EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

01.29.14

The Latest FOSS FUD Revolves Around Fakes and Bogus Arguments

Posted in Free/Libre Software, Security at 2:07 pm by Dr. Roy Schestowitz

Summary: How Free/Open Source Software (FOSS) gets discredited over “security”, based on something which has nothing to do with FOSS and more to with human error or social engineering

THE reports from IDG make it sound as though FileZilla is a security threat [1,2] when it fact it is fakes that are a threat, as Sean pointed out to counter these allegations [3].

Yesterday we took note of the trend and two days ago we gave some examples of security-flavoured FUD against Android, of which there is plenty these days (and even today). Some of it is correctly being characterised as platform-agnostic [4]. This sometimes requires user intervention [5] or social engineering [6], so there’s a lot more to be taken into account. When the OpenSSL project got compromised some weeks ago it was actually the fault of a weak password [7,8], but some of the media spread FUD about OpenSSL itself. Weak passwords are a common human error [9] and those who don’t encrypt E-mails that contain passwords (they should!) only have themselves to blame [10,11]. To get an example of real vulnerability, consider Apple’s Safari storing passwords in plain text [12]!!! GNU/Linux, by contrast, facilitates strong encryption and has protection against all sorts of attacks [13-14].

Blaming FOSS for issues that relate to social engineering is a common FUD pattern these days (like blaming Android for users installing malware they download outside repositories), but the real security issues are back doors like Microsoft’s, security flukes like Apple’s, and data leakage through so-called ‘clouds’ (which are typically promoted by proprietary software players, tightly connected to the crack-leaning NSA).

Related/contextual items from the news:

  1. FileZilla warns of large malware campaign
  2. FileZilla warns of large malware campaign
  3. FileZilla, Other Open-Source Software From ‘Right’ Sources Is Safe

    A basic tenant of open-source software security has long been the idea that since the code is open, anyone can look inside to see if there is something that shouldn’t be there.

  4. Java-based malware driving DDoS botnet infects Windows, Mac, Linux devices

    The cross-platform HEUR:Backdoor.Java.Agent.a, as reported in a blog post published Tuesday by Kaspersky Lab, takes hold of computers by exploiting CVE-2013-2465, a critical Java vulnerability that Oracle patched in June. The security bug is present on Java 7 u21 and earlier. Once the bot has infected a computer, it copies itself to the autostart directory of its respective platform to ensure it runs whenever the machine is turned on. Compromised computers then report to an Internet relay chat channel that acts as a command and control server.

  5. Yahoo users exposed to malware attack

    Users clicking on some ads are redirected to sites armed with code that exploits vulnerabilities in Java and installs a variety of different malware.

  6. Password Security Requires Multiple Layers of Protection

    The gist of the story is that “123456″ is now the most commonly used weak password—surpassing the use of the word “password.”

  7. No hypervisor vulnerability exploited in OpenSSL site breach

    The OpenSSL Project confirmed that weak passwords used on the hosting infrastructure led to the compromise of its website, dispelling concerns…

  8. OpenSSL site defacement involving hypervisor hack rattles nerves (updated)

    Code repositories remained untouched in the December 29 hack, and the only outward sign of a breach was a defacement left on the OpenSSL.org home page. The compromise is nonetheless rattling some nerves. In a brief advisory last updated on New Year’s Day, officials said “the attack was made via hypervisor through the hosting provider and not via any vulnerability in the OS configuration.” The lack of additional details raised the question of whether the same weakness may have been exploited to target other sites that use the same service. After all, saying a compromise was achieved through a hypervisor vulnerability in the Web host of one of the Internet’s most important sites isn’t necessarily comforting news if the service or hypervisor platform is widely used by others.

  9. 7 sneak attacks used by today’s most devious hackers
  10. 10,000 Top Passwords

    Back when I wrote Perfect Passwords, I generated a list of the top 500 worst (aka most common) passwords which seems to have propagated quite a bit across the internet, including being mentioned on Gizomodo, Boing Boing, Symantec, Laughing Squid and many other sites. Since then I have collected a large number of new passwords bringing my current list to about 6,000,000 unique username/password combos, including many of those that have been recently made public*.

  11. All Your Internet Are Belong To Iceland*

    All that being said, and given that the Luddite solution of forsaking the Internet may not be terribly practical, this is another reason to encrypt technical data that you are sending by email even if the recipient is a U.S. person firmly planted on U.S. soil. No, the encryption isn’t a defense to the violation, but it is at least a mitigating factor. Remember, as I posted last May, that the U.S. military thinks it can put ITAR-controlled technical data on a Chinese satellite if it’s encrypted; so if you don’t have anything else to say in your defense when an email with export controlled data accidentally wanders through Lithuania, you will at least have that. And maybe one day in the distant future, BIS and DDTC will admit that the Internet exists and that encryption works.

  12. Older Versions of Safari Store Login Info in Plain Text

    Older versions of Safari for Mac store unencrypted user login credentials in a plain text file, according to security firm Kaspersky (via ZDNet). Safari saves the information in order to restore a previous browsing session, reopening all sites, even those that require authentication using the browser’s “Reopen All Windows from Last Session” functionality.

  13. Quantum crypto pitches for data centre links
  14. Linux Is the Only Way to Protect Against Potential Sound-Transmitted Malware
Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Alice v CLS Bank (SCOTUS, 2014) Has Had a Profound Effect on 2017 as Nearly No Software Patents Upheld at a High Level

    As 2017 nears its end (less than two weeks left), a look back reveals a terrible year for proponents of software patents and a milestone for opponents of software patents



  2. PTAB Helps Defend and Encourage Work by Actual Technology Companies in the US, the Patent Trolls' Lobby is Upset

    The Patent Trial and Appeal Board (PTAB), which continues to invalidate software patents by the thousands, comes under attack from the expected sites, namely those that are fronting for patent trolls and parasites



  3. Patent Misconceptions Promoted in Media Dominated by the Patent Microcosm, Not Actual Innovators

    Examples from the media where popular myths have been promoted over the past few days, taking advantage of passivity and silence among those who actually create and invent



  4. Links 17/12/2017: KStars 2.8.9, GNOME 3.27.3, Parrot Security 3.10

    Links for the day



  5. Raw: Benoît Battistelli Has Long Been Obsessed With 'Alternative Facts' (Lying) Regarding Everything

    The chronic lying by Battistelli’s EPO goes way back and reveals a total lack of integrity, shedding doubt on just about any statement issued by the Office



  6. Raw: At the EPO “Social Democracy” is Actually a Euphemism for Authoritarian Regime

    An old document about the EPO‘s transition to so-called ‘social’ ‘democracy’ and what that means in practical terms



  7. Battistelli's 'UPC Buddy' Michel Barnier Helped Squash EU Intervention in Dysfunctional (Subverted by Battistelli) Administrative Council

    A look back at how Michel Barnier helped cover Battistelli's back, insisting that the Commission cannot do anything to rectify matters at the EPO (Elżbieta Bieńkowska, another UPC proponent, said something similar later)



  8. Raw: “Experienced Examiners Can Examine Anything.” (Even Not in Their Field!)

    An internal document shows how the EPO handles imbalance in filings, in essence shifting examiners to fields they are not familiar with



  9. Andrei Iancu in Charge of the United States Patent Office (USPTO) Would be a Patent Microcosm Coup

    The progression of Andrei Iancu's nomination/appointment is a reason for concern; it is, for a fact, a reason for optimism among patent extremists



  10. The Latest IAM Puff Pieces That Launder the 'Reputation' of Patent Trolls

    The creeping threat of patent extortion (litigation from companies that are empty shells with nothing but patents) does not worry IAM; instead, this is the vision IAM wants to actualise, having been paid by stakeholders in such a nefarious outcome



  11. The EPO Has Found 'Creative' New Ways to Bribe the Media and Promote Software Patents

    From Computer-Implemented Inventions (CII) and "Industry 4.0" the EPO is moving to creative new misnomers for carriers of software patents, SEP (patents-encumbered 'standards'), so-called 'FRAND' etc.



  12. EPO Busy Distracting From Miscarriage/Abuse of Justice at the EPO (Both Office and Organisation)

    The European Patent Organisation continues to be a vassal of the Office (Christoph Ernst is defending Battistelli) and justice is not being honoured; it's being discarded in the darkness (in secret meetings)



  13. Bristows LLP/IP Kat Carrying on With Dead UPC Jingoism

    The same old tune from Bristows not only gets played in Bristows' 'alternate reality' blog but also in other blogs where Bristows staff is 'contributing' (to confusion and misconceptions)



  14. Links 16/12/2017: Mesa 17.2.7, Wine 3.0 RC2, Kdenlive 17.12.0, Mir 0.29

    Links for the day



  15. Patrick Corcoran is Innocent, Yet Battistelli Will/May Have the Power to Sack Him Next Month (in DG1)

    The EPO's Administrative Council does not want to even mention Patrick Corcoran, as merely bringing that up might lead to the suggestion that Benoît Battistelli should be fired (yes, they can fire him), but to set the record straight, at the EPO truth-tellers are punished and those whom they expose are shielded by the Administrative Council



  16. Patent Trolls Are Going Bust in the United States (Along With the 'Protection' Racket Conglomerates)

    RPX continues its gradual collapse and patent trolls fail to find leverage now that software patents are kaput and patent opportunists struggle to access Texan courts



  17. IBM's Manny Schecter is Wrong Again and He is Attempting to Justify Patent Trolling

    In yet another dodgy effort to undermine the US Supreme Court and bring back software patents, IBM's "chief patent counsel" (his current job title) expresses views that are bunk or "alternative facts"



  18. EPO Administrative Council Disallows Discussion About Violations of the Law by Benoît Battistelli

    The EPO crisis is not ending for the Administrative Council does not want to tackle any of the obvious problems; Patrick Corcoran is a taboo subject and Ernst is coming across as another protector of Benoît Battistelli, based on today's meeting (the second meeting he chairs)



  19. Links 13/12/2017: GIMP 2.9.8, Fedora 25 End Of Life, AltOS 1.8.3

    Links for the day



  20. Judge Corcoran Got His User ID/Desk Back (as ILO Asked), But Cannot Perform Actual Work

    The latest update regarding Patrick Corcoran, whose 3-year ordeal is far from over in spite of ILO's unambiguous rulings in his favour



  21. The End of Software Patents and PTAB's Role in Enforcing That End

    Software patents are fast becoming a dying breed and the appeal board (PTAB) of the USPTO accelerates this trend, irrespective of patent immunity attempts



  22. No, China Isn't Most Innovative, It's Just Granting a Lot of Low-Quality Patents

    Patent extremists are trying to make China look like a role model or a success story because China grants far too many patents, spurring an explosion in litigation



  23. Battistelli-Campinos Transition Will Be a Smooth One as the Administrative Council Remains the Same and the Boards Still Besieged

    A rather pessimistic (albeit likely realistic) expectation from tomorrow's meeting of the Administrative Council, which continues to show that no lessons were learned and no strategy will be altered to avoid doom (low-quality patents and stocks running out)



  24. Links 12/12/2017: New BlackArch ISO and Stable Kernels

    Links for the day



  25. German Media Helps Cover Up -- Not Cover -- the Latest EPO Scandal

    EPO-Handelsblatt attention diversion tricks may be effective as German media barely shows interest in one of the EPO's biggest scandals to date



  26. PTAB Haters Fail to Guard Bogus Patents, But They Still Try

    Three Affiliated Tribes probably won't enjoy sovereign immunity from PTAB, Dennis Crouch won't manage to slow down PTAB, and patent litigation will stagnate as bad patents perish before they even land in a lawsuit



  27. Team UPC's Tilmann Defends Rogue Vote at 1 AM in the Morning With Just 5% of Politicians (Those With Vested Interests) Attending

    Just when German democracy is being stolen by a legislative coup (in the dead of night when 95% of politicians are absent/asleep) there's someone 'courageous' enough to rear his ugly head and attempt to justify that coup



  28. The Mask Falls: Lobbyist David Kappos Now Composes Pieces for the Patent Trolls' Lobby (IAM)

    David Kappos, a former USPTO Director who is now lobbying for large corporations that derive revenue from patent extortion, is writing for IAM even if his views are significantly biased by his aggressive paymasters (just like IAM's)



  29. The EPO Protest Tomorrow Isn't Just About Judge Corcoran But About the EPO as a Whole

    PO staff is about to protest against the employer, pointing out that "Battistelli is still showing a total and utter lack of respect not only for his staff and their rights but also for the Administrative Council and for the Tribunal"



  30. Claim: Judge Corcoran to Be Put Under Benoît Battistelli's Control in DG1

    Benoît Battistelli, who openly disregards and refuses to obey judges (while intervening in trials and delivering 'royal decrees' whenever it suits him), may soon gain direct control over the judge he hates most


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts