOLES. In this rare case, the intrusive government is actually doing something to help individuals overcome the problems created by programmers. HORAY for the government that I bash on such a regular basis, and shame on programmers who created the problems in the first place.

    BTW, You don't have to explain to me why engineers don't have time to write solid code, its all about making a living. But, don't you think that MS guy who made thousands of servers vulnerable could have spent a little less time downloading pirated porn and a little more time reviewing code? ;)

  177. Getting even more Offtopic by dfenstrate · · Score: 3, Insightful

    Well, you're absolutely right, with the guns people are allowed to purchase now, your average citizen would stand no chance against artillery or light armor. You might want to consider, though, how likely it would be that anyone would order domestic artillery or light armor strikes, no matter how difficult the situation. But it's late at night, and I don't feel like arguing that point right now, so I'll move on.

    Firearms are tools, Period. They can be used for self-defense, for crime, or in some historic events, revolution. The history of the US, and the history of Switzerland, and now even Israel, show that honest folk are the majority, and the more of them that go around armed, the less crime there is, or the lesser the impact of it. (armed Israeli citizens where instrumental in stopping a recent machine gun attack at a shopping plaza. Armed El Al employees stopped the July fourth attack at LAX, not any US cops or TSA employees)

    So if you think that Concealed Carry Permit holders should be licensed like drivers, I agree with you, provided they are licensed exactly like cars.

    1. There are no restrictions on the possession or use of an automobile on private property. You can let your twelve year old son drive your F-350 across the family farm if you care to. The F-350 need not be registered or insured, though you'd have to pay taxes on it. The same should be true for guns- no restrictions on the possesion or storage of any reasonable firearm on one's own private property. (I happen to think reasonable is anything short of Anti Aircraft Batteries. Think it's crazy? The swiss allow their citizens to own anti aircraft guns. Your line may be different.)

    2. Licenses are issued without question to all who qualify.

    3. Associated costs are not so high as to prevent those who may need to defend themselves the most- poor inner city folk, for example.

    4. A Concealed Carry Permit in one state is valid in any other.

    5. There are no waiting periods associated with purchasing guns, nor any limit to the amount of guns one may purchase.

    6. Operating or brandishing a firearm while intoxicated would definatly be illegal.

    As for the brady bill saving lives- the Journal of the American Medical Association seems to think they haven't done a thing: "Our analyses provide no evidence that implementation of the Brady Act was associated with a reduction in homicide rates. In particular, we find no differences in homicide or firearm homicide rates to adult victims in the 32 treatment states directly subject to the Brady Act provisions compared with the remaining control states."
    Full text here

    Based on that, I would have to say that the Brady Bill hasn't stopped any domestic disputes from turning into murder, Unless you find the AMA to be less than authoritative in matters of public health.

    I personally think that waiting periods are actually more dangerous to women, as if they know they are in imminent danger from an estranged husband or boyfriend, they are unable to arm themselves. A woman with a gun can stop an attacking man. A woman without a gun stands much less of a chance, as most men are physically stronger and larger than most women.

    Quoting Jacob Sullum from reason online (only because he says it well)Supporters say a waiting period allows potential murderers time to "cool off." But anyone who leaves the scene of an argument, drives to a gun shop, buys a weapon, loads it with ammunition, and returns to kill his interlocutor can hardly be said to be acting in the heat of the moment.

    I was going to post alot more, then I realized you're in support of handguns for self defense, so if I prattled on, it would be pointless.

    --
    Alcohol, Tobacco and Firearms should be the name of a store, not a government agency.
  178. eh... by MenTaLguY · · Score: 3, Informative

    Given debuggers and disassemblers, people are going to "read" it anyway. But there's no sense in them being spiteful about withholding source.

    --

    DNA just wants to be free...
  179. um, take it one step further... by MenTaLguY · · Score: 2

    You'll need to boot from clean boot media that wasn't in the machine at the time of installation.

    Otherwise you could be booting a modified kernel that would hide any changes made.

    --

    DNA just wants to be free...
  180. Vote "No government" by Anonymous Coward · · Score: 0

    This should be a valid option in any election. If the majority of people want to live free in 4 year increments, then so be it.

  181. What are you hiding? by Anonymous Coward · · Score: 0

    If you aren't hiding anything then why do you care? Only bad people care about hiding something.

    Sir llort

  182. I secure my own systems by Anonymous Coward · · Score: 1, Funny

    I would rather sand-paper a bobcat's ass in a telephone booth than install "government approved" software on my systems.

    No thanks, I secure my own systems.

  183. Re:All gov't-developed software is public domain.. by moogla · · Score: 2

    The example for programming is not the norm, but an extreme case your friend told you to impress you. In my experience, if you're working on a program for some DoD project, you're either cleared and mired in it or your uncleared and stay 100 feet away from it. In the few cases where it's possible, you could be doing something like what you mentioned, working with the parts that seperate are unclassified until they are brought together. I've done that once, but not because I wasn't cleared. I just didn't understand it. :-D

    Or maybe that's just with the FFRDCs... but I thought they did the majority of the DoDs engineering work.

    But anyway, yeah most code doesn't see the light of day not so much because the DoD is involved but that it is "owned" by the RDC or the group within the DoD that was responsible for it. In the case of the RDC, there's no legal requirement to disclose the code at all to the public, but the sponsor (DoD) can still check it out.

    --
    Black holes are where the Matrix raised SIGFPE
  184. Something Like this Way Back When... by lizzybarham · · Score: 1

    Hi, I read some book on internet and unix security put out by o'reilly and IIRC there was some security-related audit software the government had then (Spring 2000). It came in a binary form so I was a bit suspicious but nothing wicked became of it.

  185. I want my mommy! by Mar.Nurevo · · Score: 1

    To think, the system is so fucking scared that it will resort to good ol' spying in the name of freedom. How long will it be till they take the bite that proves to be their last? They know that someday there will be people with the guts to throw a monkey wrench in the gears and they want to stop it before it happens. They might achieve some part in their plan but thay can't get us all. It is my firm belief that they will get what they deserve and the victors will stand strong and proud. Thats if it is really spyware cause you dont really know till you see the source; But I can't get over this not trusting the goverment thang that plagues me...maybe im just nuts. Oh well, back to reading Marx and dreams of utopia.

    --
    I once caught my nemesis watching me through a window but to my surprise it wasn't a window...it was a mirror.
    1. Re:I want my mommy! by lizzybarham · · Score: 1

      To the best of my understanding, the government's aim in this regard is to provide an auditing facility to help lock-down end systems and they have no intention whatsoever of using this to spy on people.

      As far as a marxist society goes, history has proven that all marxist governments have been extremely corrupt as where the US has a fairly open form of government, allowing one another to audit the other. Further, we have the power to vote which help insure that the "old boy network" is not automatically favored (although I am sure there is some of this in the govn't just as it exists within most corporations).

      It is this internal auditing facility that helps the people by imposing certain boundaries on what the government can and cannot do.

      I'm not saying that the USA is perfect as it's not. Indeed, the best government would be a "Benign Monorchy" such as a believer in Jesus has in the Kingdom of God (which envelopes the USA, btw). However, in regards to worldly governments, the USA is the closest to ideal than any other government on the planet because it is "by the people, for the people, and of the people" - which is a big deal.

    2. Re:I want my mommy! by Mar.Nurevo · · Score: 1

      I guess I let myself get out of hand with the spyware comment but I don't trust the current leaders with our country. Well....marx had a idea that is hard to follow seeing that man "seems" to be not able to handle power in a just way; so did our founding fathers(USA) but their idea fell into the same trap as Karl Marx's. My belief is that a union between the two(marxism and democracy) can exist and maybe that will provide a better system. Fear of your leaders should not be felt but, for me, I can't help it. There has to be a better way, you know?

      --
      I once caught my nemesis watching me through a window but to my surprise it wasn't a window...it was a mirror.
  186. Re:All gov't-developed software is public domain.. by dsoltesz · · Score: 2

    I believe software published (not stuff developed for in-house) is "open source" (cuz of FOIA I believe). The gov't can't copyright products, but it can get patents.

  187. Decompile it first by iankerickson · · Score: 2

    This is what decompilers and the strings command are for. You'd be amazed how much you can learn about what a binary does by running the .exe through a decompiler and just leafing through the symbols. You might think most apps strip all useful symbols out, but it's not true. You can have yourself an old school literate programming session and leaf through the binary code like a book, if you have a few assembly references handy and limited understanding of addressing modes.

    So even if the file is .exe, it's not like you _can't_ ever know what it will really do when you run it. You just need some time, some tools, some brains, and some nerve.

    --
    Democracy. Whiskey. Sexy. Pick any two.
  188. you mentioned switzerland? by Control42 · · Score: 1

    well, sir, I live in switzerland, I was born here, and can probably be considered a typical swiss guy. And as that typical swiss guy, I must tell you that the general opinion towards the US' gun policy is: "funny, but in a tragic kind of way". It is correct that almost every male between 18 and 50 is forced to have an assault rifle with ammuniton at home in switzerland. It is also a fact, that every gun holder has to practice the use of his gun once a year, or pay a rather large fee. Nonetheless, carrying a gun when you are not rewuired to by law is widely considered embarrassing. Hell, I even find it embarassing to carry my gun when I'm doing my yearly military service. By most of the population, guns are seen for what the are: necessary evil for people working in security, and phallic compensation for those who carry them volontarily. Please do not compare the numbers of government enforced guns possesions, with actual private gun purcheses, which are quite rare in Switzerland. The US is obsessed with guns, and you should know that most of the civilized world is laughing at you, and waiting for you to grow up.

    1. Re:you mentioned switzerland? by dfenstrate · · Score: 2

      I care little what the world thinks, because it's always popular to pick on the biggest kid on the block. Nor should the derision of other countries make any lick of difference to our core principles. If they care to piss away their natural rights in the name of being progressive, and laugh at us while we preserve them- then so be it.

      Call the US gun crazy, if you will- but from what I understand, the Swiss are the most armed people on the face of the earth, per capita, not Americans. Regardless for the reasons you are armed, the fact remains that every household has at least one military firearm, doesn't it? Might this not have the slightest detterent effect on crime?

      The reason you'll find loudmouths like me vicously defending our individual right to keep and bear arms is because there are many people in our society and government seek to restrict this basic right- a problem you don't seriously have in Switzerland, from what I understand.

      Please do correct me if I'm wrong, as I've never traveled outside the US (Canada doesn't exactly count, because to the casual observer, they just use different money ;) )only read some on the subject.

      --
      Alcohol, Tobacco and Firearms should be the name of a store, not a government agency.
    2. Re:you mentioned switzerland? by pubjames · · Score: 2

      If they care to piss away their natural rights in the name of being progressive

      But in Europe we view the opinion that carrying a bug as a "natural right" as a really bizarre point of view. I know it is hard for many of you in the USA to understand, but we don't want guns. There is virtually no pro-gun political or public movement in Europe at all.

      Data published by Krug et al in 1998 indicated the following rates for gun deaths per 100,000 population:

      USA - 14.24
      Switzerland - 5.31
      Scotland - 0.54
      England & Wales - 0.41
      Japan - 0.05

      So, for every one gun death in the UK there were about 35 in the USA. And does the UK have a more serious crime problem than the USA? No. The statistics are even more extreme comparing Japan and the USA.

      Face it, the argument that gun ownership reduces crime levels is bullshit. I feel much safer on the streets in Europe than in the USA.

    3. Re:you mentioned switzerland? by Moridineas · · Score: 2

      You might want to re-examine those numbers friend. Here are a couple recent articles you may find interesting:

      http://news.bbc.co.uk/hi/english/uk/england/news id _2069000/2069400.stm

      http://news.bbc.co.uk/hi/english/uk/newsid_20470 00 /2047651.stm

      (there are more articles--a flurry of reports was released within the past month, I'm sure it can be googled easily enough).

      Older article, though I included it for use of the term "Gunchester" which I find rather amusing.
      London is now less safe than New York..New York!!

      http://www.guardian.co.uk/gun/Story/0,2763,19525 4, 00.html

      Here's another older article though interesting in that it shows Britain's gun policies NEVER returned great results:

      http://www.geocities.com/Athens/Bridge/2431/brit la w.html

      Here's an article relating to Gun facts in the US:

      http://www.cato.org/dailys/05-13-00.html

      So here's the perplexing part--guns have been banned, disabled, confiscated in Britain. So how (Why?!) are gun crimes rising?? It's simple, you take away guns from those who are properly licensed and follow the law, and you take away the ability of people to defend themselves from guns. Gang members and other lawbreakers are going to continue breaking the law, I don't see them handing their pieces over to the cops,do you? You punish the law abiding citizens with this action, not the criminals.

      Oh and incidentally, is Switzerland not considered part of Europe?? Because they certaintly don't have, use, or want guns there.

      (Another interesting article if for some reason you don't believe me about the swiss:)

      http://www.enterstageright.com/archive/articles/ 07 99swissguns.htm

    4. Re:you mentioned switzerland? by pubjames · · Score: 2

      You might want to re-examine those numbers friend.

      Erm, why? You provide a bunch of links about gun crime in the UK. So? Nobody said it didn't exist. But the USA still has substantially higher homicide rates than the UK, in fact than anywhere in Europe. Or would you care to provide some stats that prove otherwise?

      The links you provide show that crime in the UK has risen recently, whereas in the USA it has fallen. You seem to think this proves that the gun laws in the USA lower crime. However, there haven't been significant changes in the law with regard to gun use in the USA or the UK for many years, so how can you relate one to the other?

    5. Re:you mentioned switzerland? by Moridineas · · Score: 2

      Erm, why? You provide a bunch of links about gun crime in the UK. So? Nobody said it didn't exist. But the USA still has substantially higher homicide rates than the UK, in fact than anywhere in Europe. Or would you care to provide some stats that prove otherwise?

      I won't say that crime in Europe is worse than in America, because the stats don't exist to back that up. On the other hand, the US is a much bigger place--I wonder what conglomerate stat for Europe would look like, if you combined western + parts of Eastern Europe. The US also faces many of the same problems that Britain (as well as other countries) are starting to face--for instance gang warfare. Some of the links I posted talked a bit about that--crime rates among poor urban minorities in the US are what skew the stats largely--if you take the inner city gangs out the picture, and drug related deaths (the two largely relate actually), America would be much closer in line with Europe. Again, this is a problem Europe is starting to face too, look at all the recent anti-semitic attacks from France to Germany to London to Italy (mostly not performed by white Europeans) -- it's a problem. I would also agree with you that most European cities are more safe than American cities. I just don't like the notion that every crime in america is because of a gun, and wouldn't be happening otherwise. I live on the Eastern seaboard, and in my entire life, other than on police officers, I have seen *one* person carrying a gun (holster on his hip)--the guy's car also had NRA stickers, "live free or die" type things all over :) This was for a school carwash fundraiser, and he paid double for his car--not all gun users are bad people or nuts.

      The links you provide show that crime in the UK has risen recently, whereas in the USA it has fallen. You seem to think this proves that the gun laws in the USA lower crime. However, there haven't been significant changes in the law with regard to gun use in the USA or the UK for many years, so how can you relate one to the other?

      Actually the UK gun laws did change signifigantly in 1997, which is why this is a big deal. It still blows my mind that London is now less safe than New York..

  189. ...in concept... by Anonymous Coward · · Score: 0

    ...communism is a good idea too.

  190. Switzerland?! by pubjames · · Score: 3, Insightful

    Criminals prowl our streets. But they do so with far less frequency in areas where even a 20th of the population is likely to be armed (florida-they still go after tourists- Vermont, New Hampshire, or, for the Europeans out there, switzerland.)

    I almost snorted coffee up my nose when I read 'Switzerland'. Let me explain something to you, and please think about it because it may help you realise why the rest of the world finds the USAs attitude towards guns really sad and frankly bizarre. Switzerland has a low crime rate mainly because the Swiss people are good, honest, non-violent people. The requirement for men to own a rifle is so that Switzerland can defend itself in the case of war. They do not carry the rifles around with them but keep them locked up.

    1. Re:Switzerland?! by dfenstrate · · Score: 2

      Vermont, New Hampshire, and Maine- all in New England (the Northeastern part of the United States) are all basically crime free (47,48, and 49th on the list of violence by state. 50 States, by the way) because the people are good, honest, and hardworking. The fact that these states have loose gun control laws help keep things that way.
      The same cannot be said for many other areas of the country, where scum can be found on every corner. The United states is a large country, with every kind of metropolitan area you can imagine. It's just a little bit harder to keep everyone in lockstep over here because of that.

