Language Selection

English French German Italian Portuguese Spanish

Proprietary Software Leftovers

Filed under
Microsoft
Security
  • New research on Swedish public sector organisations shows that there is a need for more awareness and understanding of lock-in risks when procuring cloud services

    In a recent paper, researchers at the University of Skövde in Sweden ask the question: “How do, and by which strategies should, public sector organisations address lock-in effects before use of commercial SaaS solutions?”. This analysis plays into one of the most relevant debates related to open source in the public sector.

    Public sector lock-in to proprietary solutions has been central in arguments put forward by advocates for more use of open source software by public institutions. This research follows earlier academic findings showing how lock-in effects can impose many different types of technical, legal, economic and societal challenges for public sector organisations. But this latest paper analyses the awareness of these risks in the processes of public sector procurement of cloud services.

    The authors find that municipalities adopt and use cloud solutions from large global suppliers “under potentially problematic contract terms”. The main example given is the City of Gothenburg, who entered into an agreement with Microsoft for adopting Office365. The City uses Office365 for large scale data processing but has not carried out an impact assessment outlining the jurisdictions in which data can be, and has been, processed.

  • Addressing Lock-in Effects in the Public Sector: How Can Organisations Deploy a SaaS Solution While Maintaining Control of Their Digital Assets?

    The study shows a widespread practice amongst PSOs to adopt and use a widely deployed SaaS solution from a global supplier under potentially problematic contract terms. The City of Gothenburg and most other PSOs use their adopted SaaS solution to process data on a large scale with users that are in a position of dependence without having carried out an impact assessment, despite the fact that PSOs are unaware of in which jurisdictions data can be, and have been, processed. Some PSOs identified prior to their adoption and use of their SaaS solution that the terms allow for data processing in several third countries. None of the organisations present any evidence to suggest that they have tried to obtain all necessary patent licences for the ITU-T H.265 standard from third parties which would allow for use of the adopted SaaS solution. Since these licences, in addition to licences for a large number of other standards, would also be needed to allow for implementation of the closed file format standards in software that can be provided by other suppliers it follows that organisations are potentially exposed to significant risks of losing control over their own digital assets.

    Findings from the study also show that none of the investigated organisations present any strategy that would allow them to cease using the SaaS solution in a way that exported digital assets can be used and reused by other software applications in the future. The study shows that amongst the few PSOs that present some documented risk analysis there is strong faith that their current supplier will assist in a potential future situation if the PSO decides to abandon their current supplier.

    Further, findings show that recommendations presented in the literature for how to maintain digital assets during their entire life-cycle have been ignored by all investigated PSOs. Before adoption of a SaaS solution, none of the organisations had investigated whether digital assets created and maintained in the SaaS solution can be exported in open file formats and open standards to allow use and reuse after exit. Further, none of the investigated PSOs have presented any analysis which addresses how to obtain all licences they require when, and after, the adopted SaaS solution is used. Hence, it is unclear if any of the organisations will be able to interpret their own files without support from their current supplier in a potential future situation when they have ceased to use the SaaS solution.

    In summary, all investigated PSOs have failed successfully to address critical issues that need to be considered before adoption and use of a SaaS solution.

  • How affected was WhatsApp by Pegasus in India, asks SC

    One set of petitions challenged WhatsApp’s new privacy policy even when pleas questioning its earlier privacy policy are still pending adjudication. A second set of petitions, including one by Rajya Sabha MP Binoy Viswam, has questioned the steps taken by payment apps run by multinationals like Google, Amazon and Facebook and raised the issue of Pegasus spyware targeting WhatsApp users.

  • Pentagon May Be Forced To Discontinue With JEDI Cloud Effort

    In October 2019, Microsoft won the Defense Department JEDI cloud contract worth up to $10 billion over a period of 10 years, beating out market leader Amazon.

    In the paper, DoD says: “Regardless of the JEDI Cloud litigation outcome, the Department continues to have an urgent, unmet requirement. Specifically, the Department’s need for an enterprise-wide, commercial cloud services for all three classification levels, extending from the homefront to the tactical edge, at scale.”

    The Department clarified that work on JEDI Cloud would “continue to be paused until the litigation process is complete, and DISA/CCPO remains ready to resume management of the JEDI Cloud work if/when the entire set of litigation is resolved in the Government’s favor.”

  • U.K. Arrest in ‘SMS Bandits’ Phishing Service

    Authorities in the United Kingdom have arrested a 20-year-old man for allegedly operating an online service for sending high-volume phishing campaigns via mobile text messages. The service, marketed in the underground under the name “SMS Bandits,” has been responsible for blasting out huge volumes of phishing lures spoofing everything from COVID-19 pandemic relief efforts to PayPal, telecommunications providers and tax revenue agencies.

More in Tux Machines

digiKam 7.7.0 is released

After three months of active maintenance and another bug triage, the digiKam team is proud to present version 7.7.0 of its open source digital photo manager. See below the list of most important features coming with this release. Read more

Dilution and Misuse of the "Linux" Brand

Samsung, Red Hat to Work on Linux Drivers for Future Tech

The metaverse is expected to uproot system design as we know it, and Samsung is one of many hardware vendors re-imagining data center infrastructure in preparation for a parallel 3D world. Samsung is working on new memory technologies that provide faster bandwidth inside hardware for data to travel between CPUs, storage and other computing resources. The company also announced it was partnering with Red Hat to ensure these technologies have Linux compatibility. Read more

today's howtos

  • How to install go1.19beta on Ubuntu 22.04 – NextGenTips

    In this tutorial, we are going to explore how to install go on Ubuntu 22.04 Golang is an open-source programming language that is easy to learn and use. It is built-in concurrency and has a robust standard library. It is reliable, builds fast, and efficient software that scales fast. Its concurrency mechanisms make it easy to write programs that get the most out of multicore and networked machines, while its novel-type systems enable flexible and modular program constructions. Go compiles quickly to machine code and has the convenience of garbage collection and the power of run-time reflection. In this guide, we are going to learn how to install golang 1.19beta on Ubuntu 22.04. Go 1.19beta1 is not yet released. There is so much work in progress with all the documentation.

  • molecule test: failed to connect to bus in systemd container - openQA bites

    Ansible Molecule is a project to help you test your ansible roles. I’m using molecule for automatically testing the ansible roles of geekoops.

  • How To Install MongoDB on AlmaLinux 9 - idroot

    In this tutorial, we will show you how to install MongoDB on AlmaLinux 9. For those of you who didn’t know, MongoDB is a high-performance, highly scalable document-oriented NoSQL database. Unlike in SQL databases where data is stored in rows and columns inside tables, in MongoDB, data is structured in JSON-like format inside records which are referred to as documents. The open-source attribute of MongoDB as a database software makes it an ideal candidate for almost any database-related project. This article assumes you have at least basic knowledge of Linux, know how to use the shell, and most importantly, you host your site on your own VPS. The installation is quite simple and assumes you are running in the root account, if not you may need to add ‘sudo‘ to the commands to get root privileges. I will show you the step-by-step installation of the MongoDB NoSQL database on AlmaLinux 9. You can follow the same instructions for CentOS and Rocky Linux.

  • An introduction (and how-to) to Plugin Loader for the Steam Deck. - Invidious
  • Self-host a Ghost Blog With Traefik

    Ghost is a very popular open-source content management system. Started as an alternative to WordPress and it went on to become an alternative to Substack by focusing on membership and newsletter. The creators of Ghost offer managed Pro hosting but it may not fit everyone's budget. Alternatively, you can self-host it on your own cloud servers. On Linux handbook, we already have a guide on deploying Ghost with Docker in a reverse proxy setup. Instead of Ngnix reverse proxy, you can also use another software called Traefik with Docker. It is a popular open-source cloud-native application proxy, API Gateway, Edge-router, and more. I use Traefik to secure my websites using an SSL certificate obtained from Let's Encrypt. Once deployed, Traefik can automatically manage your certificates and their renewals. In this tutorial, I'll share the necessary steps for deploying a Ghost blog with Docker and Traefik.