SHARE
Facebook X Pinterest WhatsApp

Eric S. Raymond: Designed for Insecurity — reprised

Written By
thumbnail
Web Webster
Web Webster
Apr 17, 2000

The status of the “back door” I discussed in “Microsoft:
Designed For Insecurity” is now uncertain. Since the problem was
reported on 14 April by BugTraq and the Wall Street Journal, one of
the people involved in discovering it has retracted his report.
There is now dispute over whether this problem was due to a genuine
back door or a server misconfiguration.

The general point of “Designed For Insecurity”, though, is
independent of this particular incident. As if to illustrate this,
there is yet another back door report from 13 April that may affect
hundreds of e-commerce sites. See


http://www.internetnews.com/ec-news/article/0,2171,4_340591,00.html

The key quote in this story is this one from Kasey Johns,
webmaster of one of the affected sites:

“I want the right to look at the code, make modifications, and
not be locked into whatever ghosts the author has hiding in there,”
said Johns.

The security and trust problems that come with that kind of
lock-in are the real point here, not the details of any particular
exploit or the name of the vendor attached to it.

The bottom line is very simple: Closed source can’t be trusted,
because you can’t see what it’s doing.


Eric S. Raymond

Of all tyrannies, a tyranny exercised for the good of its
victims may be the most oppressive. It may be better to live under
robber barons than under omnipotent moral busybodies. The robber
baron’s cruelty may sometimes sleep, his cupidity may at some point
be satiated; but those who torment us for our own good will torment
us without end, for they do so with the approval of their
consciences.
— C. S. Lewis

thumbnail
Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Recommended for you...

A Thorough Approach to Improve the Privacy and Security of Your Linux PC
Damien
Oct 24, 2024
Several Russian Maintainers Removed From Linux Kernel Due To Compliance Concerns
Senthil Kumar
Oct 23, 2024
OpenSSH Splits Again: New Authentication Binary Unveiled
Bobby Borisov
Oct 16, 2024
13 Best Free and Open Source Anti-Malware Tools
webmaster
Oct 14, 2024
Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.