      Please read my response to the other swiss who posted, as if I typed on, I'd repeat myself.

      --
      Alcohol, Tobacco and Firearms should be the name of a store, not a government agency.
  191. A cigar is NOT just a cigar by Anonymous Coward · · Score: 0

    . . . when it's a Bill Clinton cigar.

  192. Re:All gov't-developed software is public domain.. by trumpetplayer · · Score: 1

    Oh yes, specially military, classified software.

  193. Re:There is information about this.... by Anonymous Coward · · Score: 0

    you fscking asshole DON'T click that link!

  194. govmt vs. M$ by Anonymous Coward · · Score: 0

    if you didn`t already get it, a part of the american govmt is the holy M$.

    time someone stood up and dropped a bomb on them (wordplay-wise)

  195. Re:All gov't-developed software is public domain.. by Our+Man+In+Redmond · · Score: 2

    Bet me $50 that whatever software the IRS uses to run its computers, it isn't public domain.

    --
    Someone you trust is one of us.
  196. I was at the Press Conference by Spyder · · Score: 2, Interesting

    WHat they released was a security template that amounts to the minimum that security experts have been advocating since roughly the dawn of time. The babble Clark was talking about (I really hate it when poeple old enough to be my grandparents use buzzwords like cybersecurity instead of information security or computer security, it makes them sound like dotcommies without a clue) is just political fluff. Without funding, visiblity and a plan of execution nothing will happen in a government program, it's a law of nature. As for the template, I'm still evaluating it, but so far I think it's a decent thing to put on a w2k pro box/ std image especaily if you do work for the gov. I'm just glad to see the government actually doing something security wise that will benift the smaller civil agencys and administrations.

    --
    Spyder
  197. source code by objwiz · · Score: 1

    if the government released the source code with the program, then I might be inclined to install it. I would want to know what they are doing before running it.

  198. GOLD standard by Anonymous Coward · · Score: 0

    I atteneded this breifing, the gold standardis just a document that was put together by SANS, NIST, CIS,and the NSA showing (step by step) how to set up good security on your machine. The only software talked about in this briefing was a read only tool to verify your settings against the GOLD standard. This is something that all government system admins will have to follow when deploying machines to their clients, and is being released publicly to help private users secure their own machines.

  199. Tax Dollars to fix Microsoft Security Holes? What? by MrJerryNormandinSir · · Score: 1

    I think this is a joke. Microsoft should fix their own security holes, and if they can't they
    are liable. Or... the public should switch to a real Operating System like BSD, Linux, or OS/X.

    What a joke.

  200. I love American patriotism by Anonymous Coward · · Score: 0

    From the article on CNN: Keeping your home computer's antivirus software updated is not just sensible -- it could be a way to demonstrate your patriotism.
    I love this way of life. Actually, patriotism makes it's way down to everything americans do. I think cleaning your teeth will soon become that much patriotic too. This will of course piss of Bin Laden, who's teeth are so yellow and smelly! F00!
    Honestly, I'm very happy for Americans, because they still know what patriotism is. I'm typing this from Israel, which has always been meant to be a patriotic country, built solely upon patriotism, but IMHO it just fails to keep it's feet on this patriotic way! Look at how the society is split up between right & left, russian & jewish, etc.! I bet there's no such thing in th US, cause after 9/11 people got connected with each other by patriotic ties which don't need any sort of propoganda! I know how every and all Americans felt that day, and I've seen those pictures on CNN showing people in New York who saluted the firefighters. This really rocks. So now back to securing American computer systems - it's just the same thing. Those "firefighters" would now be governmental hackers, who'll actually do the work of securing the cyberspace, and this IS patriotic!
    By the way, don't think this would affect your privacy, even if the Big Brother would like to watch you masturbate in the shower. Gee.

  201. Old info by jmorris42 · · Score: 2

    Not anymore. They tossed those rules and replaced them with rules that say they can decide to sell the IP rights to a private company who CAN patent/copyright.

    --
    Democrat delenda est
  202. People like you and me? by Quiet+Sound · · Score: 1

    Maybe it's just me, but I'm not rich and neither is anyone in my family, nor do I hold a high position in a multi-million dollar corporation. I have no history of shady business dealings and I do not have to gloss over my past to avoid scandal. I am not an elitist hypocrite who seeks to take things away from the little people while keeping them for myself. I do not suddenly change my thoughts on "the issues" so that I'll become popular with a new group of people. And so on, and so on, and so on...

    No, the elite of this plutocracy are not like me and I doubt they are like you either.

    1. Re:People like you and me? by Anonymous Coward · · Score: 0

      It is just you, slappy. Did you ever stop and think about the fact that the federal government consists of a lot more than Congress and the President? The vast majority of government workers do not fit the profile that you describe, including me. We are not mindless stormtroopers that are working day and night just to screw you over. Most of us are just doing a job (which does not involve screwing you over) in order to provide for our own families (who are also not screwing you over). The fact is that we are probably more like you than you care to admit, since it wouldn't fit into your whole military-industrial-complex-government-conspiracy paranoia framework.

  203. ArmyOps by Anonymous Coward · · Score: 0

    Is ArmyOps the first step. I have not been assasinated / bombed yet. Or maybe they are analysing my game stategy so when the seals arrive, they will know my every move..

    Mind you, I am English, so being shot at by the American Army is nothing new.

  204. _Hello_?? Windoze is used in China, Iraq, etc... by vidicon · · Score: 1

    Why would Uncle Sam want to force M$ to secure windows, when it presently allows 'us' access to 'enemy' nation's boxen? Let's just fix ours! (Isn't that what the NSA is all about?)

    - vidic0n

    --
    Volvo, Video, Velcro - I came, I saw, I stuck around
  205. In the good old days by doublem · · Score: 2

    Man, things have just gone downhill. At least in the days of George Bush Sr. we knew that we were safe from broccoli

    --
    "Live Free or Die." Don't like it? Then keep out of the USA
    1. Re:In the good old days by StillaCoward · · Score: 1

      Yes, but the question is...who will keep the pres safe from Pretzels ???

  206. Gun Deaths != crime. by dfenstrate · · Score: 2

    Gun Deaths != crime.
    Allow me to explain.
    According to the United States FBI and Do Health & Human services, in 1995, there where 13,790 firearm homicides in the US (about 5.51 per 100K). The same year, there where 18,503 gun suicides in the US, or 7.4 per 100K. Why guns? Because they're a very effective way to kill oneself. People who are intent on killing themselves will do so with the quickest means possible.

    Don't believe me? Ask your beloved Japan, who had a suicide rate of 16.72 in 1994 International Journal of Epidemiology (1998)
    Now, our total homicides (a category much clearer than the deceptive gun deaths) of 5.70 is still about 4 times higher than England's 1.41, but not 34 times higher, as your numbers might suggest to the uncritical reader.

    So you feel safe in Europe, huh? How about london? Where you're twice as likely to get mugged, robbed, or assaulted then in New York City?
    Quoting the Weekly Standard :
    The same pattern can be seen throughout Europe--indeed, in much of the developed world. Crime has recently hit record highs in Paris, Madrid, Stockholm, Amsterdam, Toronto, and a host of other major cities. In a 2001 study, the British Home Office (the equivalent of the U.S. Department of Justice) found violent and property crime increased in the late 1990s in every wealthy country except the United States. American property crime rates have been lower than those in Britain, Canada, and France since the early 1990s, and violent crime rates throughout the E.U., Australia, and Canada have recently begun to equal and even surpass those in the United States. Even Sweden, once the epitome of cosmopolitan socialist prosperity, now has a crime victimization rate 20 percent higher than the United States.

    Americans, on the other hand, have become much safer. Preliminary 2001 crime statistics from the FBI show America's tenth consecutive year of declines in crime. While our homicide rate is still substantially higher than most in Europe, it has sunk to levels unseen here since the early 1960s. And overall crime rates in this country are now 40 percent below the all-time highs of the early 1970s. In 1973, nearly 60 percent of American households fell victim to property crimes. In 2000 (the most recent data available), only about 20 percent did. Among the economically powerful democracies in the Group of Seven, only the Japanese now have a lower victimization rate than the United States.


    Great Britains own Home Office, with a vested interest in preserving the status quo, shows that the US, with it's lax gun control laws, has less crime. And that using categories like 'property crime' and 'violent crime,' which clearly indicate that it's one person commiting a crime against another, contrary to your "Gun Deaths."

    Also, none of this has mentioned how often guns are brandished or used to prevent crimes. (A legitimate gun death- where someone acted in self defense- would not be listed as homicide)Defensive gun uses have been estimated anywhere as low as 4.32 (National Crime Victimization survey) per 100K to as high as 103 (Dr. Kleck, Florida State University). If the truth lies in between, as is likely, the presence of guns offers a net benefit to society. Defensive Gun Uses include instances where simply brandishing the fire arm was enough to deter the criminal, and other instances where the criminal was shot)

    Now, the article I cite goes on to list other reasons why the US crime rate has fallen, outside of firearm possesion. All things being equal though, I would much rather have the option to defend myself, my family, and my friends with the most effective means available- a firearm. Your gun control clearly doesn't make you any safer.

    Also, if you think only cops should have guns- in the US, Police shoot the wrong person 11% of the time. Private citizens do so only 2% of the time.

    I think I'll keep the loose United States gun laws, thank you, and you Europeans can laugh until the armed thug knocks on your door. Natural rights exist regardless of how bizzare you think they are, and you're better off exercising them then not.

    Set. Bump. Spike. Thank you, come again.

    --
    Alcohol, Tobacco and Firearms should be the name of a store, not a government agency.
  207. Real Security. by lionchild · · Score: 1

    IMHO: If we really need to "secure insecure windows installations" then why doesn't someone put together a consortium of white-hat's to find holes and more descretely have them patched up? Hey, and image that...they could make a living do it. Get paid. That's the American way, now isn't it?

    --
    Awk! Pieces of eight. Pieces of eight. Pieces of seven... ERROR: General Protection Fault. [Paroty Error.]
  208. How to take out light armor and artillery by EverlastingPhelps · · Score: 2, Insightful
    don't know whether to laugh at your post or just feel sorry for you. What kind of armed resistance can even a large militia give against even light armor and artillery from the US's military? None.

    Molotov Cocktails tend to make short work of armor. Artillery is just as vulnerable to infiltration and sniping as it is counter-battery fire. If it is mobile artillery, see "Molotov Cocktail."

    The danger from an armed populace isn't that they have massive military might; it is that you cannot determine who is or isn't an enemy. Artillery and guided missiles are no longer your enemy; the guy delivering the produce for lunch mess, or the girlfriend of the unit's LT, or the Eagle Scouts who accidently hiked through your camp become the enemy.

  209. Re:All gov't-developed software is public domain.. by Quixadhal · · Score: 2

    Of course, as anyone working with security knows, having the source code ONLY helps you crack a product if the product wasn't developed with security in mind, and using a reasonable security paradigm.

    If you use a reasonable key system, just having the source shouldn't let you magically hack into it (although it will help if that key system is flawed).

    OTOH, if you use a complex scheme like XOR (as certain monopolistic companies who shall remain nameless have done in the past)... then I guess you're pretty well screwed either way.

  210. Re:If Al Gore made the Internet... by Anonymous Coward · · Score: 0

    Blame people who see the whole world in moronic stereotypes.

    At least you're willing to take responsibility for what you've done.

  211. an analogy by Anonymous Coward · · Score: 0

    Hmmm, this seems really stupid. Consider an analogy: you buy a car, many instances of said car turn out to be a road hazard but you are driving it on the public infrastructure (roads), does the government give you stuff to fix your car? No, they tell the car manufacturers to clean up their act ... maybe instead of helping us they should be busting M$ chops for providing dangerous products -- get rid of the no-liability-for-software clause for all software sold without access to the source.

  212. Re:If Al Gore made the Internet... by geekoid · · Score: 2

    actually, I blame Nader.

    --
    The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
  213. Carnivore by Snover · · Score: 1

    Anyone else thinking their 'cleanup mechanism' is gonna be Carnivore?

    --

    [insert witty comment here]
    1. Re:Carnivore by g00ber_sm00tch · · Score: 1

      What else would it be? Remember that isn't real though.

  214. Two words: Magic Lantern by Anonymous Coward · · Score: 0
    Can you say "Magic Lantern"? I knew you could.