upvote
by weaponization you mean Win 11 requiring specific hardware etc?

your comment honestly just sounds like you dislike closed-source software.

for most commercial software projects, releasing the source provides no tangible benefit, aside from people like HNers being happy

but if Microsoft would've open sourced their OS, they would've been vulnerable to their OS being diluted into free versions or maybe even OEM-maintained versions

from a business sense, it makes no sense.

and as for security, closed source software is harder to attack (and was a lot harder to attack before LLMs). like, there's still much that we don't know about Windows internals exactly, and even those who do are a very small group of people.

it'd be a lot easier to find vulnerabilities if the source was open.

yes, it doesn't mean it's automatically more secure, in fact it can be less so if people don't have eyes on it, but I'd say the amount of attacks is less and usually done by more sophisticated attackers

reply
Weaponization of closed source software could take many forms and is just part of the general weaponization of market mechanisms that businesses do.

Right now it doesn't really affect me that Ableton Live is closed-source. But it would affect me if the main method of sharing music on the internet was Ableton Live project files. And if Ableton had cultivated that situation on purpose they would be weaponizing the closedness of their software.

reply
If we're talking about weaponization, then for sake of completeness let's remember that weaponization of open source is a very powerful business strategy that's been frequently used in the past 20 years, whether to market software, acquire free work, or as direct move, to try and destroy a market some competitor works on.

Some business models - like OSS, and free-with-ads - are like dimension-folding weapons from Dark Forest trilogy: once deployed, there is no stopping them, they just permanently drop a degree of freedom from the universe, inside a shell expanding at the speed of light.

reply
> by weaponization you mean Win 11 requiring specific hardware etc?

I can understand specific hardware and/or CPU generation requirements up to a certain point. Because CPU generations bring more than new instructions and performance, but I don't understand why Windows Team or Microsoft doesn't use function multi versioning to allow more systems to use up to date versions of Windows for longer time.

On the other hand, using closed file format related documentation as reference in a supposedly open format's specifications and trying to short-circuit ISO to push their seemingly open but ultimately closed document formats as standard or using Embrace, Extend, Extinguish tactics to kill competing products, or inserting code which makes their applications crash in competitors' operating systems is straight up malice.

...and we have Halloween documents which are openly(!) trying to make Linux non-functional on PC hardware, so there's that.

I'll note that these stuff can be also weaponized in Free / Open Source software. Pulling hardware baseline higher, deprecating drivers, and not giving good enough errors to make the problems obvious while not giving the source and/or building instructions/configurations is also a tactic of Red^H^H^H IBM. Remember: If you merge a company with IBM, you get IBM.

> your comment honestly just sounds like you dislike closed-source software.

Insisting about something when I openly and honestly said it's not is not very nice. Yes, Free Software is my first choice and where my heart lives at, but I'm not malicious about closed source software. This comment is being written on a Mac, for example. If you really want to dig that, my comment history is also in the open. For the record, as I always say, I prefer Linux desktops and Mac laptops, again for ~20 years or so.

> but if Microsoft would've open sourced their OS, they would've been vulnerable to their OS being diluted into free versions or maybe even OEM-maintained versions

I'm not saying that Windows would be dead if it was open source, but we'd have versions where ads and telemetry are straight up ripped from every possible part of it. Windows 11 and 10 to a certain point feels like it's working against me. Constant nagging, no ability to use local accounts during install, suggested apps everywhere... It's not an operating system anymore. It's a software holding me hostage to its agenda with a side effect of making my computer run. Windows XP was not like that, 2000 was not like that. Even 7 was good.

> from a business sense, it makes no sense.

You can always make it sense, if you decide to do that. There's SQLite for example. It's not an OS, but its development environment is protected enough so you can't get the quality the official versions propose.

However, I'm not saying that Windows shall be open source. However, its closed source nature is weaponized towards its users. Not with hardware requirements primarily, but how it herds the user and siphons data out of the computer in the name of telemetry.

> and as for security, closed source software is harder to attack

Ha, no. A small anecdote: When WMF attack vector was introduced, WINE team had the laugh of their life because the problem seemed so stupid to pass on. The next day, WINE released a patch, because it turned out that WINE also had the same security hole. They reverse engineered Windows API to a level that their implementation was bug for bug compatible.

Another one, about WINE again: My friends' Linux machine got infected with a Windows virus via WINE. The virus was unable to do harm, but it was infecting any USB drive attached to that computer. So, even if we didn't have the code, WINE has reverse engineered and implemented a bug-for-bug compatible Win32 API under Linux.

Both are pre 2010 events, BTW.

Also, with the leaks we have learnt that NSA had a truckload of zero days to infiltrate Windows systems. Great for security, right?

> it'd be a lot easier to find vulnerabilities if the source was open.

This is the half truth. Finding, fixing and evading the introduction of vulnerabilities are a lot easier if the source is open. We evaded 7z incident. Do we know that there's no universal backdoor in Windows? I don't. You can't know either. I don't my computer to have a TSA-approved keyhole somewhere.

Do you remember how NSA backdoored a cryptography algorithm? I do. See: https://en.wikipedia.org/wiki/Dual_EC_DRBG

Have you ever read how Crypto AG rigged secure communication devices sold to certain countries, even NATO allies, because they were in fact owned by CIA (and BND up to a certain point)? See: https://en.wikipedia.org/wiki/Crypto_AG

Closed source something can't be audited to be secure or anything. It doesn't make it harder to attack, however. Only the good guys (or nobody but us) doctrine doesn't work. An intentional backdoor doesn't discriminate. You say the correct phrase, and it opens.

> yes, it doesn't mean it's automatically more secure, in fact it can be less so if people don't have eyes on it, but I'd say the amount of attacks is less and usually done by more sophisticated attackers

Security through obscurity never stopped anyone from infiltrating anything. With enough persistence, any system even obfuscated can be cracked, even without LLMs. People reverse engineered SMB despite Microsoft's best efforts. Then, they registered it as CIFS and open sourced it, because they had to.

Please, we have gone through this 30 years ago. These arguments doesn't hold water anymore.

reply
> Insisting about something when I openly and honestly said it's not is not very nice.

I'm not insisting anything, I'm just saying that I don't think your arguments are purely objective, but rather from a matter of principle, which is fine, but to frame it as some kind of established fact that it's being "Weaponized" even though I'd say it's a bit extreme.

I don't like Windows, especially Windows 11, but I can understand why they exist and what markets they serve.

> but I don't understand why Windows Team or Microsoft doesn't use function multi versioning

because otherwise they'd have to support systems for a really long time and they'd be unable to support newer features that *they* think are important.

> I'm not saying that Windows would be dead if it was open source, but we'd have versions where ads and telemetry are straight up ripped from every possible part of it.

this is what I mean. your views are incompatible with closed-source software. not saying all closed-source software needs to have telemetry, but for the average user, this stuff probably helps catch bugs and things.

local accounts, I agree, I've never bothered with Windows 11 for that reason.

it's enshittification, not weaponization.

> You can always make it sense, if you decide to do that. There's SQLite for example.

this is just not a very good point. we're talking about paid products, paid OS that is paid by an OEM or an end-user.

> Not with hardware requirements primarily, but how it herds the user and siphons data out of the computer in the name of telemetry.

what data specifically? I'm not a fan of this either and I'd always disable everything, but it might again be something that people would really not care about. and for an organization like Microsoft, telemetry is probably very useful because otherwise they'd have to rely on user reports or test everything themselves

> Ha, no. A small anecdote

I really think you're dismissing this just because of your principles like "security through obscurity isn't security"

yet security through obscurity literally works. it's not foolproof, but a lot of bugs are never found because of it. and a big part of finding bugs is to get enough information to know where to look

like you saying "look my friend got a bug 15 years ago" doesn't disprove what I claimed.

> Also, with the leaks we have learnt that NSA had a truckload of zero days to infiltrate Windows systems. Great for security, right?

and what are you saying with this? the fact that only NSA (and some others probably) had the ability to find bugs is proof that the security failed?

> Finding, fixing and evading the introduction of vulnerabilities are a lot easier if the source is open.

yes, that is why I said "in fact it can be less so if people don't have eyes on it".

> Do we know that there's no universal backdoor in Windows? I don't.

that's right. we can't know there isn't one in MacOS either.

and yes, I do know about DUAL_EC_DRBG and Crypto AG.

"Closed source something can't be audited to be secure or anything. It doesn't make it harder to attack"

It literally does. the only argument against it is that with it being open you'd have others that would catch bugs and report them to the vendor, vs. keeping it to themselves, which I think is fair, but it doesn't make it harder to attack, at least historically when you had to put a lot of effort into security research which of course the intelligence agencies could leverage. I think this is changing with LLMs.

"Security through obscurity never stopped anyone from infiltrating anything. With enough persistence, ..."

it has stopped tons of attempts. literally.

there simply isn't an infinite amount of "persistence" available to people/orgs. it takes a huge amount of time to meticulously reverse engineer and find security holes in an OS like Windows, it's like games with DRM like Denuvo, it works. it's security through obscurity, but it works, it has held off games for like 6+ months after release.

"security" doesn't mean impenetrable, there's always going to be new bugs even in Linux, Chromium and others even though they're open.

but with closed source software, it is much harder to comb through it and find bugs.

> Please, we have gone through this 30 years ago. These arguments doesn't hold water anymore.

like, I don't understand what you mean with this.

you're talking like this is a settled argument and that you're just absolutely right, closed-source software is not harder to attack and it's just propaganda from the NSA or something?

like, we can be objective and point out the flaws of closed-source software and security through obscurity, but we also have to be realistic. things may be changing now, but at least up until very recently, only the most determined actors (usually organized groups) would be able to conduct sophisticated attacks against these systems

but also remember that a lot of the major vulnerabilities against Windows have been through leaks from the CIA and etc. that is not Windows being "breached yesterday and today". and Microsoft has the resources to hire very well-paid engineers who work on security around the clock, unlike with many FOSS projects

reply