Eye on Security: Red Hat Explains Why Windows is Less Secure, New Windows 0-Day Attack
- Dr. Roy Schestowitz
- 2010-07-01 13:46:45 UTC
- Modified: 2010-07-01 13:46:45 UTC
Summary: Comparative security news from this week
●
Open Source is Inherently More Secure, Says Red Hat (Microsoft
admits silent patching it never discloses)
But in the closed source world, you have to trust your vendor completely. All you get to see are binaries, so you have no way of knowing how they were built. President Reagan was fond of saying to Soviet leader Mikhail Gorbachev, "Trust, but verify." With proprietary software, you simply have to trust.
Microsoft, for example, pushes out security updates on the second Tuesday of every month. Bressers said they can't do that. Microsoft has the advantage of hiding security flaws and working on them at their leisure, but with open source software, that's not possible because everyone can see that there's a problem and they expect it to be fixed right away.
And if a security hole isn't plugged quickly enough, you can fix it yourself, Bressers explained.
An example of the power of open source is the ping of death bug. Back in the late 1990s someone figured out that if you send a giant ICMP packet to a computer, just about any computer, it will crash. The bug affected every operating system, routers, printers, etc. When the problem was discovered, the open source Linux operating system had the bug squashed in about 2 hours, Bressers recalled. The closed source operating system vendors, however, took days, weeks and even months to make and distribute a patch for the ping of death.
●
Microsoft: 10,000 PCs hit with new Windows XP zero-day attack
Nearly a month after a Google engineer released details of a new Windows XP flaw, criminals have dramatically ramped up online attacks that leverage the bug.
Microsoft reported Wednesday that it has now logged more than 10,000 attacks. "At first, we only saw legitimate researchers testing innocuous proof-of-concepts. Then, early on June 15th, the first real public exploits emerged," Microsoft said in a blog posting.
●
New Windows Live Messenger has same old privacy problems
Why do I get the impression that some folks at Microsoft just don’t get it?
●
Privacy problems persist in latest Windows Messenger 2011 beta [
via]
Earlier versions of Messenger played fast and loose with your privacy. The new Live Messenger 2011, currently in beta, suffers from some of the same defects
Recent Techrights' Posts
- The Register MS Says "AI Web Crawlers Are Destroying Websites", So Why Does The Register MS Help 'AI' Companies? (Spoiler: Money)
- People need to call out The Register MS on its hypocrisy
- Slopfarms Already Peaked, They Will Die When Slop Companies Run Out of Money to Borrow
- slopfarms will lack an actual "engine"
- Why We Publish Information About the SLAPPs (But Not About the Legal Process), an Abuse of Process by Americans Trying to Silence Critics of Their Employer, Microsoft
- It doesn't take thousands of pages to explain something simple
-
- Slopwatch: Plagiarism and Ponzi Scheme, Bubble About to Burst Entirely, Admits Goldman Sachs
- the hype that Google News and The Register MS actively participate and profit from
- Links 02/09/2025: SCO Summit and Russia Suspected Of Jamming GPS
- Links for the day
- Gemini Links 02/09/2025: Mediterranean Marriage and Staying Connected at 35,000 Feet
- Links for the day
- Links 02/09/2025: Attacks on Unions, Microsoft TCO, and DDoSing a Growing Problem
- Links for the day
- Internet Relay Chat Didn't Fall Off a Cliff
- IRC will turn 40 in less than 3 years from now
- The UEFI 9/11 - Part V - This is Not a Drill (Disable "SecureBoot" Now)
- A "9/11" Coming
- There's No Obligation to Speak to Anybody
- The very fact that "bkuhn" is till spending time in social control media says a lot about his poor judgment
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, September 01, 2025
- IRC logs for Monday, September 01, 2025
- Microsoft Trying to Force People to Resign (Amid Mass Layoffs) a Strategy That Takes Its Toll
- Microsoft seems to be circling down the drain and the "final flush" will be the moment the "hey hi" (AI) bubble implodes completely
- Google Simply Cannot Be Trusted
- Only fools would trust GAFAM
- Admission That a Third Party (or Parties) Funds the SLAPPs Against Techrights
- This can end up costing them over a million dollars
- Modifying and Writing One's Own Computer Programs is Not a Crime (or: Google Proves That Stallman Was Right)
- We're generally gratified to see so many positive mentions of him
- Why We Stopped Publishing Videos (for Now)
- We'll probably get back to videos one day, but it's hard to say when or to what extent
- What Animal Rights Activism Teaches Us About Sympathy and Focus
- It's possible to believe that the planet is warming, that we must do something about it, and still eat eggs and butter
- When You Turn Web Sites About Tech Into Political Sites
- A lot of people fall into the trap of catering only for particular groups
- Gemini Links 02/09/2025: ROOPHLOCH 2025 and Lagrange 1.19 Released
- Links for the day
- Gemini Links 01/09/2025: News Corp. WSJ and A Month With NixOS
- Links for the day
- “Sideloading” Never Killed Anybody
- There are many online discussions this week about the misnomer "sideloading"
- Slopwatch: Google News as FUD Vector Against Linux and Plagiarism Enhancer, Serial Slopper (SS) Uses LLMs to Googlebomb "Linux"
- Slop destroys the Web not just by screwing with search engines and helping plagiarists. It's also responsible for de facto DDoS attacks...
- Links 01/09/2025: "Attacks on Science" and China's "Soft Power" Grows
- Links for the day
- Links 01/09/2025: Fresh Backlash Against Slop and "Norway’s Electricity Crisis is About to Hit Britain"
- Links for the day
- Writing and Coding Isn't Always Enough
- Last year we had to assume a role we didn't have before: litigants
- Links 01/09/2025: Catching Up (Mostly via Deutsche Welle), "Windows TCO" Effect in UK
- Links for the day
- Gemini Links 01/09/2025: Linguistic Barriers and "Web 1.0 Hosting"
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, August 31, 2025
- IRC logs for Sunday, August 31, 2025
- Autumn Has Come
- Autumn should be exciting in all sorts of ways; it'll also mark our anniversary
- The UEFI 9/11 - Part IV - External Interference
- They all seem to be playing a role in crushing Software Freedom and self-determination for users
- Links 31/08/2025: Baggage Claim Scams, an Insurrectionist’s War on Culture, and a Sudden Robotics Hype
- Links for the day
- Gemini Links 31/08/2025: Reviewing Netsurf and Slightly Less Historic Ada Design
- Links for the day
- IBM Has Taken Control of GNOME
- Don't expect a successor to be found any time soon
- Links 31/08/2025: Google Gmail Data Breach and LF Puff Pieces for Pay
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, August 30, 2025
- IRC logs for Saturday, August 30, 2025
- This is What Google News Has Become
- Moments ago
Comments
saulgoode
2010-07-01 14:10:44
Not just trust the vendor, but also those with whom they've shared the source code (subcontractors, governments, large corporate clients, etc).
It is noteworthy that there were claims that the recent attack on Google stemmed from sources within the Chinese government (with whom MS shares its source code), it is not that surprising that Google would quickly put an end to a situation where the malware authors get to see the Windows source code and they do not.
Dr. Roy Schestowitz
2010-07-01 14:17:26