A Conversation with Cory Doctorow and Hal Stern
ChelleChelle writes "In a rare meeting, popular sci-fi writer and co-editor of the blog Boing Boing Cory Doctorow and Sun VP Hal Stern consider the open source approach. The resulting interview deals with the pros and cons of going open source, as well as the issues of security and privacy. From the article: 'It seems to me that one of the big problems with the filters you've just identified is who gets to set policy in the machine. As a science fiction writer, I am offended by sci-fi movies where it turns out that the rocket ship has a self-destruct button, it has been pressed by accident, and now the whole thing is going to explode. ... By the same token, I often wonder whether trusted computing architectures that allow remote parties to enforce policy on your hardware are a good idea. Although we can imagine beneficent examples of this, this is what spyware is, by definition, right? Spyware is remote parties setting policies on your computer against your wishes. Is it ever a good idea?'"
I demand to know what Kilgore Trout says about all this.
These stories are free but worth money.
What I really wan to know is where can I get that shirt that Cory's wearing?
Cory Doctorow. Biggest self promoter, ever.
TCPA and DRM (Especially Palladium) are not means of improving computer security. They are there to subvert the ownership of users of technology in favor of powerful companies. DRM isn't going to safe guard medical records. And TCPA isn't going to stop a space ship from Self Destructing.
What will help computer security are good security practices.
At my house, everyone logs in to a Linux powered Domain, LDAP coated in SSL for Authorization, Kerberos for Authentication. Traffic (especially Wifi) encapsulated with IPSec. SE Linux policies in place. Directory service authorized Radius Server with MySQL server Accounting, and cataloged MAC Addresses in OpenLDAP. These are good security policies. Everyone should have some variation of this.
If I were on a space ship, I damned well better be able to secure my systems against unauthorized access. But DRM and TCPA do not make this happen.
Really,
this article is soo boring. Only ~10 comments and Zonk spammed the frontpage already with 3 other un-informative, irrelevant, stupid articles that lack anything including journalism.
I encourage everyone to disable Javascript for slashdot.org in his settings and to disable the loading of images from other servers than slashdot.org as long as that FUD spewing loser is wasting our precious time here.
You forgot to mention the servers are wired with motion detectors, CO2 detectors and mercury tilt switches connected to one thousand pounds of C-4. was Re:Don't lend Trusted computing legitimacy
davecb5620@gmail.com
But you can always take advantage of GPLV3 to remove my DRM synapses
Not only that, but the previous poster is Cory's mom. So you KNOW it's serious.
Spyware is remote parties setting policies on your computer against your wishes
Now you understand my problem with Microsoft.
Everyone knows Cory Doctorow wears a red cape and goggles.
http://xkcd.com/c239.html
On the bright side, Cory is using an analogy that might spark some brain cells in the semi-joe sixpack crowd.
So called trusted computing is not spyware, it is worse! It is remote administration! That's right! It is the coercive wresting of control of the machine and its software that you paid for by a hostile stranger that you are not allowed to know. That is also right.. you are not allowed to find out who really controls what runs or is installable on your machine. With Vista's 'Background Intelligent Transfer System', this control can be updated without your knowledge or consent much less your participation at all. On windows operating environments and systems and increasingly and progressively with each successive version, you are neither the owner nor the real root operator of the equipment that you paid for with your money! And now comes the ultimate insult and coup-de-grace to your privacy and ownership rights in the form of 'software as a service'! Here you will have all your rights to your data finally arrogated away, sacrificed on the altar of interoperability, to have your own private records kept under your own roof! All your personal data will now be in some 'homeland security (KGB)' controlled warehouse to be kept forever, every last typo of it. More than that, hidden hands will be allowed unfettered access to add things to it for which you could be punished legally in USA kangaroo courts. Of course such things can now be added to Vista systems in the middle of the night or maybe in the daytime right under your nose. Do you know that there are companies that want to use the unused memory on your hard drive to store their data, and that want the unused cycles of your CPU to process this; and do you know that strangers are probably right at this moment selling this to other strangers without you being party to any of it unless the data was illegal and found by a sudden unannounced gestapo raid.....then you would be prosecuted for it and the strangers would fade into the night. Just like the rights that were stolen from your apathetic ass while you sleepwalked your way through the last twenty years.
What they said is not what Trusted Computing does. It does not enforce policy on your machine.
Rather, it provides a way for people to prove what policies they are enforcing on their own machines. And thereby that will allow someone to say, I won't give you this data unless you are running a certain policy (that will protect my data). Today, that wouldn't really work because they couldn't tell what policies you were running. But with Trusted Computing, it will be possible. You will be able to prove your policies and they can decide whether to give you the data depending on what your policies are.
It may seem like a subtle distinction, and in a way there's not that much difference. But saying that third parties can enforce policy on your machine evokes many images that just would not happen with the real Trusted Computing. It suggests that your machine could be made to spy on you or do some other bad thing and there's nothing you can do about it. But that's not true. You always have a choice with Trusted Computing to tell the other guy to stuff it, you just won't take his damn data if he wants to put so many restrictions on it. Just like today you don't have to shop at Apple music store if you don't like DRM, you can download music from independent bands who make it freely available in MP3 format.
The whole point of Trusted Computing is to keep things completely voluntary. It aims to replace legal restrictions (that you have no choice about) with technological ones (that you can always choose not to use). It adds choices and options without taking any away. It lets people who are honest prove that they are honest: when they agree to the policies in return for taking the data it lets them prove what policies they are truly following.
Honest people have nothing to fear from Trusted Computing. In fact they will gain many advantages by letting them prove their honesty and gain others' trust. The only people who will be hampered by Trusted Computing are those who would aim to falsely agree to observe copyright restrictions and then violate them once they get their hands on the data. Unfortunately, judging by the negative reception to Trusted Computing, such people make up a substantial fraction of the online community.
You mean I can read the opinion of a c-list sci-fi author whose only contribution to boingboing is daily updates on anything walt disney? Does the article have any snazzy pictures of the haircut he's been sporting for the last 10 years? I can't wait to look!
>Spyware is remote parties setting policies on your computer against your wishes. Is it ever a good idea?
If you actually own all the remote machines. For example your workers do their job at home.
M$ doesn't own my machine.
Patents Drive Free Software as Hurricanes Drive Construction Industry