Software Choice Group Tells DOD Not to Use Open Source
ducomputergeek writes "A group calling themselves the Initiative for Software Choice, backed by Microsoft and others, is recommending that the DOD drop plans for further adoption of Open Source software. This comes after MITRE, a defense contractor, published a report stating that not only does the Department of Defense use opensource, but is recommend on using it more. The article is at News.com and you can read it here."
I work for the DoD, in a branch that plans technology policy for various projects. Over the last 5-10 years, the push for "Open Standards Architecture" (OSA) has been at the forefront. It's the stated policy of the DoD, which comes from the mouth of a former Secretary of Defense, to push for open standards, open interfaces, and in general to be as far from proprietary as possible. Proprietary software means more expense for the government due to non-competition, and it also puts the government in the hands of a private corporation.
Open Source, while not specifically targeted by the DoD, is the next logical step. Although the previous generation of nuclear submarines ran HP-UX, the next generation (due to be delivered starting 2006) will run about half Solaris, half Linux. So yes, open source is on the way in in the government. Slightly off-topic, but if you want a good example of why proprietary software is no good for mission-critical work, look up on Google the problems the USS Yorktown had with Windows NT about 5 years ago...
"If at first you don't succeed, lower your standards."
It's important to make clear the difference between:
1) using OSS code in your software
2) using OSS code to write your software, or to deploy your software, or to distribute your software, or to hang your software out to dry on your clothesline, etc...
Only #1 requires you to make your software open source.
(btw, I work as a contractor for the DOD. we do #2 constantly, and I can promise you it's the much more common activity)
http://kered.org
I work for the DoD, in a technology policy branch.
Not only is proprietary softare inherently insecure, it's inherently more expensive, inherently doesn't work as well, and inherently causes the government to be screwed if the company goes out of business or decides to stop supporting the software. In fact, the government got screwed by using HP-UX when HP decided not to make new versions of the OS backwards-compatible with the older HP processors being used in most of our submarines...now, wisely, half of the computers in the NEXT generation of subs are running Linux (the rest are running Solaris...)
"If at first you don't succeed, lower your standards."
> This comes after MITRE, a defense contractor,
> published a report stating that not only does the
> Department of Defense use opensource, but is
> recommend on using it more.
MITRE is one hell of a lot more than just another defense contractor. Look into it's history and you'll see that DoD will value its opinion far above that of some Microsoft lobbiest.
Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
This bring up a question I've asked before and no one seems to have a conclusive answer for. Technically, by the GPL rules, anyone who gets the binary has to be able to get the source. Now the DoD employees are certainly getting the binary, so they should have access to the source as well, correct? And if they have access to the source, the GPL gives them full legal rights to redistribute it as they want, correct?
The Free Software Foundation and Richard Stallman have both made this very, very clear.
Software kept within an organization is not considered to have been distributed. There is a very precise definitions of what distributed means, which the GPL, the FSF, etc. have made very clear. You can use as much GPLed code as you like with your in-house software, and as long as that software stays in-house it is not being distributed, and you are under no obligation to provide a single line of sourcecode to anyone. This has been made explicity clear by RMS and others.
Now, if you distribute the software outside of your organization, then you are obligated to provide the source code to that other organization.
So yes, the Army giving the Navy software would have to give them source code (and if the Navy wanted to give it to Joe Blow, the Army couldn't stop them). But having the source code distributed from Army Headquarters in the Pentagon to GI Jane in the field does not constitute distribution outside of the organization, and there is no obligation to either give Jane the code, nor to allow her to distribute it outside of the organization (in this case, the US military).
The Future of Human Evolution: Autonomy
The part that I wonder about is "other software products with limited or no warranty, such as those commonly known as freeware or shareware". I wonder if this was meant to indicate Open Source Software? IANAL, but I've never seen a EULA for software that didn't indicate a limited warranty. In fact, from my layman's point of view, all the standard EULAs seem to indicate that the software has no warranty, since they seem to claim that the software doesn't have to do anything at all...
Elegance is for tailors. -A. Einstein
Actually, the problem was that HP-UX ran only on HP processors. A brand new Navy nuclear submarine has a lifespan of 35-40 years, while a typical computer operating system becomes outdated in 5-7 years. The problem was that after about a year ago, HP stopped supporting the latest version of HP-UX that ran on those processors, stopped making patches for it, stopped adding support for new hardware, etc., etc. Thus, as the Navy's needs changed, their operating system couldn't change to meet the new needs. The options were to either upgrade all the hardware to all new HP processors and OSes (and probably get screwed again in the future), or move to something that was more likely to be supported, upgradeable, and backwards-compatible in the future. Since Linux is a relative newcomer, the choice was made at the time to use Sun Solaris, though the big push now is towards Linux.
"If at first you don't succeed, lower your standards."
It already is. The newly signed homeland security bill saw to it.(all 420+ pages could not have been adequately examined by those who voted for it but that is another rant.) Download the PDF from the govt web site.
...the selection of specific technical hardware and software information security solutions should be left to individual agencies from among commercially developed products.
Page 323 Line 15.
comment directly in my journal