Re: No Blob without Puffy

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Lars D. Noodén
Date: Monday, March 19, 2007 - 11:59 am

On Mon, 19 Mar 2007, Dave Anderson wrote:

It harms more than just the campaign, it harms anyone wanting to maintain
a modicum of options further down the road in regards to hardware
lifecycles, operating system and kernel lifecycles, and last but not least
security.

One anecdote regarding insecurity of mysterious binaries / BLOBs:
A local privilege escation has been known to exist, unfixed, for several
years in nvidia's binary drivers:
 	http://lwn.net/Articles/204541/

However, if you can't audit (and subsequently compile) all the code,
including the applications, libraries, compilers and OS, then you've got
nothing secure and nothing that can be made secure - regardless of
anecdotes, no amount of assurances, claims, hand waving, shouting, smoke,
noise etc. from vendors.  Don't take my word for it, read what the ACM had
to say about it:
 	http://www.acm.org/classics/sep95/

But it's not just 'security' that is at risk.  The lifecycle of both the
operating system/kernel and the hardware that rely on the continued
availability of the BLOBs become dependent on the BLOBs producers.  Those
are groups which may or may not continue to have interests and motivations
which overlap yours.  If your hardware or system needs a BLOB to run, then
the BLOB-maker has you on a leash.

Endorsing BLOBs puts *all* hardware, systems, and security at risk through
active effort, which is reprehensible.  To have one system accepting them,
makes it all that much harder to keep them off.  Think digital scab.

Tolerating BLOBs or failing to eliminate BLOBs, are simply balless passive
means of putting the above at risk.  To put it another way, it's possible
to gain control (political, economical, technical) of systems that get
locked into BLOBs either passively or actively and encroachment into one
system/distro can be used to marginalize the others.

So to put it as kindly as I can, only people somewhere on the spectrum
between stupid and troll would be advocating acceptance or tolerance of
BLOBs.  It's an act of harm that affects more than just the system with
the BLOB.

-Lars
Lars NoodC)n (larsnooden@openoffice.org)
         Ensure access to your data now and in the future
         http://opendocumentfellowship.org/about_us/contribute
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: No Blob without Puffy, SW, (Sun Mar 18, 4:06 pm)
Re: No Blob without Puffy, Jason Dixon, (Sun Mar 18, 5:52 pm)
Re: No Blob without Puffy, Luke Bakken, (Sun Mar 18, 5:53 pm)
Re: No Blob without Puffy, Craig Brozefsky, (Sun Mar 18, 6:20 pm)
Re: No Blob without Puffy, SW, (Sun Mar 18, 6:31 pm)
Re: No Blob without Puffy, Rafael Almeida, (Sun Mar 18, 6:41 pm)
Re: No Blob without Puffy, Jason Dixon, (Sun Mar 18, 7:19 pm)
Re: No Blob without Puffy, Daniel Ouellet, (Sun Mar 18, 7:54 pm)
Re: No Blob without Puffy, Adam, (Sun Mar 18, 7:56 pm)
Re: No Blob without Puffy, Damien Miller, (Sun Mar 18, 8:27 pm)
Re: No Blob without Puffy, Jason LaRiviere, (Sun Mar 18, 8:30 pm)
Re: No Blob without Puffy, Rafael Almeida, (Sun Mar 18, 8:31 pm)
Re: No Blob without Puffy, Artur Grabowski, (Mon Mar 19, 2:00 am)
Re: No Blob without Puffy, Henning Brauer, (Mon Mar 19, 3:35 am)
Re: No Blob without Puffy, Timo Schoeler, (Mon Mar 19, 4:15 am)
Re: No Blob without Puffy, Jacob Yocom-Piatt, (Mon Mar 19, 4:56 am)
Re: No Blob without Puffy, Karel Kulhavy, (Mon Mar 19, 7:04 am)
Re: No Blob without Puffy, Karel Kulhavy, (Mon Mar 19, 7:27 am)
Re: No Blob without Puffy, Nick !, (Mon Mar 19, 8:46 am)
Re: No Blob without Puffy, Marco Peereboom, (Mon Mar 19, 8:48 am)
Re: No Blob without Puffy, Chris Black, (Mon Mar 19, 8:54 am)
Re: No Blob without Puffy, Dan Farrell, (Mon Mar 19, 8:59 am)
Re: No Blob without Puffy, Artur Grabowski, (Mon Mar 19, 9:05 am)
Re: No Blob without Puffy, Timo Schoeler, (Mon Mar 19, 9:17 am)
Re: No Blob without Puffy, Ted Unangst, (Mon Mar 19, 10:31 am)
Re: No Blob without Puffy, Dave Anderson, (Mon Mar 19, 11:49 am)
Re: No Blob without Puffy, Lars D. Noodén, (Mon Mar 19, 11:59 am)
Re: No Blob without Puffy, Dan Farrell, (Mon Mar 19, 1:55 pm)
Re: No Blob without Puffy, RW, (Mon Mar 19, 3:00 pm)
Re: No Blob without Puffy, chefren, (Mon Mar 19, 4:33 pm)
Re: No Blob without Puffy, Tony Abernethy, (Mon Mar 19, 6:52 pm)
Re: No Blob without Puffy, Daniel Ouellet, (Mon Mar 19, 9:43 pm)
Re: No Blob without Puffy, Dan Farrell, (Tue Mar 20, 7:03 am)
Re: No Blob without Puffy, Nick !, (Tue Mar 20, 7:29 am)
Re: No Blob without Puffy, Daniel Ouellet, (Tue Mar 20, 12:31 pm)
Re: No Blob without Puffy, Karel Kulhavy, (Sun Mar 25, 11:47 am)
Re: No Blob without Puffy, Karel Kulhavy, (Sun Mar 25, 12:00 pm)
Re: No Blob without Puffy, Karel Kulhavy, (Sun Mar 25, 12:06 pm)
Re: No Blob without Puffy, Nick !, (Sun Mar 25, 5:09 pm)