Bonum Certa Men Certa

Unverified Claim: Sam Ransbotham's Belittling of Free/Libre Software Funded by Microsoft

Campus photos



Summary: "Open-Source Could Mean an Open Door for Hackers," says a new article from Robert Lemos, but the facts just don't add up and suspicions arise that Microsoft is in fact partly funding these claims

Two readers separately E-mailed us about a new article that looks too suspicious because it's flatly wrong. "This came up in the ACM daily email today," wrote one reader and another one writes: "Find out if there is any Microsoft connection"



"Apparently, this is another Microsoft-funded study bad-mouthing open source software," said the first reader. I asked: "Where can I see that it's Microsoft funded?"

"Even if that's not the case," he replied, "it has been characterized as a FUD attack."

"I didn't have time to investigate it myself," points out this first reader who cites Dana Blankenhorn and some of the comments we'll get to in a moment:

You don’t expect misleading FUD about open source from MIT’s Technology Review. But here it is.

The story is about a Boston College professor (and Georgia Tech grad — go Jackets) named Sam Ransbotham...

The misleading bit is the idea that open source vulnerabilities spread faster, and are exploited both sooner and with more force, than bugs in proprietary software.

It’s true, but it’s wrong to draw large conclusions from that.

In his work Ransbotham looked at a list of 883 known vulnerabilities and found 97 exploited over two years, 30 of them in open source. Attacks on open source were broader and moved faster than those on closed source.

The real story is a bit nastier. The biggest correlation Ransbotham found was not between open source and attack, but between the existence of a security signature and attacks.


Here is the original article. There is a comment titled "How Paid Studies Reflect Desires of Those Who Pay" and it says (emphasis in red is ours): "Paid studies are all notorious for proving that the sponsor of a study can usually get findings that support their desired outcome. Since this study is funded primarily by Microsoft, then the results should not be surprising. The article is not based on any outright deception or lies, simply on two levels of ignorance. First, the naivete and lack of programming expertise of the general audience who might accept these findings -- a response that no credible or responsible programmer would support, unless he or she also were a partisan MS loyalist. One must only read the weekly threat announcements of critical vulnerabilities in Microsoft and Adobe products, for example to realize that nothing could be more vulnerable than these highly vaunted proprietary products. The second level of ignorance relates to intrinsic security permissions in most UNIX/LINUX operating systems versus that of Microsoft Windows, including Windows Seven. Most of the worlds secure servers are all running on some UNIX based OS, not Windows, for matters of security and reliability -- they are running Solaris, UNIX, or some flavor of LINUX. And this has everything to do with inherent security permissions for the Root user account, versus the "administrative permissions" in Windows that always leave a number of little windows, shutters, back doors and ports wide open to attack, and ability to modify critical registry entries in the Windows OS. There is no "registry" to attack in UNIX, Solaris or LINUX, and nothing can modify a Root file unless it is a live password protected Root User. Autorun scripts and VBS scripts cannot exploit these systems at all."

Another commenter claims an "advertisement coincidence" when s/he writes: "The advertisement for this article is for Microsoft Server. Coincidence? I think not."

Comments

Recent Techrights' Posts

Microsoft Trots Out Its Propaganda Agent Preston Gralla to Make It Sound Like Microsoft Breaks Up With China (Reality: Microsoft Got Dumped by China)
This discredits any publisher that plays along
SLAPP Censorship - Part 161 Out of 200: Low Standards in Defamation Cases Just Muddy the Waters and Distract From Legitimate Cases
The judge at the trial said that Garrett's case was a waste of the court's money
Congrats to Linux.org for Adopting or Getting Back to IRC
This is the way the Net ought to work and was originally designed to work [...] IRC as a protocol turns 38 this month
 
Links 25/08/2026: Microsoft Salaries Leaked Again, "Oasis Photograph Sparks Copyright Lawsuit"
Links for the day
GNU/Linux Did Not Start in 1991 and America Wasn't Discovered by Europeans
it'll be 43 next month
Rolling Out Some Changes Soon
To the regular reader no change will be seen
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, August 24, 2026
IRC logs for Monday, August 24, 2026
Gemini Links 25/08/2026: Separated by Plexiglass, Low-Tech Information Networks, Jörg Rippel Comes to Geminispace
Links for the day
The Tragedy of Software Developers Making Up Narratives and Making Excuses for Plagiarism (of Their Own Work, Too)
one lingering issue is that many who vote in Debian GRs receive money from slop companies
Evri Makes Us Optimistic About the Collapse of the Slop Pyramid Scheme (Bubble)
Do not be seduced by false promises of "automation" or "intelligence" where only automation may exist but no intelligence at all
Links 24/08/2026: "Journalism Can Help Expose Bad Science And Trigger Real-World Change"; Further Suppression and Censorship in China/HK
Links for the day
Gemini Links 24/08/2026: Soul Mentality, Words to Live by, Mozz.us Gemlog Resumes, Smol Conversations
Links for the day
Today The Register MS Published Greenwashing Spam for the Slop Pyramid Scheme, It Mentions "AI" 29 Times
More people need to talk about the role of the media in this pyramid scheme
Slop Plagiarism and Chatbots Are Killing Evri (They Infuriate and Insult Clients)
Slop destroys companies and leads to misery (miserable clients, time-wasting)
Links 24/08/2026: Re-defining the IndieWeb and "Data Center Backlash Bursts Into the Midterms"
Links for the day
The Issue With Omarchy is the Slop, the Politics Are a Side Issue
Those corporations do not oppose slop, they participate in it
In South Korea, Steady Increases for GNU/Linux
authorities said they would migrate to GNU/Linux or consider moving in that direction
SLAPP Censorship - Part 160 Out of 200: In Astounding Repetition of Last Year, Brett Wilson LLP Deliberately Ignores Holidays of People It is Attacking and Crushes Principles of Access to Justice
Disconnected from the law
Links 24/08/2026: Vision and Skill, Doing Good, Chiperia Project
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, August 23, 2026
IRC logs for Sunday, August 23, 2026
Gemini Links 23/08/2026: Turning 60, PineTime, and Simulation Hypothesis
Links for the day
Will Your "Modern" New Car Still be on the Road in 2060?
Are people now expected to change a car as often as they replace a mobile phone and, if so, how fast would costs add up?
The Sniff Test
Be sceptical of "CoCs"
Cloudflare Sees a Quarter of Requests in China Coming From GNU/Linux Today
Will 23% ever be the average for GNU/Linux rather than a mere peak?
You Can Lose Some Battles and Still Win the War
Winning or losing isn't something for a scoreboard
GNU/Linux Usage Measured at 23% in Russia Today
the average was almost 10%
Things Not to Fear Missing Out on
Life is too short to pay attention to social control media
Gemini Links 23/08/2026: Exercising Again, Tackling Phone Addiction, and Putting Graal Online Back Online
Links for the day
Northern Africa: GNU/Linux Measured at Around 5%
by Clownflare
PIPs and Lawsuits: On the Future of IBM Trying to Spit Out Its Own Staff at Minimal Cost
"I'd rather be laid off than be put on a PIP"
France: GNU/Linux Averaging at 7%, Peaked at 14% Today
When will 14% be the average?
Links 23/08/2026: Water Crises, Illegal Tariffs, and Carney Confronts US Over Patent Imperialism
Links for the day
Links 23/08/2026: Slop "Children's Stories Contain Bizarre Patterns" and "Butterflies at the One Garden"
Links for the day
SLAPP Censorship - Part 159 Out of 200: Telling Courts False Information and Spoon-feeding Them Insults, Hoping or Expecting Them to Repeat These Insults
When lawyers trick courts into repeating something false
Microsoft is in Double Trouble in Singapore
Android+GNU/Linux+ChromeOS are near 20%
The Slop Industry Bribed the Media to Pretend It Has Something New and Revolutionary. Now It Bribes Politicians Too. Anything to Avoid Scrutiny and Regulation.
borrowed money has long been used to bribe the media
"AGI" is Decades Old and It Never Found a Viable Business Model or Real, Actually Useful Use Cases
I keep reminding people of local firms (right here in Manchester) doing the same thing the media now calls "AGI"...
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 22, 2026
IRC logs for Saturday, August 22, 2026
Microsoft to Its Workers in April-May: You're Too Old, Go Away. Microsoft in August: Young People, Go Away.
What does this company even sell anymore?
Clownflare Data US-Centric
We are assuming that for national security reasons not many sites in Chinese (or based in China) outsource their traffic to Clownflare
Gemini Links 22/08/2026: Broken Car, Devuan, and Thundermail
Links for the day