EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

07.31.09

Security FUD Against GNU/Linux

Posted in Apple, FUD, GNU/Linux, Microsoft, Security, Windows at 1:59 pm by Dr. Roy Schestowitz

Mask

Summary: Sightings of security FUD against GNU/Linux in the news

MICROSOFT WINDOWS never had the reputation of a secure platform. In fact, just a short while ago a new kernel vulnerability was found in Windows. To give the gist of the issue:

A local user can invoke NtUserConsoleControl() in ‘win32k.sys’ to execute arbitrary code on the target system with elevated privileges.

There is also this new report from Heise and many more that we shared over the past few days (the last one came yesterday morning).

Microsoft has issued updates for Internet Explorer and Visual Studio “out of band”, between the regular monthly patch days, to mend the ActiveX support of Internet Explorer. Additionally, these updates plug another three critical security vulnerabilities in the browser. All versions, including Internet Explorer 8, are affected.

This brings us to the following new article from Forbes, which states:

Virtual machines, which perform like physical machines but are simulated with software, have fewer sources of entropy: Linux-based virtual machines, for instance, gather random numbers only from the exact millisecond time on their internal clocks. And that source isn’t enough to generate strong keys for encryption, Stamos argues. “Normally there’s enough variation that after a while your operating system can gather up the entropy it needs to provide you with secure random numbers,” he says. “The fundamental issue is that with virtualized hardware, many of those random variations don’t exist.”

[...]

If a malicious hacker were to set up his or her own Linux virtual machine in Amazon’s EC2 cloud service, for example, he or she could use that machine’s entropy pool to better guess at the entropy pools of other recently created Linux-based virtual servers in Amazon’s cloud, Stamos posits.

What does that have to do with GNU/Linux? Why does Forbes conveniently assume that only “Linux” can suffer from this co-allocation issue? If it is not intended to daemonise GNU/Linux, then it might be worth correcting.

Carla has just found another new example that she wrote about in length. She addresses the whole “obscurity” argument, noting that:

Linux permeates every possible segment of tech– routers and networking devices, home and business automation, security and surveillance systems, phones, netbooks and other consumer mobile devices, desktops, vehicles, media servers and settop boxes; it’s already a major player in the datacenter, server room, mainframes, clusters, and supercomputing. Linux runs on multiple CPU architectures. So a Windows-type Trojan horse or worm on Linux should have a much more catastrophic effect because of Linux’ much greater reach.

According to Roughly Drafted Magazine, Rupert Murdoch’s Fox is taking shots at Mac OS X as well.

Fox News reports new Mac virus that is neither Mac nor viral nor new

A report published by Fox News says that “online criminals are apparently so impressed with its scorching sales they are sending Macintosh computers an attack typically aimed at” Windows PCs. The story then falls apart in series of inept contradictions.

The press loves pretending that Windows is never the culprit, despite compelling evidence that these very same outlets/publications are most certainly aware of the culprit.

“Our products just aren’t engineered for security.”

Brian Valentine, Microsoft executive

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Journal of Intellectual Property Law and Practice Calls the European Patent Office “Rotten”, Other Sources Scrutinise Recent Moves

    The patent office which was once known for being the best bar none is rotting under the Frenchman Benoît Battistelli, who made himself and his friends the main clients of the Office



  2. PTAB Emerges as Hero of USPTO Because Quality of Patents Improves, Software Patents Are Effectively Dead (or Dying Once Reassessed)

    With help from the Patent Trial and Appeal Board (PTAB) -- not just patent courts -- software patents drop like flies by the thousands



  3. Creative Technology, Now Operating in 'Patent Troll' Mode, Shot Down by the ITC; Jawbone Too Shot Down

    Some good news from the U.S. International Trade Commission (ITC), which may have put an end to Creative's new war on Android (using old patents)



  4. Corporate Media in India Misrepresents Startups to Push for Software Patents

    A parade of misinformation as seen in Indian (but English-speaking) press this week as questions about patentability of software resurface



  5. Links 25/8/2016: Linux Turns 25, NetworkManager Turns 1.4

    Links for the day



  6. Links 24/8/2016: More From LinuxCon, Uganda Wants FOSS

    Links for the day



  7. Links 23/8/2016: GNOME 3.22 Beta, Android 7.0 Nougat

    Links for the day



  8. The Linux Foundation Gives Microsoft (Paid-for) Keynote Position While Microsoft Extorts (With Patents) Lenovo and Motorola Over Linux Use

    This morning's reminder that Nadella is just another Ballmer (with a different face); Motorola and Lenovo surrender to Microsoft's patent demands and will soon put Microsoft spyware/malware on their Linux-powered products to avert costly legal battles



  9. Not Just President Battistelli: EPO Vice-Presidents Are Still Intentionally Misrepresenting EPO Staff

    Evidence serving to show that EPO Vice-Presidents are still intentionally misrepresenting EPO staff representatives and misleading everyone in order to defend Battistelli



  10. Battistelli the Liar Causes a Climate of Confrontation in French Politics, Lies About Patent Quality (Among Many Other Things)

    Battistelli's lies are coming under increased scrutiny inside and outside the European Patent Office (EPO), where patent quality has been abandoned in order to artificially elevate figures



  11. The Collapse of Software Patents and Patent Law Firms Trying to “Overcome” Alice

    The United States continues its gradual crackdown on software patents (which are viewed as abstract and thus unpatentable), whereas in Europe things are murkier than ever



  12. Apple's Patent Wars Against Android/Linux Make Patent Trolls Stronger

    Apple's insistence that designs should be patentable could prove to be collectively expensive, as patent trolls would then use a possible SCOTUS nod to launch litigation campaigns



  13. Links 22/8/2016: Linux 4.8 RC3, Linux Mint 18 “Sarah” KDE Beta

    Links for the day



  14. Links 21/8/2016: Apple and Microsoft Down, Systemd Spreading to Mount

    Links for the day



  15. Links 20/8/2016: Android Domination, FSFE summit 2016

    Links for the day



  16. Patents Roundup: Trolls Dominate Litigation, PTAB Crushes Patents, Patent Box Regime Persists, and OIN Explains Itself

    Another roundup of patent news from around the Web with special focus on software patenting



  17. The Cost/Toll of the 'New' EPO and Where All That Money Goes or Comes From

    The European Patent Office has become a servant of the rich and powerful (including large foreign corporations) and even its own employees now pay the price associated with misguided new policies (or 'reforms' as Battistelli habitually refers to these)



  18. Links 19/8/2016: Linux Mint With KDE, Linux Foundation's PNDA

    Links for the day



  19. The End of an Era at the USPTO as Battistelli-Like (EPO) Granting Policies Are Over

    The United States is seeing the potency of patents -- especially software patents (which make up much of the country's troll cases) -- challenged by courts and by the Patent Trial and Appeal Board (PTAB)



  20. Battistelli's European Patent Office Goes to the United States to Speak About the UPC and Software Patents

    The European Patent Office is showing its utter contempt -- not just disregard -- for the very fundamental rules that put it in its place and brought it into existence



  21. Turkey Subjected to the European Patent Convention (EPC) But Benoît Battistelli is Not?

    The ‘constitutional crisis’ at the European Patent Office in the context of Turkey, which has signed "the EPC and as such recognises the competence and the decisions of the institutions which have been introduced in the convention."



  22. Links 18/8/2016: EFF Slams Vista 10, Linux Foundation Makes PNDA

    Links for the day



  23. Links 17/8/2016: GNOME and Debian Anniversaries

    Links for the day



  24. Personal Audio LLC and Patent Troll Jim Logan Demonstrate the Harms of Software Patents and Why They Must Never Spread to Europe

    Jim Logan of Personal Audio (a notorious Texas-based patent troll) is still fighting with his bogus patent, having already caused enormous damage with a single software patent that should never have been granted in the first place (due to prior art, not just Alice)



  25. The Patent Microcosm Hopes That the Originators of Software Patents Will Undermine the Patent Trial and Appeal Board

    Now that the actions of the Patent Trial and Appeal Board (PTAB), which have been consistently upheld by the CAFC in precedential decisions, are suddenly being questioned the patent microcosm gets all giddy and tries to undermine PTAB (again)



  26. That Time When the Administrative Council Helped Battistelli Crush Oversight (Audit Committee) and What ILO Said About It a Month Ago

    Things are becoming ever more troublesome at the EPO as the Administrative Council enjoys inaction from the International Labour Organization (ILO), in spite of its role in destroying much-needed oversight at the behest of Battistelli



  27. The EPO's Administrative Council Keeps Postponing Debate About Grounds for Firing the President

    A recollection of events prior to the latest Administrative Council meeting, where Benoît Battistelli's failings and accountability for failing to correct them never even came up



  28. A Surge of Staff Complaints About the European Patent Office Drowns the System, Disservice to Justice Noted

    Self-explanatory graphs about the state of the justice [sic] system which is prejudiced towards/against EPO workers, based on internal reports



  29. Links 16/8/2016: White House Urged by EFF on FOSS, Go 1.7 Released

    Links for the day



  30. Links 15/8/2016: Linux 4.8 RC2, Glimpses at OpenMandriva Lx 3.0

    Links for the day


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts