cross-posted from: https://feddit.org/post/4415864

The petitioner calls for the European Union to actively develop and implement a Linux-based operating system, termed ‘EU-Linux’, across public administrations in all EU Member States.

This initiative aims to reduce dependency on Microsoft products, ensuring compliance with the General Data Protection Regulation (GDPR), and promoting transparency, sustainability, and digital sovereignty within the EU.

The petitioner emphasizes the importance of using open-source alternatives to Microsoft 365, such as LibreOffice and Nextcloud, and suggests the adoption of the E/OS mobile operating system for government devices. The petitioner also highlights the potential for job creation in the IT sector through this initiative.

[Edit typo.]

  • millie@beehaw.org
    link
    fedilink
    English
    arrow-up
    4
    ·
    23 hours ago

    It also means the entirety of the EU’s governments would be susceptible to the same vulnerabilities and bugs, and would share the same dependencies. Given recent issues with bad actors taking control of small but essential repos, this seems like a potentially dangerous security flaw.

    • Appoxo@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      2
      ·
      16 hours ago

      They are already interconnect at various points.
      Schools are connected to university networks, university networks to loval government intranets and those are again probably at some point connected to the federal network.
      I don’t wanna guess where else they have connections to like the police or legislative network.

      • millie@beehaw.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        15 hours ago

        There’s a world of difference between interconnectedness and an enforced monoculture of dependencies on a wide range of insecure repos maintained by hobbyists.

    • IrritableOcelot@beehaw.org
      link
      fedilink
      arrow-up
      3
      ·
      18 hours ago

      I mean yes, but currently they’re all dependent on Windows, so its less of centralizing OSes, and more changing what its centralized on.

      • millie@beehaw.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        17 hours ago

        Okay, but when’s the last time someone created a security vulnerability by sneakily taking over a Windows dependency controlled by a single developer after pressuring them into handing the keys over with a bunch of sockpuppets?

          • millie@beehaw.org
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            15 hours ago

            It’s not, though. It’s a much wider potential for failure, as there are a great number of dependencies that are often left to individual developers to maintain. That may be a somewhat reasonable amount of risk when you’ve got multiple options for dependencies and no major target, but when the entire EU relies on single individual maintainers? That’s a massively exploitable threat vector. It would be absurd to assume no one will take advantage given what we’ve already seen.

            It would be an extremely foolish move to put the whole EU’s security on one single set of open source dependencies. Microsoft at least has a financial and legal incentive to try to prevent straight up breaches by state actors, shitty as they may be. There’s no such resource allocation or responsibility when it comes to open source repos.

            Push a switch to Linux, by all means, but security monoculture is as big a mistake as putting your eggs in any other single basket, especially one as exposed as one single distro.