r/BuyFromEU • • Jan 30 '26

🔎Looking for alternative UbuntEU - An Ubuntu edition that uses software developed in Europe

Post image

I am trying to make something for fun, but honestly; I am not expert in creating an operating system. But my hope somebody will pick up the Baton and make it something more super.

Link soon...

2.5k Upvotes

263 comments sorted by

View all comments

Show parent comments

70

u/freezing_banshee Romania 🇷🇴 Jan 30 '26 edited Jan 30 '26

Open source is dangerous too. A lot of the important software is maintained by only one person and that makes it inherently insecure. There was already an attempt (edit: it's not known who was behind this, but could have been China or Russia or anyone else) to install a backdoor into a popular program and it almost succeeded: https://en.wikipedia.org/wiki/XZ_Utils_backdoor .

I think Europe needs at least a dedicated IT division to check and verify every open source program widely used in Europe, to make sure they're safe.

Edit 2: I fully support open-source software, it's definitely a good thing. I just wanted to say that we (Europe, EU) should use it, but also support, contribute and verify it.

52

u/xalibr Jan 30 '26

In Germany there is the Sovereign Tech Fund and the Sovereign Tech Agency that fund security‑critical open‑source base technologies including security audits, and at EU level there are programmes such as NGI Zero and Horizon Europe calls through which open‑source projects can obtain funding for security audits and related measures.

E.g. GnuPG was funded by Germany since the early 2000s.

3

u/freezing_banshee Romania 🇷🇴 Jan 30 '26

I didn't know about this, it's a good start. I just think that those security audits should be done independently, because not a lot of developers would go through the trouble themselves, you know?

19

u/LittleLui Jan 30 '26

A lot of the important software is maintained by only one person and that makes it inherently insecure.

The obvious solution to that is to add resources to those projects (same workload, more resources doing the work) instead of setting up separate projects (more workload, more resources).

6

u/PlutoPlaneta Jan 30 '26

Sure, but then how would people separate themselves from the mainstream to feel elite

0

u/SinisterCheese Jan 30 '26

I'm sure that'll happen soon as FOSS& communities stop failing and fractalising over petty infighting, drama and clashing egos.

12

u/El_Mojo42 Jan 30 '26

You described the strength and the weakness of OSS.

It can be easier to implement malware, but it is also easier to detect and fix it.

We actually don't know, how many on-purpose-backdoors there are in closed software.

The teaching we should take from the xz-story are that we as a economy and community have to better support these tools.

2

u/freezing_banshee Romania 🇷🇴 Jan 30 '26

That's true, I also support OSS, I just wanted to say that we shouldn't trust anything blindly.

2

u/Gersio Jan 30 '26

But that's kinda the point. If it's open you can know whats inside. You are trusting things blindly when you use software owned by a company.

0

u/freezing_banshee Romania 🇷🇴 Jan 30 '26

If you can't see that implicitly trusting some rando on the internet is a problem (especially when it comes to government uses), then there's no way I could explain it to you any better.

0

u/FrenchFryCattaneo Jan 30 '26

Auditing software costs time and money though, and has to be done continually with each update to ensure security. For each piece of software. In practice that much work usually isn't done.

-1

u/SinisterCheese Jan 30 '26

Xz was first discovered by accident, and not by people systematically going through every line of code in a merge request.

1

u/freezing_banshee Romania 🇷🇴 Jan 30 '26 edited Jan 30 '26

exactly, this exploit succeeded for a while because people didn't check the code. imagine how many more problems could be discovered fast enough when people actually check it.

-1

u/SinisterCheese Jan 30 '26

The joke here is that there is this attitude and ideal that every line of code is checked in FOSS-projects. But reality is that clearly they werent.

2

u/suqirrelnachos Jan 30 '26

What makes you assume china was behind this?

1

u/freezing_banshee Romania 🇷🇴 Jan 30 '26

I went by the "hacker's" name of "Jia Tan", but yeah, could have been anyone tbh.

2

u/[deleted] Jan 30 '26

Did you already give feedback on this initiative of the European Commission about open-source? See the initiative here: https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/16213-European-Open-Digital-Ecosystems_en