EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

09.26.13

Former Novell Staff Still Pushing the Linux Foundation Into Restricted Boot Territory, Ignoring the Real Threat (Back Doors)

Posted in GNU/Linux, Kernel, Novell, Security at 3:54 am by Dr. Roy Schestowitz

Greg Kroah-Hartman
Photo by Sebastian Oliva

Summary: Back doors in code, embedded in blobs, and even shoehorned into encryption is the overlooked security threat, which gets pushed aside in favour of phantom threats which Microsoft ‘sells’ through former Novell staff (i.e. funded by Microsoft)

A MONTH or two ago we mostly ignored exaggerated (sexed-up) reports about something called “Hand of Thief”. When there’s a Windows security threat the press does not call out Windows, but when it relates to GNU/Linux then tabloids like ZDNet scream from the rooftops. This thing called “Hand of Thief” is basically a malicious program which GNU/Linux users need to install themselves in order for it to do malicious things. It is not a virus, it does not spread, and it hardly even uses social engineering to get itself installed. We cited some reports which stress these facts and now comes a belated one too [1]. LynuxWorks is now offering some “Linux rootkit detector” [2] as if rootkits on GNU/Linux are a common issue. In a sense, since the Linux Foundation seems to insist on helping UEFI restricted boot, we are led to the belief that bootkits are a common threat to Linux. As the Linux Foundation’s site put it, as in the words of the employee it acquired from Novell:

Now that The Linux Foundation is a member of the UEFI.org group, I’ve been working on the procedures for how to boot a self-signed Linux kernel on a platform so that you do not have to rely on any external signing authority.

Greg K-H has been working on all sorts of other kernel-level projects that help Microsoft. He did this while being paid by Novell, which was in turn being given money by Microsoft. That’s the power of money. Other former Novell employees also helped promote UEFI restricted boot, as we showed before. Rogue influence by Novell in the Linux Foundation is a subject we have written about for half a decade, showing numerous examples.

The bigger security issue right now might be back doors, which might also exist in Linux, even in encryption form [3] (giving away passwords over the network for example), so hard-to-crack passwords [4] might not be enough. Microsoft’s and Sony’s network compromises sure reveal the massive financial effects of system intrusions, so this subject should not be taken lightly.

UEFI restricted boot is actually a security threat, not a security solution, especially when a signature is provided and managed by some rogue company in the United States — one which has been secretly in bed with the NSA. With UEFI restricted boot, hardware can be bricked remotely. In a way, UEFI restricted boot deserves the name “unsecure boot”. In some devices it can block the user from accessing his/her own computer. Nobody should promote such treacherous computing.

Related/contextual items from the news:

  1. Hand of Thief, Not

    Linux’s biggest vulnerability is the software that users install with full “superuser” privileges. If you just install applications from your distro’s official repository, that’s not a problem. But if you download software from dubious web sites, or if you add a mysterious repository to your package manager, you’re opening yourself up for an infection. Always, always make sure you know what software you are installing, why you are installing it, and where it’s from.

  2. Linux rootkit detector adds hardware punch to security scanning

    LynuxWorks is stepping up the battle with the release of the first hardware-based rootkit detection system powered by the LynxSecure separation kernel. Called the RDS5201, it combats and detects stealthy advanced persistent threats. Built on the LynxSecure 5.2 separation kernel and hypervisor, this small form factor appliance has been designed to offer a unique detection capability that complements traditional security mechanisms as they try to protect against the growing number and complexity of cyber threats.

  3. RSA warns developers not to use RSA products

    In today’s news of the weird, RSA (a division of EMC) has recommended that developers desist from using the (allegedly) ‘backdoored’ Dual_EC_DRBG random number generator — which happens to be the default in RSA’s BSafe cryptographic toolkit. Youch.

  4. How-to make hard-to-crack passwords you can easily remember
  5. Australian who boasted of hacking to plead not guilty to charges stemming from raid

    Dylan Wheeler, who claimed in February to have breached Microsoft’s and Sony’s networks, has not been charged with hacking

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 24/2/2017: Ubuntu 17.04 Beta, OpenBSD Foundation Nets $573,000 in Donations

    Links for the day



  2. IAM, Greased up by the EPO, Continues Lobbying by Shaming Tactics for the UPC, Under the Guise of 'News'

    The shrill and well-paid writers of IAM are still at it, promoting the Unitary Patent (UPC) at every opportunity and every turn



  3. Patent Scope Gone Awry: European Vegetable Patents Office?

    In its misguided race to raise so-called 'production', the EPO lost sight of its original goals and now facilitates patent royalty payments/taxation for naturally-recurring items of nature



  4. Yes, There is Definitely Brain Drain (Experience Deficit) at the European Patent Office and Stakeholders Feel It

    The direction that the European Patent Office has taken under Battistelli undoes many decades (almost half a century) of reputation-building and progress and naturally this repels existing staff, not to mention hampers recruitment efforts



  5. The Sickness of the EPO – Part IV: Cruel Management That Deliberately Attacks the Sick and the Weak

    The dysphoric reality at the European Patent Office, which is becoming like a large cell (with bolted-down windows) where people are controlled by fear and scapegoats are selected to perpetuate this atmosphere of terror and maintain demand (or workload) for the Investigative Stasi



  6. Links 23/2/2017: Qt 5.9 Alpha, First SHA1 Collision

    Links for the day



  7. UPC Roundup: War on the Appeal Boards, British Motion Against the UPC, Fröhlinger Recalled, and Fake News About Spain

    Taking stock of some of the latest attempts to shove the Unitary Patent (UPC) down Europe's throat, courtesy of Team Battistelli and Team UPC



  8. The Sickness of the EPO – Part III: Invalidity and Suicides

    An explanation of what drives a lot of EPO veterans to depression and sometimes even suicide



  9. The Appeal Board (PTAB) and Federal Circuit (CAFC) Maintain Good Pace of Patent Elimination Where Scope Was Exceeded

    The Court of Appeals for the Federal Circuit (CAFC) continues to accept about 4 out of 5 decisions of the Patent Trial and Appeal Board (PTAB) and the US Supreme Court (SCOTUS) refuses to intervene



  10. Software Patents Are Ebbing Away, But the “Swamp” Fights Back and Hijacks the Word “Fix”

    The club of patent maximalists, or those who profit from excess prosecution and legal chaos, isn't liking what has happened in the United States and it wants everything reversed



  11. Report From Yesterday's Debate About the European Patent Office (EPO) at the Bavarian Landtag

    A report of the EPO debate which took place at the Bavarian Landtag yesterday (21/2/2017)



  12. Links 22/2/2017: Wine-Staging 2.2, Nautilus 3.24

    Links for the day



  13. French Politician Richard Yung Tells the Government About Abuses at the European Patent Office (EPO)

    The subject of EPO scandals has once again landed in French politics, just a couple of months since it last happened



  14. The Sickness of the EPO – Part II: Background Information and Insights

    With a privatised, in-house (sometimes outsourced and for-profit) force for surveillance, policing, justice, public relations and now medical assessment (mere vassals or marionettes of the management) the EPO serves to show that it has become indistinguishable from North Korea, where the Supreme Leader gets to control every single aspect (absolutely no separation of powers)



  15. EPO Cartoon/Caricature by KrewinkelKrijst

    A new rendition by Dutch cartoonist and illustrator KrewinkelKrijst



  16. Inverting Narratives: IAM 'Magazine' Paints Massive Patent Bully Microsoft (Preying on the Weak) as a Defender of the Powerless

    Selective coverage and deliberate misinterpretation of Microsoft's tactics (patent settlement under threat, disguised as "pre-installation of some of the US company’s software products") as seen in IAM almost every week these days



  17. The Sickness of the EPO – Part I: Motivation for New Series of Articles

    An introduction or prelude to a long series of upcoming posts, whose purpose is to show governance by coercion, pressure, retribution and tribalism rather than professional relationship between human beings at the European Patent Office (EPO)



  18. Insensitivity at the EPO’s Management – Part VII: EPO Hypocrisy on Cancer and Lack of Feedback to and From ECPC

    The European Cancer Patient Coalition (ECPC), which calls itself "the largest European cancer patients' umbrella organisation," fails to fulfill its duties, says a source of ours, and the EPO makes things even worse



  19. Links 21/2/2017: KDE Plasma 5.9.2 in Chakra GNU/Linux, pfSense 2.3.3

    Links for the day



  20. EPO Caricature: Battistelli's Wall

    Battistelli's solution to everything at the EPO is exclusion and barriers



  21. The 'New' Microsoft is Still Acting Like a Dangerous Cult in an Effort to Hijack and/or Undermine All Free/Open Source Software

    In an effort to combat any large deployment of non-Microsoft software, the company goes personal and attempts to overthrow even management that is not receptive to Microsoft's agenda



  22. PTAB Petitioned to Help Against Patent Troll InfoGation Corp., Which Goes After Linux/Android OEMs in China

    A new example of software patents against Free software, or trolls against companies that are distributing freedom-respecting software from a country where these patents are not even potent (they don't exist there)



  23. Links 20/2/2017: Linux 4.10, LineageOS Milestone

    Links for the day



  24. No, Doing Mathematical Operations on a Processor Does Not Make Algorithms Patent-Eligible

    Old and familiar tricks -- a method for tricking examiners into the idea that algorithms are actual machines -- are being peddled by Watchtroll again



  25. Paid-for UPC Proponent, IAM 'Magazine', Debunked on UPC Again

    The impact of the corrupted (by EPO money) media goes further than one might expect and even 'borrows' out-of-date news in order to promote the UPC



  26. Lack of Justice in and Around the EPO Drawing Scrutiny

    The status of the EPO as an entity above the law (in Germany, the Netherlands, Switzerland and so on) is becoming the subject of press reports and staff is leaving in large numbers



  27. Links 19/2/2017: GParted 0.28.1, LibreOffice Donations Record

    Links for the day



  28. The EPO is Becoming an Embarrassment to Europe and a Growing Threat to the European Union

    The increasingly pathetic moves by Battistelli and the ever-declining image/status of the EPO (only 0% of polled stakeholders approve Battistelli's management) is causing damage to the reputation of the European Union, even if the EPO is not a European Union organ but an international one



  29. Patent Misconceptions Promoted by the Patent Meta-Industry

    Cherry-picking one's way into the perception of patent eligibility for software and the misguided belief that without patents there will be no innovation



  30. As the United States Shuts Its Door on Low-Quality Patents the Patent Trolls Move to Asia

    Disintegration of Intellectual Ventures (further shrinkage after losing software patents at CAFC), China's massive patent bubble, and Singapore's implicit invitation/facilitation of patent trolls (bubble economy)


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts