EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

11.24.13

Trusting Trust and Trusting Red Hat et al.

Posted in Microsoft, Red Hat, Servers at 5:27 am by Dr. Roy Schestowitz

Even Red Hat’s logo does not inspire confidence

Red Hat logo

Summary: Why companies which are based on the United States cannot be trusted as US law requires them to provide access to personal information (or even back doors) without ever disclosing this

Red Hat Enterprise Linux 6.5 has just come out [1,2,3]. Red Hat targets the so-called 'cloud' (surveillance-friendly) market with it, quite frankly as usual [4]. Cutting-edge RHEL prototypes like Fedora 20 are to be released soon, and Scientific Linux (not just CentOS) will need to catch up by rebranding RHEL (they are being compared in terms of performance in [5]). Some people are remixing [6] Red Hat’s distributions, not rebranding them. But few people actually audit RHEL code line by line. Disassembling RHEL binaries is an even greater challenge, so nobody knows for sure what RHEL does. It’s a vast body of software and it is deployed in many mission-critical operations, not just in the United States.

“Trusting Trust” is an old concept, coined by some of the earlier UNIX folks. This subject happened to have been raised during business lunch earlier this week and it speaks on the degree of trust we must place on compiler developers, chipmakers, high-level software companies, and even Free software developers whose code we never personally audited (or continue to audit every time a new release is made available). Verifying the security of a small piece of software like a CMS (as Germany currently does) is feasible, but for entire operating systems it is virtually impossible and then there’s the peril of checking chip designs, their fabrication process, and the same for software (compilers). IBM et al., those who infect computers with TPM (NSA connections) only lead to mistrust. We are talking about a “special surveillance chip” here. And yes, there is history to it. Slashdot published this bit of analysis a few months ago. Read the comments too. One says: “I work for Red Hat…. The NSA asks me to put code in the Linux kernel and I pass it to Linus.” (see the context for more interesting information of this kind).

There is currently a discussion in Diaspora about this. It is argued that Red Hat will need to appease the government — especially the Pentagon/DOD — in order to keep winning major contracts that are derived from black budgets sometimes. There are stories I am aware of (but cannot share) about the role spies play in procurement for government. They can veto and influence decisions. This is a very ugly side of procurement which many people are simply not aware of. It only makes sense for Red Hat to try to appease the NSA and perhaps attach code from the NSA, with or without sufficient scrutiny (it goes well beyond involvement in SELinux, which is not the NSA’s only role in Linux). Well, some in Twitter wanted more information about this, so I reminded them that several years ago I wrote about how RHEL goes through the NSA before release; the same is true for SUSE. Now we know for sure that Linux was the target of NSA back doors [1, 2, 3, 4]; more new reporting on this [7-10] is starting to appear (people are catching up) and a new report tells us that “NSA infected 50,000 computer networks with malicious software” [11].

“he law in the US has become somewhat incompatible with freedom-respecting software.”We already know that the NSA worked closely with Microsoft and got a widely-used platform (internationally) with back doors it has exclusive access to, which basically means that Microsoft Windows is a Trojan horse for the NSA. Just remember where Linux is being developed. It’s the same country as Microsoft and Apple. Projects like Debian inherit some code from Red Hat, which complicates things further. The chain of trust is undone.

After the new report from the New York Times [12,13] (published to make huge impact this weekend) perhaps it’s time for Torvalds to withdraw his newly-acquired US citizenship and move back Linux development to Finland. With all sorts of National Security Letters, gag orders, oppressive laws like PATRIOT Act etc. we just know that those based in the US can be forced to facilitate surveillance (without ever speaking about it publicly). This may sound like a radical solution, but when companies like Red Hat and the Linux Foundation need to comply with US laws we just simply cannot have any trust. Torvalds pretty much lied to us (in a clever way) about NSA request for back doors in Linux, but his father, who is a European politician based in Europe, told us the truth.

In the past we argued that Red Hat should move to Europe because of software patents (I asked Red Hat’s CEO about it and he dismissed the possibility). Now we have another reason to suggest relocation. The law in the US has become somewhat incompatible with freedom-respecting software.

Related/contextual items from the news:

  1. Red Hat Enterprise Linux 6.5 Delivers Precision Timing
  2. Red Hat Launches Latest Version of Red Hat Enterprise Linux 6
  3. Red Hat Enterprise Linux 6.5 arrives
  4. Red Hat and eNovance to accelerate adoption of Red Hat Enterprise Linux OpenStack platform

    Red Hat Inc. and eNovance, an emerging European leader in the open source cloud computing market, are collaborating to deliver OpenStack implementation and integration services to joint customers. The companies made the announcement at the OpenStack Summit in Hong Kong.

    The collaboration between Red Hat and eNovance is aimed at accelerating enterprise adoption of OpenStack globally. According to a new report from 451 Research, OpenStack-related business revenue is expected to exceed $1 billion by 2015 as the enterprise market for OpenStack evolves.

  5. Fedora 20 Beta vs. Ubuntu 13.10 vs. Scientific Linux 6.4
  6. Update on x2go

    I’ve been playing with / using x2go more lately and I sure do like it. I originally learned about it by reading the Fedora 20 ChangeSet and saw that it will be a new feature in the upcoming Fedora 20. I started using Fedora 20 shortly before the alpha release came out. Fedora 20 Beta was released on 2013-11-12… and I’ve been building my MontanaLinux remix about once a week.

  7. NSA wanted a backdoor in Linux, confirms Linus’ father
  8. Did NSA contact Linus for a backdoor in Linux? [updated]
  9. Linus’ father confirms NSA attempt at backdoor in Linux
  10. Mastering Linux, Backdoor’d, & openSUSE 13.1
  11. NSA infected 50,000 computer networks with malicious software
  12. N.S.A. Report Outlined Goals for More Power

    In a February 2012 paper laying out the four-year strategy for the N.S.A.’s signals intelligence operations, which include the agency’s eavesdropping and communications data collection around the world, agency officials set an objective to “aggressively pursue legal authorities and a policy framework mapped more fully to the information age.”

    Written as an agency mission statement with broad goals, the five-page document said that existing American laws were not adequate to meet the needs of the N.S.A. to conduct broad surveillance in what it cited as “the golden age of Sigint,” or signals intelligence. “The interpretation and guidelines for applying our authorities, and in some cases the authorities themselves, have not kept pace with the complexity of the technology and target environments, or the operational expectations levied on N.S.A.’s mission,” the document concluded.

    Using sweeping language, the paper also outlined some of the agency’s other ambitions. They included defeating the cybersecurity practices of adversaries in order to acquire the data the agency needs from “anyone, anytime, anywhere.” The agency also said it would try to decrypt or bypass codes that keep communications secret by influencing “the global commercial encryption market through commercial relationships,” human spies and intelligence partners in other countries. It also talked of the need to “revolutionize” analysis of its vast collections of data to “radically increase operational impact.”

  13. Latest Snowden leak reveals NSA’s goal to continually expand surveillance abilities

    In a mission statement last year the US National Security Agency described how it would continue to expand its power and assert itself as the global leader in clandestine surveillance, according to a new report based on the Edward Snowden leaks.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 19/4/2018: Mesa 17.3.9 and 18.0.1, Trisquel 8.0 LTS Flidas, Elections for openSUSE Board

    Links for the day



  2. The Patent Microcosm, Patent Trolls and Their Pressure Groups Incite a USPTO Director Against the Patent Trial and Appeal Board (PTAB) and Section 101/Alice

    As one might expect, the patent extremists continue their witch-hunt and constant manipulation of USPTO officials, whom they hope to compel to become patent extremists themselves (otherwise those officials are defamed, typically until they're fired or decide to resign)



  3. Microsoft's Lobbying for FRAND Pays Off as Microsoft-Connected Patent Troll Conversant (Formerly MOSAID) Goes After Android OEMs in Europe

    The FRAND (or SEP) lobby seems to have caused a lot of monopolistic patent lawsuits; this mostly affects Linux-powered platforms such as Android, Tizen and webOS and there are new legal actions from Microsoft-connected patent trolls



  4. To Understand Why People Say That Lawyers are Liars Look No Further Than Misleading Promotion of Software Patents

    Some of the latest misleading claims from the patent microcosm, which is only interested in lots and lots of patents (its bread and butter is monopolies after all) irrespective of their merit, quality, and desirability



  5. When News About the EPO is Dominated by Sponsored 'Reports' and Press Releases Because Publishers Are Afraid of (or Bribed by) the EPO

    The lack of curiosity and genuine journalism in Europe may mean that serious abuses (if not corruption) will go unreported



  6. The Boards of Appeal at the European Patent Organisation (EPO) Complain That They Are Understaffed, Not Just Lacking the Independence They Depend on

    The Boards of Appeal have released a report and once again they openly complain that they're unable to do their job properly, i.e. patent quality cannot be assured



  7. Links 18/4/2018: New Fedora 27 ISOs, Nextcloud Wins German Government Contract

    Links for the day



  8. Guest Post: Responding to Your Recent Posting “The European Patent Office Will Never Hold Its Destroyers Accountable”

    In France, where Battistelli does not enjoy diplomatic immunity, he can be held accountable like his "padrone" recently was



  9. The EPO in 2018: Partnering With Saudi Arabia and Cambodia (With Zero European Patents)

    The EPO's status in the world has declined to the point where former French colonies and countries with zero European Patents are hailed as "success stories" for Battistelli



  10. For Samsung and Apple the Biggest Threat Has Become Patent Trolls and Aggressors in China and the Eastern District of Texas, Not Each Other

    The latest stories about two of the world's largest phone OEMs, both of which find themselves subjected to a heavy barrage of patent lawsuits and even embargoes; Samsung has meanwhile obtained an antisuit injunction against Huawei



  11. The EPO Continues to Lie About Patent Quality Whilst Openly Promoting Software Patents, Even Outside Europe

    EPO patent quality continues to sink while EPO management lies about it and software patents are openly being promoted/advocatedEPO patent quality continues to sink while EPO management lies about it (the article above is new) and software patents are openly being promoted/advocated



  12. SCOTUS on WesternGeco v Ion Geophysical Almost Done; Will Oil States Decision Affirm the PTAB's Quality Assurance (IPRs) Soon?

    Ahead of WesternGeco and Oil States, following oral proceedings, it's expected that the highest court in the United States will deliver more blows to patent maximalism



  13. Links 17/4/2018: Linux 5.x Plans and Microsoft's 'Embrace'

    Links for the day



  14. The European Patent Office (EPO) Grants Patents in Error, Insiders Are Complaining That It's the Management's Fault

    The EPO has languished to the point where patents are granted in error, examiners aren't happy, and the resultant chaos benefits no-one but lawyers and patent trolls



  15. The European Patent Office Will Never Hold Its Destroyers Accountable

    With only one in seven EPO stakeholders believing that Battistelli's pick (António Campinos) will turn things around for the better, it certainly does not seem like people are happy and there's no real hope that Battistelli will ever be held accountable for his abuses after his immunity expires



  16. With Liars Like These...

    The European Patent Office continues to lie about the Unified Patent Court (UPC) amongst other things, still revealing its reluctance to say anything which is truthful or work to repair the damage caused by Benoît Battistelli



  17. Links 16/4/2018: Linux 4.17 RC 1, Mesa 18.0.1 RC, GNOME 3.28.1

    Links for the day



  18. IAM, Patently-O and Watchtroll (the Patent Trolls' Lobby) Try to Stop Patent Oppositions/Petitions (PTAB)

    In spite of fee hikes, introduced by Iancu's interim predecessor, petitions (IPRs) at the PTAB continue to grow in number and the patent maximalists are losing their minds over it



  19. The Patent Trial and Appeal Board (PTAB) is Ending Software Patents One Patent at a Time

    At an accelerating pace and with growing determination, PTAB (part of AIA) crushes patent trolls and software patents; the statistics and latest stories speak for themselves



  20. Academics and Think Tanks for Patent Maximalism

    Right-wing think tanks and impressionable academics continue to lobby for patent maximalism, rarely revealing the funding sources and motivations; in reality, however, such maximalism mainly helps large (already-wealthy) corporations, monopolists, and law firms



  21. Killing Patent Quality and Encouraging 'Covert' Software Patents Using the Buzzwords Du Jour

    The epidemic of buzzwords and/or hype waves that are being exploited to dodge or bypass patent scope/limitations, as seen in Europe and the US these days



  22. Crisis of Quality at the EPO Extends to Staff (Notably Examiners) and Management as Institutional Integrity is Severely Compromised

    A rather pessimistic but likely realistic outlook for the European Patent Office (EPO), which seems unable to attract the sort of staff it attracted for a number of decades



  23. The 'Blockchaining' of Software Patents (to Dodge the Rules/Guidelines) Now Coming to Europe

    A lot of software patents are being declared invalid (or not granted in the first place); having said that, using all sorts of hype waves (like calling databases “blockchains”) firms and individuals manage to still be granted software patents and sometimes patent trolls hoard these



  24. Links 14/4/2018: Wine 3.6, KDE Elisa 0.1

    Links for the day



  25. East Asia Should Have Adopted the Patent Strategy of South Asia, Notably India

    China seems to be so interested in patent maximalism that it has lost sight of the effect on foreign investment, e.g. US/European/Taiwanese/Japanese/Korean firms operating/manufacturing in mainland China



  26. Samsung is the 'New IBM', Sans the Trolling With Patents

    The 'relic' company, IBM, loses its patent leadership (as measured using some yardstick) to Samsung, a company which is relatively calm when it comes to patent activity (unless/only when sued, as happens a lot nowadays)



  27. David Barcelou May or May Not be a Patent Troll, But He is Certainly a SLAPPing Bully and Watchtroll is Fine With It

    Like a thin-skinned person/entity (which many in the patent microcosm are), David Barcelou and Automated Transactions (“ATL”) SLAPP their critics and surprisingly enough it's Watchtroll, who has been threatened by WIPO, coming to the bully's rescue (double standards)



  28. Links 12/4/2018: Stable New Kernels, Neptune 5.1

    Links for the day



  29. The USPTO Has a Nepotism and Lobbying Problem That Jeopardises the Rationality of US Patent Law

    The influence games of Washington are spilling over to the US patent office and poisoning/harming its ability to conduct professional operations without corporate influence (from either side, both corporations and law firms)



  30. Patent Trolls in the United States Show the Importance of Stopping Software Patents (Trolls' Favourite) Worldwide

    The abundance of entities that exist for no purpose other than to initiate lawsuits is a contagious threat to real innovation (or science and technology being practiced); a new jury verdict (record-breaking $500,000,000) is a reminder of this


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts