Bonum Certa Men Certa

Security Disinformation

Measuring electricity



Summary: Latest OpenSSL FUD and Microsoft's Howard Schmidt's role informing the public about cyber-security risks

OUR complaints about The Register have intensified recently [1, 2, 3, 4] because of poor articles like this one (see the comments).



The Register spreads FUD about OpenSSL (not the first such smear, after comparisons to "communism" too) and Bradley M. Kuhn from the SFLC has responded as follows:

Ok, Be Afraid if Someone's Got a Voltmeter Hooked to Your CPU



Boy, do I hate it when a FLOSS project is given a hard time unfairly. I was this morning greeted with news from many places that OpenSSL, one of the most common FLOSS software libraries used for cryptography, was somehow "severely vulnerable".

I had a hunch what was going on. I quickly downloaded a copy of the academic paper that was cited as the sole source for the story and read it. As I feared, OpenSSL was getting some bad press unfairly. One must really read this academic computer science article in the context it was written; most commenting about this paper probably did not.

First of all, I don't claim to be an expert on cryptography, and I think my knowledge level to opine on this subject remains limited to a little blog post like this and nothing more. Between college and graduate school, I worked as a system administrator focusing on network security. While a computer science graduate student, I did take two cryptography courses, two theory of computation courses, and one class on complexity theory. So, when compared to the general population I probably am an expert, but compared to people who actually work in cryptography regularly, I'm clearly a novice. However, I suspect many who have hitherto opined about this academic article to declare this "severe vulnerability" have even less knowledge than I do on the subject.


There are much bigger problems to worry about, such as the latest news about Windows botnets [1, 2, 3]. The authors of the Windows exploit might not even face a jail sentence, based on this report.

Three Spanish men were arrested last month for allegedly building an international network of more than 12 million hacked PCs that were used for everything from identity theft to spamming. But according to Spanish authorities and security experts who helped unravel the crime ring, the accused may very well never see the inside of a jail cell even if they are ultimately found guilty, due to insufficient cyber crime legislation in Spain.


Regarding this new article about Scott Charney's outrageous remarks [1, 2] (he worked for the US government before Microsoft hired him), Groklaw wrote 3 days ago: "First Microsoft fills the world with security issues and problems, then it wants the public to be taxed to fix them? I think Microsoft needs to fix its own software itself." Microsoft's own negligence [1, 2, 3] ought to have Microsoft bear the bill.

Howard Schmidt, the US Cyber Czar who came directly from Microsoft [1, 2, 3, 4], claims/pretends that there is no problem, even though many firms that include Google were intruded due to an Internet Explorer hole that Microsoft had knowingly ignored for 5 months [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12] (there are more security patches coming shortly). Even Google source code got grabbed. [via]

Operation Aurora continues to be a hot topic inside and outside of security circles. At this week’s RSA Conference in San Francisco many conversations are on the topic of the attacks that hit Google and dozens of other companies in January.


These reports indicate that proprietary source code got nicked from Google. Microsoft also nicks proprietary source code from companies/projects like Plurk [1, 2, 3, 4], which probably puts the Redmond-based company at the same side as the crackers.

"Cyberwar Hype Intended to Destroy the Open Internet," says this report from Wired. [via]

The biggest threat to the open internet is not Chinese government hackers or greedy anti-net-neutrality ISPs, it’s Michael McConnell, the former director of national intelligence.

McConnell’s not dangerous because he knows anything about SQL injection hacks, but because he knows about social engineering. He’s the nice-seeming guy who’s willing and able to use fear-mongering to manipulate the federal bureaucracy for his own ends, while coming off like a straight shooter to those who are not in the know.


And on the other hand, on the same occasion we find that "US urges 'action' needed to fight net attacks," according to the BBC.

Homeland Security secretary Janet Napolitano has admitted there is an urgent need to step up efforts to protect Americans from cyber attacks.


They seem to contradict themselves. Now they claim to be looking for ideas:

Homeland Security wants to pick your brains



[...]

The lucky winners will be invited to an event in Washington DC in late May or early June. They'll get to partner with the department to lead in the planning of the National Cybersecurity Awareness Campaign, due to launch in October.


Over at CNET, Dennis O'Reilly has this new article about "five ways to keep your [Windows] PC free of viruses and Trojans". Here is one of his suggestions.

If you can't give up Windows, you may still be able to install Linux on an old PC or in a partition of your Windows PC. Then you can use that system (or partition) whenever you engage in any sensitive computer activities. You'll find instructions for dual-booting Windows and the Ubuntu version of Linux on the Ubuntu Community Documentation site.


Thumbs up to Dennis.

"Usually Microsoft doesn't develop products, we buy products. It's not a bad product, but bits and pieces are missing."

--Arno Edelmann, Microsoft's European business security product manager

Comments

Recent Techrights' Posts

Jurgen Gaeremyn on Software Freedom Day
"today the event is more important than ever in the movement to further Software Freedom."
 
The Share of Microsoft's Vista 11 is Going Down This Year in China
Twilight for Microsoft
The Media May Never Recover (Major Divestments in the Public's Right to Know)
We shall be writing about press etc. and we'll explain the direction of the Web - albeit this topic is only indirectly related to Free software
Things to be Pleased About
Maybe GNU/Linux can exceed 5% by year's end or even reach 10% if one counts Chromebooks
statCounter Measures GNU/Linux at 12% in Sudan
strong adoption of GNU/Linux amid war
FSFE Copies the FSF, It Also Copies Techrights
Just copying a term that Techrights coined around 2007
GNU/Linux in Denmark: From Under 1% to 8%
this month
[Meme] Publishing as "allegedly breaching national security law."
China under CPC and HK under CPC is a sign of what may come next to the West
Killing the Public's Right to Know in Five Simple Steps
Julian Assange: Did I tell you about the time they forced me to plead guilty for 'conspiring' to expose war crimes?
Links 03/07/2024: Rubik Cube Turns 50, History Of Perpetual Motion, and Censorship in Social Control Media
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, July 02, 2024
IRC logs for Tuesday, July 02, 2024
Happy Birthday (With the Family)
So far they've managed to dodge or to avoid the tabloids
IBM's "DEI" Means Proprietary Software
Fedora Week of Diversity 2024, as we noted here last week, was just some niche event (online PR stunt)
Techrights Thanks Readers for the Support
People sacrifice a lot to inform and emancipate other people
About Half of Web Requests in Republic Of Korea Come From Android, It Used to be Over 99% Windows (2010)
The important thing is the trend
Matt Campbell's LibrePlanet Talk on AccessKit (Making Free/Libre Software Accessible to Disabled People)
"This talk will cover what we've accomplished so far, what's next, and how the community can help."
It's Time to Say Goodbye to Microsoft and Bill Gates
Nobody elected Bill Gates and why would Sunak wish to associate with an enabler of Jeffrey Epstein?
Adam Monsen on Steadfast Self-hosting
"Both the book and talk are about self-hosting free software, were created with free software, and are free software themselves."
Tomorrow It's British (UK) General Election, Cybershow Has a New Episode Exploring the Tech Angle
There are about 4 people involved in this episode
GNU/Linux and ChromeOS Rising in Zambia, Android Rises Above 72%, and Windows Down to Only 7%
Windows is down, Android is surging, and even GNU/Linux is doing reasonable well
Free Software Foundation (FSF) on Track to Meet Fundraising Goal
There are over 17 left
Links 02/07/2024: Summer Plans, Unit of Selection, and Debian
Links for the day
In Northern Mariana Islands (and Saipan) Android Replaces Microsoft Windows as Dominant Platform
Android finally exceeded Windows in terms of market share in Northern Mariana Islands
It's Julian Assange's Birthday, His Fundraiser Still 30,000 Pounds Short
20 days are left and it's one way to give a "birthday gift"
Luc Zimmerman (Geneva city council, Le Centre political party) advised Software Freedom Institute on trademark registration
Reprinted with permission from Daniel Pocock
This Month Colombia Has Exceeded the 4% Milestone for GNU/Linux
Colombia is more than twice the size of France
Even the News/Articles About Debian Are Slop and Spam Now
linuxsecurity.com is trying to destroy Linux news on the Web for SEO purposes (selling its proprietary junk)
Windows Measured at 1.6% in Central African Republic This Month
If we're meant to think Microsoft is worth "trillion of dollars", what is that valuation based on?
This Article is Freeware
Microsoft AI CEO mentions "freeware"
Steady Increases for GNU/Linux in Israel This Year
Windows is down to a quarter
An Own Goal: Filing Legal Cases in the UK When You Don't Even Live in the UK and Weren't Born In the UK
It'll just be expensive, tedious, and fruitless
Brazil's GNU/Linux Community Growing (a New High)
It's a new all-time high
Speaking to Sources (or People Outside One's Country) is Not Crime and Not Seditious
serious ramifications for publishers
GNU/Linux Above 6% in Hong Kong, Windows Falls to New Lows
Many choose to walk away from Windows
Android (Linux) Blasting Past Windows in France, Highest Desktop Share Since Winter for GNU/Linux
while Windows down
Stella Assange and Kristinn Hrafnsson Recorded This a Week Before Julian Was Freed (Knowing He Would Fly Out Soon)
What happened last week shows that even in notorious and stacked courts there's some hope
statCounter: GNU/Linux Starts July at Over 4%, Steam Survey Shows GNU/Linux at Over 2%
More to come, over time...
The Truth Will Always Win (Eventually)
RMS et al
CIA Whistleblower Jeffrey Sterling on Julian Assange and the Espionage Act
Some people don't survive and get out of there at all
Jen Robinson Explains How the Case of Evan Gershkovich Contributed to the Case for Release of Julian Assange
Robinson is an excellent counsel
Links 02/07/2024: DMA Violations and CSA Regulation
Links for the day
LibrePlanet 2024: Roberto Innocenti on the Latest Buzzword and Typically Misnomer ("AI")
It's about the latest "hot" buzzword
IBM: We Killed CentOS, Now Start Paying Us
The M in IBM is marketing
Links 02/07/2024: Jennifer Robinson Turns to Free Press in Hong Kong, Calls for an Assange Pardon
Links for the day
Gemini Links 02/07/2024: Project Crossroads and Reloading Packet Filter Tables
Links for the day
Seth Patterson on Git-based Workflow and Free Software for Literature and Storytelling
"We can create a storytelling community that allows cross-pollination between creators and disciplines (e.g., novels, songs, and video games) and changes us from consumers to creators."
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, July 01, 2024
IRC logs for Monday, July 01, 2024
Jennifer Robinson on Julian Assange's Birthday Tomorrow (Even the Judge Wished Him an Early Happy Birthday)
we know recordings exist and some people selectively publish these online
It's About Community, About Society, Not Business or Profit
The "rat race" is not for humans
LibrePlanet Talk on Making Movies With Free Software Only
"I can talk about how I made it and what I had to do to manage the project."
Links 01/07/2024: Catchup With Science and War in Ukraine
Links for the day
Gemini Links 01/07/2024: New ICQ and Demise of 'Agile' Cargo Cult
Links for the day
[Meme] IBM's Brand of Diversity and Inclusion: You Can't Install GNU/Linux If You Are Blind
Maybe Wayland is a lot more important to them than Diversity and Inclusion
Wikileaks Actually Helped Save the Planet
Without leaks, we'd not see the coordination of climate science deniers
Anti-Assange Provocations in Our IRC Network
We suspect it is the Microsofters, using a fresh batch of aliases
ChromeOS+GNU/Linux in Europe in First Half of 2024 (Windows Gradually Drowning)
We expect the latest measures to be even higher tomorrow, hopefully above 6%
Elon Musk Killed Not Only the Twitter Bird, He Also Killed the Platform
Today begins the second half of 2024 (2024 H2)
[Meme] Wayland at Every Cost
Fedora DEI and Wayland
RMS: "I am very glad for Assange for being out of prison, but I am alarmed that the danger of being treated similarly will face other journalists and publishers in the future"
what RMS said about the release of Julian Assange
What Richard Stallman (RMS) Thinks of Paying With Cash or 'Cashless Society'
RMS: Don't be tracked
No Discrimination Allowed Against People Who Pay With Cash
City of Philadelphia on cash
Anthony Albanes: Assange's "arrival home ends a long running legal process. [...] We'll have meetings about AUKUS and other arrangements over coming days as well."
Official transcript
4.04 Linux Not Found, No Such Agency (NSA)
The CoCs never failed Microsoft
Julian Assange Turns 53 in a Couple of Days, Give Him the Gift of Freedom From Debt
Julian Assange turns 53 on Wednesday
IBM's Abandonment of Disabled People (Orca and Wayland Incompatibility) Has Basically Killed Their "DEI" Channel (Room)
The "DEI" channel (Matrix room) as been silent for 4 days
[Meme] Just Because You Throw Money at Lawyers Doesn't Mean You'll Win
Welcome to the second half of 2024
Audio: Julian Assange Tells US Judge That Espionage Act and First Amendment Contradict One Another, But Pleads Guilty (to Save His Life)
Have a listen to Julian Assange and the judge in Saipan
How to Help Pay Assange Debt (£520,000 Plane Bill and Beyond)
Budget travel was not permitted
Paulo Henrique Santana (Collabora) on the Debian Brazil Community
There was similar material in DebConf22
Making the Wikileaks Site More Active Again (and Gradually Exiting "X" or Other Social Control Media)
As soon as Assange got kidnapped the Wikileaks Web site reached a near-standstill
Wikipedia Co-Founder (Not Wales) Expresses Support for Wikileaks Founder Julian Assange, Says Assange Will Probably Continue
probably exactly the sort of thing that the US prosecutors did not want
Marco Calegaro on Hacking Art Into a Community
talk by Marco Calegaro
Links 01/07/2024: Chokecherry Leaf and Agile Manifesto
Links for the day
Johannes Åsgård on Making the Raspberry Pi More Free With librerpi
Johannes (also known as dolphinana)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, June 30, 2024
IRC logs for Sunday, June 30, 2024