Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

75% Positive

Analyzed from 505 words in the discussion.

Trending Topics

#closed#security#profit#source#nhs#author#healthcare#repos#here#etc

Discussion (12 Comments)Read Original on HackerNews

ameliaquiningabout 2 hours ago
I get that this was probably difficult because of timing and such, but I wish Anthropic had announced at least one vulnerability in a closed-source program as part of the Mythos announcement. Since all the vulnerabilities announced at that time were in OSS, I think this contributed to the perception that the coming wave of security-research automation is specifically for programs where the LLM can look at the source code. (Anthropic claims that Mythos found vulnerabilities in closed-source programs, but that none of them had been fully patched yet as of the announcement, so didn't say what they were.)
extraduder_ireabout 1 hour ago
Is that "obscurity through insecurity"?
yummybrainzabout 4 hours ago
Perhaps I'm being paranoid and should assume ignorance rather them malice, but I can't help but wonder if there was significant lobbying from companies providing healthcare software to make these repos closed-source.

I know nothing about the NHS, so I have no idea if this is plausible.

keepupnowabout 3 hours ago
Not paranoia, that is entirely the case here.
FerretFred12 minutes ago
That almost how you spell "palantir"...
partomniscientabout 2 hours ago
The last things the capitalist powers that be want, is any sort of socialism. Profit > people, rather than People > profit.

Just a reminder - socialism does not necessarily imply communism, and and implementation of communism thus far has been extremely corrupt.

I lived the in the UK for a couple of years in the early 2000's, the NHS was awesome. It's now a shallow shell of its former self.

Australia where I'm from is trying to imitate the privitisation of health, but my state-local for-profit hospital just went tits up and has been acquired by the government. Partially because a baby needlessly died because profit > caring about human lives, but it wasn't accountable and used tax havens etc. etc.

Fuckin' mess.

I feel for the the UK, because at their best, they probably had the best socialised healthcare system in the world (partly because their population size afforeded them access to medical equipment that other similar countries in Scandinavia etc. can't quite afford).

The US profit motive trumps well-being and healthcare tied to your employment just screws with our heads for most reasonable people. The people that need the help the most are denied it, whilst for the rich - it's built in.

robin_realaabout 5 hours ago
Like you say in the article, please make sure you mirror the repos back up to a public forge in the event that they’re closed.

I remember when I was at GDS back in 2016 a less-central team tried to make a repo private because of an security incident they decided not to prioritise, and they were surprised to find out that forks didn’t go private as well when they did it. Luckily they changed tack after a pointed conversation.

benj111about 1 hour ago
So security through obscurity then.
bcjdjsndonabout 1 hour ago
Every secret service and military on the planet seems to think it's a valid tactic
bcjdjsndonabout 1 hour ago
> I've no idea what led to NHS England making this retrograde decision - so I've send a Freedom of Information request to find out.

Is he being naive here? They give explicit reasons for the change. I suspect the author is unaware of the wider picture here, he may be tech savvy but he does not know how to run a national health service and he's speaking way out of his comfort zone.

nextaccountic38 minutes ago
The author has this to say

> The majority of code repos published by the NHS are not meaningfully affected by any advance in security scanning. They're mostly data sets, internal tools, guidance, research tools, front-end design and the like. There is nothing in them which could realistically lead to a security incident.

Such repositories should not be closed due to a knee jerk reaction

skeledrewabout 1 hour ago
Author is very much aware as author was a part of the organization and helped with the open sourcing efforts in the first place.