EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

03.07.10

Security Disinformation

Posted in FUD, Free/Libre Software, Microsoft, Security at 8:57 am by Dr. Roy Schestowitz

Measuring electricity

Summary: Latest OpenSSL FUD and Microsoft’s Howard Schmidt’s role informing the public about cyber-security risks

OUR complaints about The Register have intensified recently [1, 2, 3, 4] because of poor articles like this one (see the comments).

The Register spreads FUD about OpenSSL (not the first such smear, after comparisons to "communism" too) and Bradley M. Kuhn from the SFLC has responded as follows:

Ok, Be Afraid if Someone’s Got a Voltmeter Hooked to Your CPU

Boy, do I hate it when a FLOSS project is given a hard time unfairly. I was this morning greeted with news from many places that OpenSSL, one of the most common FLOSS software libraries used for cryptography, was somehow “severely vulnerable”.

I had a hunch what was going on. I quickly downloaded a copy of the academic paper that was cited as the sole source for the story and read it. As I feared, OpenSSL was getting some bad press unfairly. One must really read this academic computer science article in the context it was written; most commenting about this paper probably did not.

First of all, I don’t claim to be an expert on cryptography, and I think my knowledge level to opine on this subject remains limited to a little blog post like this and nothing more. Between college and graduate school, I worked as a system administrator focusing on network security. While a computer science graduate student, I did take two cryptography courses, two theory of computation courses, and one class on complexity theory. So, when compared to the general population I probably am an expert, but compared to people who actually work in cryptography regularly, I’m clearly a novice. However, I suspect many who have hitherto opined about this academic article to declare this “severe vulnerability” have even less knowledge than I do on the subject.

There are much bigger problems to worry about, such as the latest news about Windows botnets [1, 2, 3]. The authors of the Windows exploit might not even face a jail sentence, based on this report.

Three Spanish men were arrested last month for allegedly building an international network of more than 12 million hacked PCs that were used for everything from identity theft to spamming. But according to Spanish authorities and security experts who helped unravel the crime ring, the accused may very well never see the inside of a jail cell even if they are ultimately found guilty, due to insufficient cyber crime legislation in Spain.

Regarding this new article about Scott Charney’s outrageous remarks [1, 2] (he worked for the US government before Microsoft hired him), Groklaw wrote 3 days ago: “First Microsoft fills the world with security issues and problems, then it wants the public to be taxed to fix them? I think Microsoft needs to fix its own software itself.” Microsoft’s own negligence [1, 2, 3] ought to have Microsoft bear the bill.

Howard Schmidt, the US Cyber Czar who came directly from Microsoft [1, 2, 3, 4], claims/pretends that there is no problem, even though many firms that include Google were intruded due to an Internet Explorer hole that Microsoft had knowingly ignored for 5 months [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12] (there are more security patches coming shortly). Even Google source code got grabbed. [via]

Operation Aurora continues to be a hot topic inside and outside of security circles. At this week’s RSA Conference in San Francisco many conversations are on the topic of the attacks that hit Google and dozens of other companies in January.

These reports indicate that proprietary source code got nicked from Google. Microsoft also nicks proprietary source code from companies/projects like Plurk [1, 2, 3, 4], which probably puts the Redmond-based company at the same side as the crackers.

“Cyberwar Hype Intended to Destroy the Open Internet,” says this report from Wired. [via]

The biggest threat to the open internet is not Chinese government hackers or greedy anti-net-neutrality ISPs, it’s Michael McConnell, the former director of national intelligence.

McConnell’s not dangerous because he knows anything about SQL injection hacks, but because he knows about social engineering. He’s the nice-seeming guy who’s willing and able to use fear-mongering to manipulate the federal bureaucracy for his own ends, while coming off like a straight shooter to those who are not in the know.

And on the other hand, on the same occasion we find that “US urges ‘action’ needed to fight net attacks,” according to the BBC.

Homeland Security secretary Janet Napolitano has admitted there is an urgent need to step up efforts to protect Americans from cyber attacks.

They seem to contradict themselves. Now they claim to be looking for ideas:

Homeland Security wants to pick your brains

[...]

The lucky winners will be invited to an event in Washington DC in late May or early June. They’ll get to partner with the department to lead in the planning of the National Cybersecurity Awareness Campaign, due to launch in October.

Over at CNET, Dennis O’Reilly has this new article about “five ways to keep your [Windows] PC free of viruses and Trojans”. Here is one of his suggestions.

If you can’t give up Windows, you may still be able to install Linux on an old PC or in a partition of your Windows PC. Then you can use that system (or partition) whenever you engage in any sensitive computer activities. You’ll find instructions for dual-booting Windows and the Ubuntu version of Linux on the Ubuntu Community Documentation site.

Thumbs up to Dennis.

“Usually Microsoft doesn’t develop products, we buy products. It’s not a bad product, but bits and pieces are missing.”

Arno Edelmann, Microsoft’s European business security product manager

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • StumbleUpon
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Propeller
  • Slashdot
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

A Single Comment

  1. your_friend said,

    March 7, 2010 at 12:39 pm

    Gravatar

    Everyone should email the DHS and tell them what the message should be, not how to carry it. They message should be to Stop Using Windows and move to free software.

    cyberchallenge@dhs.gov

    It is doubtful DHS will publish such a message but it would be good to let them know what the real consensus opinion is. If you read BN without TOR, you are already on their list of trouble makers. Go ahead and let them know what you really think.

What Else is New


  1. Vista 7 Price Drops Show Its Sales Are Poor

    Vast majority of Vista 7 "sales" are licence write-offs and Microsoft tries to convince people to shop for Vista 7, not be forced to get it with a new PC



  2. U.S. Military Hit by Windows, Learns Nothing From Microsoft Negligence

    Failures to name the culprit after a serious military intrusion; new examples where Microsoft knowingly ignores and leaves open holes inside Windows



  3. Let Them Eat Mice

    Where almost every Microsoft-branded computer mouse is made there is little action to ensure humane treatment of employees



  4. IRC Proceedings: September 5th, 2010

    IRC logs for September 5th, 2010



  5. Microsoft Almost Downgraded Again (This Time by Credit Suisse), Value Falls Sharply

    Microsoft's value falls well below Apple's and Credit Suisse gives Microsoft another small blow



  6. Microsoft's Veteran Suzan DelBene 'Part of the Problem' in D.C.

    How former Microsoft employees who become politicians facilitate the company's corruption of the government



  7. Microsoft IDC Managing Director is Leaving on September 24th, Another Vice President Quits

    Srini Koppolu (MSIDC) and Bill Mitchell say goodbye to Microsoft, leaving the company deeper in a gutter



  8. Links 5/9/2010: KDE SC 4.5 Coverage, Systemd in Fedora 14, Debian 7.0 Named

    Links for the day



  9. New Event Video: Software Patents and the Commons

    Keynote address by Professor Eben Moglen, “The Commons As An Actor in Transforming Global Political Economy" (September 1st, 2010)



  10. IRC Proceedings: September 4th, 2010

    IRC logs for September 4th, 2010



  11. Links 4/9/2010: Huawei and Android Phones, Toshiba and Android Tablets

    Links for the day



  12. Novell De-emphasises OpenOffice.org and Emphasises Mono Trojan Horses Instead

    Banshee, which Microsoft may be entitled to demand money for after an explicit warning, is being promoted by new employees of Novell, whereas other projects no longer receive much support



  13. Readers Respond to IDG's Fauxpen Source Blog

    Linux Today readers and also one of our own do not fancy IDG's attempts to change perception around the term "Open Source" and around Linux



  14. Death Patents Now Challenged and Software Patents Continue to be Used by Apple and Microsoft Against Linux

    Another quick overview of patent news most of which affecting Linux and Android



  15. Microsoft is Ranked the Worst Security Patching Offender

    Despite silent patching (without any disclosure) Microsoft is positioned worst in a new report



  16. Links 4/9/2010: 'Amnesia: The Dark Descent' as GNU/Linux Demo, WeTab Runs MeeGo

    Links for the day



  17. On Matters of Patents, Google Less of a Problem Than Microsoft, Apple

    Google has no history of patent aggression and hoarding (unlike IBM), it mostly falls prey to patent attacks, and it actively spreads Linux; thus, it should also help abolish software patents



  18. 'Inside Google' is an AstroTurfing/Lobbying Site, Not a Real Blog

    Edelman's anti-Google campaign seems to be nymshifting and chances are increasing that Microsoft is funding it, given its prior business with Edelman (e.g. laptop bribes)



  19. IRC Proceedings: September 3th, 2010

    IRC logs for September 3th, 2010



  20. No, Virginia! APIs, Visual Studio, and Apple Are Not Open Source

    Latest dangers to the identity of "Open Source", which increasingly means all sorts of things that depart completely from software freedom (or from software as a whole)



  21. Microsoft Crashes Rival's Event (OpenOffice.org Conference) Using Moritz Berger

    IBM's Rob Weir is rightly angry at Microsoft's intrusion into OpenOffice.org Conference, which he claims Microsoft is denigrating after giving some anti-OpenOffice.org talks in the same city



  22. Links 3/9/2010: Wine 1.3.2, Great Fedora Site Redesign

    Links for the day



  23. Divide and Conquer: How Microsoft Fractures Free and Open Source Software, GNU/Linux

    Latest examples of Microsoft's strategy, wherein it sends out affiliates to pretend to be FOSS people and then promote software patent deals, separation between Open Source and Free software, departure from the GPL, promotion of 'open' core (proprietary) as "Open Source", and demotion of free/libre platforms like GNU/Linux along with free suites/formats like ODF



  24. GNU/Linux Users in Techrights

    We deal with the old question, how many people who read Techrights use GNU/Linux?



  25. “Only Idiots Want to Pay for Novell” (Corrected)

    Strong words from Rui Seabra to Red Hat's Wildeboer, who criticises people's willingness to pay Microsoft for GNU/Linux



  26. GNU/Linux Keeps Gaining Market, Microsoft-Funded Net Applications Keeps Lying

    GNU/Linux market share on the desktop approaching 5% in W3Schools.com



  27. The Truth About Thomas Edison and New Species of Patent Trolls

    A look back at very abusive behaviour from a patent office icon; new critique of the patent process



  28. AOL Escapes Microsoft

    AOL turns to Google, despite rumours that Microsoft wanted to buy AOL



  29. Eye on Security: Windows Ransomware, DLL Hole, Malware, and More

    Menaces and unpleasant 'niceties' that only affect users of Windows this week



  30. Links 3/9/2010: GNOME 2.32 Beta 2, Android Tablets

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts