Slashdot Mirror


Linux & Microsoft as a Cold War?

I confirm writes "The BBC's Bill Thompson summarises the GNU/Linux vs. Microsoft struggle as a "cold war", and in one choice quote says:"It is rather ironic that Microsoft and other closed model companies rather resemble the Stalinist or Maoist model of a command economy with complete centralised control." I'm not sure I accept Thompson's conclusions, however: "So now would be a good time to start thinking about how we persuade governments that market in software may eventually need to be regulated, just as the market in electricity, water and food is, and that that regulation may well include a statutory duty to disclose source code and allow it to be used elsewhere." "

2 of 443 comments (clear)

  1. Pig iron [2002 Gates memo calls for security] by NZheretic · · Score: 5, Informative
    The suggestion has been made before ...

    Subject: Pig iron [Was: Article: Gates memo calls for security focus]

    On Fri, 18 Jan 2002 15:16:08 GMT, Alun Jones <alun@texis.com> wrote:

    >In article <u0O18.81315$Sj1.32399626@typhoon.ne.mediaone.net> , Simon Chang
    ><schang@quantumslipstream.net> wrote:
    >>It remains to be seen whether Gates & Co. continues to treat inadequate
    >>security policy and implementation as just public relations issues.
    >

    >In Microsoft's favour, look what happened when Gates wrote a memo suggesting
    >that the company should get with the Internet. Complete U-turn on the part of
    >the whole company, with a huge emphasis on Internet development. What Gates
    >says, goes. Just maybe those doomsayers within Microsoft who have been saying
    >yes, but what about the security angle? (I presume there are some) will now
    >be listened to, and their recommendations acted on. I certainly hope so.
    >

    I fully admit, it is a Great Leap Forward, just like another one in history...

    http://www.asiaweek.com/asiaweek/magazine/99/0924/ cn_economy.html
    +Mao launched the Great Leap Forward program in 1958, arguably the greatest
    +economic folly of the 20th century. To help China surpass the economies of
    +Britain and the U.S. in 15 years, he decreed that every Chinese should
    +produce smelt iron. Hundreds of millions of citizens neglected farms to make
    +low-grade pig iron. Beijing did not know that grain was rotting in the fields

    Why the above quote? Check out the language Mr Gates uses in his letter
    ( see the register
    http://www.theregister.co.uk/content/4/23715.html
    ). Remind you of the announcements of the old five year plans from
    the old Soviet and Maoist regimes? Even down to the use of catch phrases!

    If Microsoft's Management is serous ( and given their past pronouncements
    on the security of their products - thats a very big if ) , it is a
    Herculean but not impossible task ahead. It will not happen overnight.


    Microsoft Makes Software Safety a Top Goal - January 17, 2002
    http://www.nytimes.com/2002/01/17/technology/17SEC U.html
    +Every developer is going to be told not to write any new line of code, Mr.
    +Allchin said, until they have thought out the security implications for the
    +product.

    YES !!! Finally, but a little too late since almost all of the core OS and
    application code has already been written.

    Microsoft should have started this process three years ago.
    The attempt to turn their current inherently designed insecure products
    into a trusted system is like that of turning a sows ear into a silk
    purse. The result is more likely to be pots and pans into useless,
    unsaleable pig iron. A lot of the core design for many of the products
    is going to have to be rewritten.

    As for Trustworthy computing See

    Avoiding bogus encryption products: Snake Oil FAQ ...
    http://www.faqs.org/faqs/cryptography-faq/snake-oi l/
    ... the warning principals apply as much to secure software
    products as it does to cryptographic products.

    For software to be Trustworthy it requires that both the source and
    build processes be verifiable by public inspection by peers in the
    industry. That *requires* an unrestrictive license such as open
    source (

  2. Already regulated in some sectors by SimoM · · Score: 5, Informative
    What you can (and probably should) do is to regulate its use in any of these fields as that field seees fit (or not regulate at all, as the case may be). When it is to be used in medicine, regulate it as a medical technology.

    Software is already regulated in some fields, such as when it is part of a medical device. See, for instance, FDA-imposed design controls on medical devices "automated with computer software" in 21 CFR 820.30. FDA has stated that "Software must be validated when it is a part of the finished device. FDA believes that this control is always needed, given the unique nature of software, to assure that software will perform as intended and will not impede safe operation by the user." (in their final rule on that "Quality System Regulation"). The regulations call for extensive documented verification and validation activities.