EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

04.02.11

Red Hat’s Obfuscated Patches Harm Small GNU/Linux Players and Help Microsoft/Novell

Posted in Oracle, Red Hat at 6:22 pm by Dr. Roy Schestowitz

James WhitehurstSummary: Suggestions to Red Hat, whose commitment to transparency has eroded somewhat and needs prodding for

TECHRIGHTS runs on top of CentOS, which relies on Red Hat for its updates. Earlier this week at work I was told that CentOS had not released patches since December, whereas RHEL patches are released at a pace of several per week. This may make one wonder about the new Scientific Linux, which might one day outpace CentOS and replace it as the de facto RHEL clone.

“Red Hat can improve its bottom line by sticking a cork in CentOS and preventing access to RHEL-targeted patches.”Red Hat defends its dubiously obfuscated patches by pointing the finger at Oracle, but let’s face it; it is often said that the most widely used distribution of GNU/Linux is the quiet giant, CentOS. Many Web hosts run it and they are not alone, sector-wise. Nobody knows just how many servers run CentOS, but it’s probably many millions. Red Hat can improve its bottom line by sticking a cork in CentOS and preventing access to RHEL-targeted patches. Oracle would be a convenient Goliath to blame, but is it really as dangerous as Red Hat wants us to believe while Red Hat’s financial numbers keep hitting new record highs? The subject of transparency at Red Hat was addressed here quite recently and Techrights will continue to pressure Red Hat to rectify these issues, both by explaining the Acacia settlement [1, 2, 3] and by providing GPL-friendly patches to those who require them. The GPL is designed to avoid exclusion, even if that means allowing Oracle to embrace other people’s work.

As we pointed out this morning, Novell is trying to take advantage of Red Hat’s practices, hoping to sell Microsoft-taxed SLE* at the expense of/instead of RHEL (there is also a peripheral article about it now). Who would that benefit?

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

5 Comments

  1. David Gerard said,

    April 2, 2011 at 6:34 pm

    Gravatar

    Well, now. This is anecdotal, but … I work for a company that has various web-based applications. These are written in Java. (Yes, we saw the Oracle-Google suit and several people had a good hard think about their career path.) They were running on Solaris, but Oracle is insane and on crack, so I strongly advised my boss and boss’s boss to ignore all our years of Solaris experience and move to Linux post-haste.

    We’re going to VM-based hosting. Oracle want £300 to run Solaris on non-Oracle hardware for a year. So we’re going Linux.

    The hosting company offered RHEL or … Ubuntu server. We went Ubuntu ‘cos we like Debian and it’s close enough for our purposes. (IT’S JUST RUNNING JAVA.)

    Supporting all the hardware ever is a big plus for RHEL … but not so much if people are hosting in VMs. And you know, Ubuntu is free as in beer too. (And you don’t have to put up with the hideous Unity interface on a server.)

    Dr. Roy Schestowitz Reply:

    Well, Ubuntu servers that I deploy are X-less. It should not be a problem. Debian is a safe bet, too.

    BenderBendingRodriguez Reply:

    Roy, do you realize that debian is at it’s default the least safe Linux distro out there?

    http://labs.mwrinfosecurity.com/notices/security_mechanisms_in_linux_environment__part_1___userspace_memory_protection/

    http://labs.mwrinfosecurity.com/notices/assessing_the_tux_strength_part_2_into_the_kernel/

    Granted it has been written on september but i really doubt that debian changed security wise

    twitter Reply:

    Calling Debian the “least safe Linux distro” is sort of like calling flint the most toxic of metamorphic rocks and glasses. I’m particularly wary of articles that complain that free software does not have tools that non free software inevitably needs to make up for mono cultural flaws and code staleness. Olympic athletes can use crutches too but generally don’t rate themselves on their ability to use them. Until we see successful attacks in the wild, most of these security articles are an academic exercise at best and FUD at worst.

    There’s a lot to recommend Debian. Complexity is itself a flaw that leads to exploitation and Debian sensibly avoids this unless forced. Debian also is one of the most package rich and platform diverse distributions, diversity that is both useful and protective. When and if there’s a problem, the Debian community can and will deploy these alternate tools.

    Dr. Roy Schestowitz Reply:

    If one depends on Debian’s well-tested patches, then there might be a delay between ‘real’ patch and Debian patch. But otherwise, people can always patch using whatever comes from the original source. I had this discussion in London some days ago. Calling Debian “the least safe Linux distro” is odd to me too.

What Else is New


  1. Links 23/5/2012: printerd, Mageia 2 Released

    Links for the day



  2. Links 22/5/2012: Google/Motorola Deal Secured, Chrome Passes IE

    Links for the day



  3. Links - Explorer Goes Down, Oracle Judge is Coder





  4. Links 21/5/2012: Linux 3.4 Released, Dream Studio 12.04

    Links for the day



  5. Articles Against Software Patents and Patent Trolls

    An accumulation of recent articles on matters such as patent trolls, which mostly use software patents based on a recent survey



  6. New Zealand (NZ) Patent Debates Expand

    The kiwi (NZ) press turns its attention to a patent controversy other than the question of software patenting



  7. AOL Helps Microsoft Infiltrate, Harm Open Source Communities, Feeds Facebook With Google-Hostile Patents

    Microsoft is preying on AOL funds and patents



  8. 'Piracy' and 'Discount' Propaganda Used to Kick Free Software Out of Governments in Favour of Microsoft Deals

    A look at new tactics and moves which omit freedom and autonomy from nations foreign to Microsoft



  9. Sun: Interoperability More Important Than Patents

    An old position paper from Sun Microsystems helps shows a certain resistance to patents such as those which Oracle uses against Android



  10. In Motorola Case, Microsoft Boosters Use Slashdot for Anti-Linux/Android Patent Propaganda

    Covering what's right/correct -- not what's wrong/incorrect -- about the Microsoft case against Motorola/Android



  11. Microsoft Tax on Everything

    The company which hardly pays any tax is busy trying to tax GNU/Linux, Android, and all hardware in the OEM channel



  12. Links 19/5/2012: Mandriva Linux Freed, New Linux Mint RC

    Links for the day



  13. Apple Patent Wars Make Android Devices Less Attractive, Everyone Suffers

    Bits of patent news regarding Apple and its patents



  14. Defeat for Software Patents in the United Kingdom

    Wise words from a prominent Linux figure and news from the UK



  15. BSA and IDC Systematically Lie to the Public, Distort Press Coverage

    IDC and the Business Software Alliance (BSA) liaise once again in order to give ammunition to lobbyists of proprietary and copyright conglomerates



  16. Links 17/5/2012: “Bio Computer” Runs Linux, Raspberry Pi Grows

    Links for the day



  17. IRC Proceedings: May 11th-May 16th, 2012

    IRC logs for May 11th, 2012 (and subsequent days until May 16th)



  18. IRC Proceedings: May 5th-May 10th, 2012

    IRC logs for May 5th, 2012 (and subsequent days until May 10th)



  19. IRC Proceedings: April 29th-May 4th, 2012

    IRC logs for April 29th, 2012 (and subsequent days until May 4th)



  20. Android Under Patent Attacks From Nokia, Microsoft, and Oracle

    A roundup of patent news involving Android and the US patent/copyright system, which facilitates ridiculous patents or lawsuits over APIs



  21. Helping OpenSUSE is Helping Microsoft Tax GNU/Linux

    A short wave of calls to refrain from OpenSUSE promotion, which through the upstream is helping Microsoft, the sponsor



  22. Microsoft May Face Federal Action for Blocking Rival Web Browsers on ARM

    Mozilla's call for action is taken seriously by people at The Hill (Washington)



  23. Links 16/5/2012: 125,000 GNU/Linux Machines for Pakistani Students, Android 4.0 Rollouts

    Links for the day



  24. Links 15/5/2012: Linux 3.4 is Near, Mandriva to Have More Releases

    Links for the day



  25. Links - TPP Meeting Infiltrated, More Protest Needed.





  26. Europe Rules Against Monopolies on APIs

    The case against Android notwithstanding, the highest European court rules that APIs cannot be covered by copyrights



  27. Microsoft Versus Education

    A bit of news/commentary on Microsoft in education (indoctrination)



  28. Patents Are Never 'Open Source'

    The disinformation tactic which ascribes patents to FOSS as seen in the news



  29. Signs of Progress: Work for Microsoft, Get Ostracised From Panels/Public Consultations

    Convinced monopolist Microsoft has its moles' voice invalidated, based on the conflict of interest (Microsoft versus the public)



  30. Links 14/5/2012: Linux Kernel 3.3.5, Wine 1.5.4

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts