EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

07.01.10

Eye on Security: Red Hat Explains Why Windows is Less Secure, New Windows 0-Day Attack

Posted in GNU/Linux, Microsoft, Red Hat, Security, Windows at 8:46 am by Dr. Roy Schestowitz

Knobsets

Summary: Comparative security news from this week

Open Source is Inherently More Secure, Says Red Hat (Microsoft admits silent patching it never discloses)

But in the closed source world, you have to trust your vendor completely. All you get to see are binaries, so you have no way of knowing how they were built. President Reagan was fond of saying to Soviet leader Mikhail Gorbachev, “Trust, but verify.” With proprietary software, you simply have to trust.

Microsoft, for example, pushes out security updates on the second Tuesday of every month. Bressers said they can’t do that. Microsoft has the advantage of hiding security flaws and working on them at their leisure, but with open source software, that’s not possible because everyone can see that there’s a problem and they expect it to be fixed right away.

And if a security hole isn’t plugged quickly enough, you can fix it yourself, Bressers explained.

An example of the power of open source is the ping of death bug. Back in the late 1990s someone figured out that if you send a giant ICMP packet to a computer, just about any computer, it will crash. The bug affected every operating system, routers, printers, etc. When the problem was discovered, the open source Linux operating system had the bug squashed in about 2 hours, Bressers recalled. The closed source operating system vendors, however, took days, weeks and even months to make and distribute a patch for the ping of death.

Microsoft: 10,000 PCs hit with new Windows XP zero-day attack

Nearly a month after a Google engineer released details of a new Windows XP flaw, criminals have dramatically ramped up online attacks that leverage the bug.

Microsoft reported Wednesday that it has now logged more than 10,000 attacks. “At first, we only saw legitimate researchers testing innocuous proof-of-concepts. Then, early on June 15th, the first real public exploits emerged,” Microsoft said in a blog posting.

New Windows Live Messenger has same old privacy problems

Why do I get the impression that some folks at Microsoft just don’t get it?

Privacy problems persist in latest Windows Messenger 2011 beta [via]

Earlier versions of Messenger played fast and loose with your privacy. The new Live Messenger 2011, currently in beta, suffers from some of the same defects

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

2 Comments

  1. saulgoode said,

    July 1, 2010 at 9:10 am

    Gravatar

    But in the closed source world, you have to trust your vendor completely. All you get to see are binaries, so you have no way of knowing how they were built.

    Not just trust the vendor, but also those with whom they’ve shared the source code (subcontractors, governments, large corporate clients, etc).

    It is noteworthy that there were claims that the recent attack on Google stemmed from sources within the Chinese government (with whom MS shares its source code), it is not that surprising that Google would quickly put an end to a situation where the malware authors get to see the Windows source code and they do not.

    Dr. Roy Schestowitz Reply:

    Let’s remember that one Chinese company that Microsoft let write its code was unethical enough (even criminal) to rip someone else’s work and rebrand it as Microsoft’s [1, 2, 3, 4].

What Else is New


  1. Links 30/3/2020: GNU Linux-libre 5.6, WireGuard 1.0.0

    Links for the day



  2. IRC Proceedings: Sunday, March 29, 2020

    IRC logs for Sunday, March 29, 2020



  3. Links 30/3/2020: Linux 5.6, Nitrux 1.2.7, Sparky 2020.03.1

    Links for the day



  4. The Fall of the UPC - Part IX: Campinos Opens His Mouth One Week Later (and It's That Hilarious Delusion Again)

    Team Campinos said nothing whatsoever about the decision of the FCC until one week later, whereupon Campinos leveraged some words from Christine Lambrecht to mislead everybody in the EPO's official "news" section



  5. Pretending EPO Corruption Stopped Under António Campinos When It is in Fact a Lot Worse in Several Respects/Aspects (Than It Was Under Benoît Battistelli)

    Germany's eagerness to keep Europe's central patent office in Munich (and to a lesser degree in Berlin) means that politicians in the capital and in Bavaria turn a blind eye to abuses, corruption and even serious crimes; this won't help Germany's image in the long run



  6. IRC Proceedings: Saturday, March 28, 2020

    IRC logs for Saturday, March 28, 2020



  7. Links 28/3/2020: Wine 5.5 Released, EasyPup 2.2.14, WordPress 5.4 RC5 and End of Truthdig

    Links for the day



  8. IRC Proceedings: Friday, March 27, 2020

    IRC logs for Friday, March 27, 2020



  9. The Fall of the UPC - Part VIII: Team UPC Celebrates Death, Not Life

    Team UPC plays psychological games now; it is trying to twist or spin its defeat as good news and something to be almost celebrated; it is really as illogical (and pathetic) as that sounds



  10. Links 27/3/2020: GNU/Linux Versus COVID-19 and Release of GNU Guile 3.0.2

    Links for the day



  11. When Your 'Business' is Just 'Patent Portfolio'

    Hoarding loads of patents may seem impressive, but eating them to survive is impossible if not impermissible



  12. LOT Network is a One-Man (Millionaire's) Operation and Why This Should Alarm You

    The ugly story of Open Invention Network (OIN) and LOT; today we take a closer look at LOT and highlight a pattern of 'cross-pollination' (people in both OIN and LOT, even at the same time)



  13. Faking Production With Fake Patents on Software

    The EPO with its illegal guidelines (in violation of the EPC) can carry on churning out millions of fake patents that European courts would only waste time on and small companies be blackmailed with (they cannot afford legal battles)



  14. With the Unified Patent Court (UPC) Out of the Way Focus Will Return to EPO Corruption

    Expect the European Patent Office (EPO) to receive more negative attention now that the ’cause’ of UPC is lost and there’s no point pretending things are rosy



  15. IRC Proceedings: Thursday, March 26, 2020

    IRC logs for Thursday, March 26, 2020



  16. Links 27/3/2020: qBittorrent 4.2.2, Krita 4.2.9, pfSense 2.4, Bodhi Linux 5

    Links for the day



  17. IRC Proceedings: Wednesday, March 25, 2020

    IRC logs for Wednesday, March 25, 2020



  18. Still Work in Progress: Getting Those 2,851 Pages of Police Report About Arrest for Pedophilia in Home of Bill Gates

    It’s extremely difficult to get those police records, which were requested exactly one day before the media started attacking Richard Stallman (associating him with pedophiles based on a deliberate distortion)



  19. Links 26/3/2020: Plasma Bigscreen, New Kubernetes, Fedora's New Identity and Bodhi Linux 5.1.0

    Links for the day



  20. Guest Article: Window Managers, Github and Software Disobedience

    "Walking away from monopolies is the essence of freedom"



  21. Links 25/3/2020: LLVM 10.0.0 and UCS 4.4-4 Released, WordPress 5.4 RC4

    Links for the day



  22. 'Team UPC' Last Week

    The looks on Team UPC's faces 5 days ago (before and after the 9:30AM announcement)



  23. The Fall of the UPC - Part VII: Lies and Revisionism About the Reasons for the UPC's Ultimate Demise (to Leave the Door Open for More Failed Attempts)

    The media was lying in a hurry, in a coordinated effort to distort the meaning of the FCC's decision or belittle the impact of this decision; Techrights will carefully watch and respond to these lies



  24. IRC Proceedings: Tuesday, March 24, 2020

    IRC logs for Tuesday, March 24, 2020



  25. Linux Foundation Became Anti-Linux, Run by Microsoft People to Serve Microsoft's Agenda

    Microsoft is taking over the bodies of healthy projects, infecting the hosts in order for them to become slaves of the proprietary parasite; there's still no (known) cure, but we're familiar with the symptoms



  26. Microsoft Continues to Attack and Steal From the Open Source/Free Software Communities

    Microsoft cannot be trusted and there's no "new Microsoft," as another fairly new story serves to show



  27. Targeted Attack Leveraging FSF Servers

    Targeted by a determined and persist perpetrator, I've received over 20,000 E-mails. And the weapon of choice was the FSF's infrastructure, remotely misused against yours truly.



  28. If We Weren't Silencing Founders, Critics and People We Just Don't Like

    "In the long run, history is rarely very kind to tyrants, especially the ones who did little more than lie to people and demand things that served no real purpose."



  29. The Fall of the UPC - Part VI: Drowning in Material

    We're starting to see few good reports on the subject of UPC being rejected by the constitutional court of Germany; we also have a rapidly-growing 'buffer' of rather blatant examples of disinformation (which we'll tackle as best we can)



  30. FFII: EU Software Patent Court Stopped by Constitutional Court, Patent Industry Will Try Again

    The third attempt to validate software patents in Europe via a central patent court (UPC) has been stopped by the German Constitutional Court. The Unified Patent Court (UPC) would have given the keys of the kingdoms to the patent industry, and the last word over software patentability. FFII predict that the patent industry will continue to push for an UPC v2.0.


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts