Bonum Certa Men Certa

For Real Security, Use CentOS -- Never RHEL -- and Run Neither on Amazon's Servers

Red Hat logo



Summary: Never run Red Hat's "Enterprise Linux", which cannot be trusted because of NSA involvement; Amazon, which pays Microsoft for RHEL and works with the CIA, should never be used for hosting

SEVERAL years ago CentOS almost died; now it's being embraced by Red Hat and one pundit from tech tabloid ZDNet is moving to CentOS Linux on the desktop [1,2].



CentOS is still in the news [3], with the CentOS project leader (Karanbir Singh) giving an interview to the Linux Foundation [4]. We trust CentOS, whereas trusting Red Hat is hard. RHEL is binary and based on news from half a decade ago, the NSA is said to be involved in the building process, as well as SUSE's, whereas CentOS is built from source (publicly visible). Microsoft and the NSA do the same thing with Windows and it's now confirmed that Windows has NSA backdoors.

Earlier this month vulnerabilities in RHEL's openssl and RHEL's gnupg [5,6], contributed even less to trust. RHEL is so standard in the industry that it would probably be simpler than other distributions to exploit; the NSA may as well have off-the-shelf exploits for all major RHEL releases, which are deployed in many countries' servers (even so-called 'rogue' countries). Based on the NSA leaks, Fedora -- not RHEL -- is being used by the NSA itself to run its spying operations (e.g. collecting radio signals from afar). Fedora is not truly binary-compatible and its source code makes secrets hard to keep.

Lastly, mind the latest of Red Hat's Fog Computing hype [7,8], including the CIA's partner Amazon that's lumped onto Red Hat [9,10] as part of a conference [11,12]. Avoid Amazon at all costs. It's a malicious trap for many reasons. Amazon also pays Microsoft for RHEL after a patent deal with Microsoft, as we pointed out years ago. Suffice to say, Microsoft's servers are as bad as Amazon's for privacy.

RHEL and its derivatives continue to be deployed in many large networks of systems [13], so it's clear why the NSA would drool over the possibility of back doors in RHEL. Watch out for that. Given the way NSA infiltrated standards bodies and other institutions, it's not impossible that there are even moles at Red Hat or Fedora. There used to be some at Microsoft (we know about those who got caught).

Red Hat's CEO is now telling his story in a Red Hat site [14] and one needs to remember who he used to work for (close to Boeing, which is primarily an army company), not just the country he is based on (hence the rules that apply to him, especially when he wishes to appeal to government contractors, DoD/Pentagon etc. which are the most lucrative contracts).

It should be noted that my Web sites are mostly running CentOS and the same goes for the host of Techrights, who focuses on security. With CentOS you can get the source code and redistribute; with Red Hat's RHEL you can't (it's sold as binary).

There is definitely a good reason to trust CentOS security more than RHEL security. As for Oracle ("Unbreakable"), well... just read Ellison's public statements in support of the NSA (never mind the company's roots and the CIA). That tells a lot.

The bottom line is, blind faith in binary distributions is a bad thing. Blind faith in NSA partners (Red Hat collaborates with the NSA not just in SELinux) is even worse.

Related/contextual items from the news:



  1. Taking the long view: Why I'm moving to CentOS Linux on the desktop


  2. Is CentOS ready for the Linux desktop?
    CentOS is a very interesting and different choice for a desktop distribution. I haven't heard of many people using it that way. Whenever somebody brings it up it's usually within the context of running a server.


  3. Fedora and CentOS Updates, Linux for Security, and Top Seven


  4. CentOS Project Leader Karanbir Singh Opens Up on Red Hat Deal
    In the 10 years since the CentOS project was launched there has been no board of directors, or legal team, or commercial backing. The developers who labored to build the community-led version of Red Hat Enterprise Linux (RHEL) worked largely unpaid (though some took a few consulting gigs on the side.) They had a few hundred dollars in their bank account to pay for event t-shirts and that was it. And the project's direction was decided based on the developers' immediate needs, not a grand vision of future technology.


  5. Red Hat: 2014:0015-01: openssl: Important Advisory
  6. Red Hat: 2014:0016-01: gnupg: Moderate Advisory


  7. Red Hat Invests in Open Source IaaS, Cloud Talent


  8. Red Hat Academy Expands Training, Includes OpenStack Coursework


  9. Red Hat Launches Test Drives on AWS
    At its annual Partner conference in Scottsdale, Arizona this week Red Hat (RHT) announced new Test Drives on Amazon Web Services (AWS) with three Red Hat partners – CITYTECH, Shadow-Soft, and Vizuri. Through the AWS Test Drive program, users can quickly and easily explore and deploy ready-made solutions built on Red Hat technologies.



  10. Why Red Hat Needs OpenStack ... And AWS
    OpenStack, the cloud's community darling, desperately needs leadership, and Red Hat seems the ideal leader. But OpenStack isn't the only needy party here. As good as Red Hat's growth has been over the last decade, it pales in comparison to that of VMware, a later entrant that has grown much faster than Red Hat. And the open source leader still trails well behind Microsoft.


  11. Google, Amazon Clouds Invade Red Hat Partner Conference
    Google Cloud Platform and Amazon Web Services executives are set to address Red Hat Partner Conference attendees on Jan. 13 in Arizona. No doubt, the keynotes will seek to ensure Linux resellers understand how to move customer workloads into the Google and AWS public clouds, respectively.


  12. 7 Surprises At Red Hat Partner Conference 2014


  13. How to deploy OSSEC across a large network of systems from RPMs


  14. Teens and their first job: How to get on the path to a happy career
    I grew up in the 1980s in Columbus, Georgia. You needed a car to get around, so I did not work until I could drive. Within months of getting my driver's license, I got my first job as a part-time computer programmer for a stockbroker.


Comments

Recent Techrights' Posts

Apparently Confirmed: IBM Layoffs in Canada Today, Hundreds Affected
Impacting "177 people", says one person, "in Ottawa"
[Video] Dr. Richard Stallman's Keynote Speech in Kerala Finally Uploaded
In non-free format and proprietary YouTube, but perhaps that's better than nothing
 
Links 27/03/2025: Obituary to a Shop, Russia Trying to Buy Time
Links for the day
Links 27/03/2025: Slop, Autosuggestions, and Nostr
Links for the day
When Windows Was Dominant (1990s) Browser Monopoly Meant MSIE, But Now Google Android is Dominant and the Web in a 'Webapps' Era Works With (or Is Designed for) Chrome-isms
We've been there before
Slopwatch: BetaNews, LinuxSecurity.com, and the Attack on Web Search Using Fake and Likely Plagiarised Pages
Changing a few words here and there won't change the fact that it's not properly authored
Links 27/03/2025: U.S. Honeybee Deaths Reach Record High, Legal Occupation Next in Line After War on Science
Links for the day
Using Courts for 'Revenge' is Always a Losing Strategy
Trying to cause someone you dislike to spend a lot of money
IBM CFO James Kavanaugh Refers to Firing of Almost 10,000 Americans as "Workforce Rebalancing" (Shifting IBM's Centre of Balance to Low-salary Contracts/Countries)
The scale of IBM layoffs is getting too large to evade WARN Notices
Islands Are Leaving Microsoft Behind, According to statCounter
Android has had a very strong year
EPO Management Fails to Deny That the Office is Discriminating Against Women
Europe's second-largest institution isn't just exceedingly corrupt but also immoral
In Some Countries the Market Share of Vista 11 is Going Down, Not Up
despite being released in 2021
Rumour: Mass Layoffs in IBM Canada Today
Maybe later today some people from Canada will say something firmer and maybe some media will even talk about that
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, March 26, 2025
IRC logs for Wednesday, March 26, 2025
Gemini Links 27/03/2025: X-Files' "Kill Switch", Orlando, and ASN (Autonomous System Number) 'Hack'
Links for the day
Links 26/03/2025: Healthcare Cuts and Turkey's Own "2025 Project" (Culling Opposition)
Links for the day
LLM Slopfarm: A Site's Last Incarnation Before Throwing in the Towel, Going Offline Permanently
A lot of coverage that claims to be about Finland is chatbot-generated nonsense or poorly-plagiarised work
Microsoft Canonical Pays IDG to Spread FUD (Fear, Uncertainty, Doubt)
this seems a tad exploitative and reminds us of the time Novell kept telling companies that using anything other than SUSE was dangerous
Gemini Links 26/03/2025: GTD, Zenshuu, and Geminispace Community
Links for the day
Links 26/03/2025: Media's Failures, Arrests of Journalists, Limitations of End-to-End Encryption
Links for the day
LLM Slop (Lots of It Spewed Out by Microsoft) Versus Linux
Microsoft is a very, very evil company. It doesn't mind destroying the Web if there's a chance it'll make a buck in the process or mess up people's brains (in Microsoft's favour).
Slopfarms (Sites That Only Ever Publish LLM Slop) Are Killing Google News
pair of slopfarms still propped up by Google News
Microsoft's Serial Strangler's Law Firm Has a Long History of Fronting for People Who Do Bad and/or Illegal Things
Whose terrible idea was this?
Novell and Microsoft Apologist/Booster Bruce Byfield Writing About the FSF is a Recipe for Problems
Totally not shoehorning some agenda
Looking Forward to the Fall of UPC and Revocation of the Unified Patent Court (UPC) Agreement, Which Was Always Illegal and Unconstitutional
We'll try to keep abreast of any progress in this case
Slopwatch: Google News, LinuxSecurity.com, and the General Demise of the Web
many supposed or so-called "news" pages are just spewed out by some chatbots (or tools which help plagiarise original articles without getting caught; detection gets harder)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, March 25, 2025
IRC logs for Tuesday, March 25, 2025
Links 25/03/2025: Clownflare’s Slop and Bounties on Fake Patents
Links for the day
Links 25/03/2025: Terrace Workbench and Spellcheck in LibreOffice on FreeBSD
Links for the day
Let Them Eat 'Apps'
Go Appless
Linux Runs Almost Everything, But They Almost Never Tell You This (No Marketing Budget)
Only about 1% (or at most 2%) of the Linux Foundation's budget goes towards Linux; a lot is routed towards Bill Gates and Microsoft promotion
Free Software Community Folks Are Closer Together Than the Cliques and Opportunists Rallying Around "Open Source" (Openwashing, Marketing, Conniving)
Generally speaking, freedom-loving geeks learn to reject morbid elements and trolls, who end up expelled
The Open Source Initiative (OSI) Might Get 'Forked' Soon
Someone who read our series has already taken a leading role
IBM Layoffs in the United Kingdom (UK) in 2025
Should Free software people trust such a secretive company?
Roku Will 'Lead' Attempts to Abolish the Illegal and Unconstitutional Unified Patent Court (UPC), Which Represents EPO Corruption and Lobbyism Spreading Upwards Inside the EU
When bribery buys policies and courts, even illegal policies and courts
Growing Poverty Rates in the United States of America (or Elsewhere) Beneficial to GNU/Linux Adoption
Toxic politics around the world, including the US, may mean weaker economies
European Patent Office (EPO) Illegally Turning to Slop Behind Closed Doors, Staff Objects to This Hidden Catastrophe
Who stands to gain from all this and at whose expense?
Gemini Links 25/03/2025: Relaxation, Literary "Movements", and Gemini Mentions
Links for the day
After US Government Funding Cuts the Centralisation of the Web (Especially Certificate Authority Let's Encrypt) is at Risk
They try to pull the plug on open protocols with decent encryption available (unless it is outsourced to third parties)
Links 25/03/2025: Putin Sends Children to Battle, 23andMe Drowns as People's Highly Personal DNA Data Floats
Links for the day
When Microsoft Folks Who Literally Strangle Women Try to Strangle Microsoft Critics
Speaking to Court staff yesterday, they too are shocked about those SLAPPs
Martinique: Windows Down to All-Time Low
we cannot expect Windows to ever recover
Anticipated in 2018: Lilie James & Location tracking, Googlists complained
Reprinted with permission from Daniel Pocock
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, March 24, 2025
IRC logs for Monday, March 24, 2025