EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

07.01.10

Eye on Security: Red Hat Explains Why Windows is Less Secure, New Windows 0-Day Attack

Posted in GNU/Linux, Microsoft, Red Hat, Security, Windows at 8:46 am by Dr. Roy Schestowitz

Knobsets

Summary: Comparative security news from this week

Open Source is Inherently More Secure, Says Red Hat (Microsoft admits silent patching it never discloses)

But in the closed source world, you have to trust your vendor completely. All you get to see are binaries, so you have no way of knowing how they were built. President Reagan was fond of saying to Soviet leader Mikhail Gorbachev, “Trust, but verify.” With proprietary software, you simply have to trust.

Microsoft, for example, pushes out security updates on the second Tuesday of every month. Bressers said they can’t do that. Microsoft has the advantage of hiding security flaws and working on them at their leisure, but with open source software, that’s not possible because everyone can see that there’s a problem and they expect it to be fixed right away.

And if a security hole isn’t plugged quickly enough, you can fix it yourself, Bressers explained.

An example of the power of open source is the ping of death bug. Back in the late 1990s someone figured out that if you send a giant ICMP packet to a computer, just about any computer, it will crash. The bug affected every operating system, routers, printers, etc. When the problem was discovered, the open source Linux operating system had the bug squashed in about 2 hours, Bressers recalled. The closed source operating system vendors, however, took days, weeks and even months to make and distribute a patch for the ping of death.

Microsoft: 10,000 PCs hit with new Windows XP zero-day attack

Nearly a month after a Google engineer released details of a new Windows XP flaw, criminals have dramatically ramped up online attacks that leverage the bug.

Microsoft reported Wednesday that it has now logged more than 10,000 attacks. “At first, we only saw legitimate researchers testing innocuous proof-of-concepts. Then, early on June 15th, the first real public exploits emerged,” Microsoft said in a blog posting.

New Windows Live Messenger has same old privacy problems

Why do I get the impression that some folks at Microsoft just don’t get it?

Privacy problems persist in latest Windows Messenger 2011 beta [via]

Earlier versions of Messenger played fast and loose with your privacy. The new Live Messenger 2011, currently in beta, suffers from some of the same defects

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

2 Comments

  1. saulgoode said,

    July 1, 2010 at 9:10 am

    Gravatar

    But in the closed source world, you have to trust your vendor completely. All you get to see are binaries, so you have no way of knowing how they were built.

    Not just trust the vendor, but also those with whom they’ve shared the source code (subcontractors, governments, large corporate clients, etc).

    It is noteworthy that there were claims that the recent attack on Google stemmed from sources within the Chinese government (with whom MS shares its source code), it is not that surprising that Google would quickly put an end to a situation where the malware authors get to see the Windows source code and they do not.

    Dr. Roy Schestowitz Reply:

    Let’s remember that one Chinese company that Microsoft let write its code was unethical enough (even criminal) to rip someone else’s work and rebrand it as Microsoft’s [1, 2, 3, 4].

What Else is New


  1. Video: LinuxWorld 1999, Torvalds and Stallman

    LinuxWorld 1999, Torvalds and Stallman



  2. GNU World Order is a Personal Sacrifice, LinuxWorld Just Business

    As the Linux Foundation shows, Linux is just business (and proprietary software) as usual, software patents included, whereas it’s GNU that continues the Free Software Movement’s battles



  3. Links 20/2/2020: Oracle Solaris 11.4 SRU18, Mesa 20, VirtualBox 6.1.4

    Links for the day



  4. Open Source Did Not Win, It Was Assimilated to and by Proprietary Software

    Don’t fall for the whole “Open Source has won!” spiel; You know we’ve lost the battle (and were in effect gradually conquered) at OSI and elsewhere when those who speak for the OSI are Michael Cheng (Facebook), Max Sills (Google), and Chris Aniszczyk (Linux Foundation); they say “Open Source Under Attack” (FOSDEM talk) but their employers are the ones attacking and they downplay openwashing



  5. Former Microsoft Employees Don't Like Talking About Past and Present Microsoft Back Doors (Designed for Spy Agencies)

    In a typical Microsoftian fashion, once they cannot defend the illusion/delusion that Microsoft values security the 'Softers' run away and block any further debate



  6. Techrights Warns Against Impending Extradition Efforts (Passage of Julian Assange to His Death in the United States)

    Imprisonment of journalists who are effective at exposing crimes (of the powerful, not petty crimes) must never be condoned



  7. Team UPC: Many Mouths and No Ears

    The mental condition of Team UPC gets more worrisome by the week



  8. Team UPC Insults Judges Because the UPC is Dead and UPC Lobbyists Have Nothing Left to Lose

    More judge-shaming tactics are in the mix; Team UPC seems to feel like there's nothing left to lose as the UPC is already dead (hope itself is next to die)



  9. IRC Proceedings: Wednesday, February 19, 2020

    IRC logs for Wednesday, February 19, 2020



  10. China Bashing is Grounded in Fear (That They Can Simply Do Better Than the West)

    The atmosphere of hate towards China — fuelled partly by a white supremacist in the White House — is unhelpful and insulting; dignity and understanding is the way to go



  11. IRC Proceedings: Tuesday, February 18, 2020

    IRC logs for Tuesday, February 18, 2020



  12. FFII Press Release: Germany Can No Longer Ratify the Unitary Patent Due to Brexit and the Established AETR Case-law, says FFII

    Germany cannot ratify the current Unitary Patent due to Brexit and the established AETR case-law. The ratification of the UPC (Unified Patent Court) by Germany would constitute a violation of the AETR case-law, which was used during the EPLA negotiations in 2006 to consider a deal with non-EU countries, such as Switzerland.



  13. DRM (Proprietary Software) Already Makes Mozilla Firefox Broken, Unreliable, Undependable (Dependent on Binary Blobs)

    More people are beginning to realise that Mozilla resorted to self-harming DRM and self-inflicted damage that impacts Firefox; can Mozilla (re)join the anti-DRM coalitions?



  14. EPO and Other Patent Updates Over RSS

    Site syndication (over RSS feeds or XML/Atom) is vastly better than what became popular in recent years (censored, centralised, discriminatory "Social Control Media"); here are some feeds of interest



  15. When It Comes to a Unitary Patent System, Bad (or Intentionally Dishonest) Legal Advice Has Become the Norm

    The Unified Patent Court and Unitary Patent (UPC and UP, respectively) reinforce the old saying about lawyers being liars, doing anything to attract clients (to take their money); the UPC is basically dead, but fiction, falsehoods and outrageous fantasies still find their way into Web sites of law firms



  16. Links 19/2/2020: KDE Plasma 5.18.1, GNOME 3.36 Beta 2 and WordPress 5.4 Beta 2

    Links for the day



  17. Is Linux Foundation a Microsoft Branch Now?

    The so-called ‘Linux’ Foundation (LF) nowadays helps Microsoft cement its monopoly — the very opposite of what ages ago it said the LF would do



  18. Are Songs Property? And Maths Also Property? Artificial Monopolies Are Not Property...

    Patent maximalists continue to face stronger arguments from their sceptics, who rightly allege that words are being intentionally misused and numbers fabricated so as to distort underlying facts



  19. Battistelli Blocked Techrights at EPO (Banned for More Than 5 Years), So CEIPI Won't Respect Access to Information Either

    The use of censorship to confront people who talk about (not even expose) corruption isn't novel; but the adoption of this approach in Europe (not just places like Russia and China) is definitely noteworthy



  20. IRC Proceedings: Monday, February 17, 2020

    IRC logs for Monday, February 17, 2020



  21. Links 18/2/2020: Linux 5.6 RC2, Wine 5.2, GNU Social Contract and Sparky 2020.02 Special Editions

    Links for the day



  22. IRC Proceedings: Sunday, February 16, 2020

    IRC logs for Sunday, February 16, 2020



  23. Links 16/2/2020: MX Linux 19.1 and MyPaint 2.0

    Links for the day



  24. IRC Proceedings: Saturday, February 15, 2020

    IRC logs for Saturday, February 15, 2020



  25. Guest Article: Au Revoir, GNU/Linux

    "Funny how OSI just ended up being another vehicle for their takeover of the computing world..."



  26. Former Microsoft Employee: ZDNet is Owned by Microsoft (and Others) in Some Senses

    A noteworthy message we've received from someone who knows Microsoft from the inside



  27. Links 15/2/2020: Blender 2.82, Qt 5.15 Alpha and NetBSD 9.0 Released

    Links for the day



  28. Microsoft Views 'Open Source' as a Zero-Cost Heist Opportunity (Making Proprietary Software/Spyware Using Other People's Free Labour)

    Making GPL-licensed (copyleft) software and hosting it outside Microsoft’s jaws is the best way to counter the abusive monopolist, which still says it “loves” what it is actually attacking



  29. Did Microsoft 'Buy' ZDNet?

    A look at what ZDNet tells its readers (screenshot from this morning) and a rare look at how its writers are censored/suppressed



  30. Anatomy of a Crime and Protection From Prosecution

    It’s hard to forget what António Campinos hides for his friend


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts