logoalt Hacker News

danaristoday at 10:01 AM1 replyview on HN

> And then you say, loudly and publicly, "all the source code of our software is public, and our binaries use binary transparency so it's not possible for us to build a binary that doesn't match the source, and people will rapidly find this in our source code at which point we go out of business and you stop having a product to backdoor in the first place".

> (And you move out of the US.)

And then everybody claps.

Name me a software or hardware company—one big enough that the US government would actually care to force them to add a backdoor—that would be willing to give up the US market? The only one that's shown the least bit of backbone is Apple, and while I like them and appreciate what they've done in that vein so far, they're never going to move to open source software running their stuff, and they're pretty well embedded in the US, and very, very unlikely to try to move regardless of the headwinds there.

I'm fully with you that this would be a wise and moral thing to do, but frankly, our tech companies are neither wise nor moral. They are self-serving, greedy, and many of them have wanted to become the neofeudal overlords of a new order since before Trump started smashing the old one.


Replies

JoshTripletttoday at 12:04 PM

I'm not suggesting giving up the US market. I'm suggesting moving out of the US and continuing to serve the US market from elsewhere, because the US does not have a nation-wide firewall. And working with organizations mounting legal challenges to "please destroy your company in order to put in a backdoor for us".

Certificate Transparency has essentially eliminated the problem of backdoored CAs, because attempting to do so would destroy an entire CA. Binary Transparency can do the same for software.